The online racing simulator
Hackers alert / license rental
(189 posts, closed, started )
Hackers alert / license rental
Dear LFS Racers,

We have seen evidence of people obtaining the GAME passwords of LFS racers.

[EDIT: We know of around 20 passwords obtained by one person - there is no evidence of a widespread problem]

We don't know where they get the data, but there is no evidence of a breach of security on our servers. Passwords have not been obtained by brute force attack either. We suspect there are multiple sources, possibly including data from pirate master servers that no longer exist. Possibly some password guessing and possibly passwords could have been obtained by software supplied by unscrupulous LFS community members.


EDIT: Unfortunately, I started this one thread about two separate subjects which are probably not related. For the password subject, I have now started a new thread: https://www.lfs.net/forum/thread/107278


We have also received a report of a rental system in Turkey, run by some users that have obtained at least the GAME password of several LFS accounts and are renting them out for money (although some of these accounts may have been purchased legitimately rather than stolen).

If you have not changed your GAME password recently, please change it now, and make sure it is not related to any other passwords you use on the internet.

I'll have to take some more days off actual Live for Speed development in order to try to detect accounts that are being passed around.

If you have seen any account being used illegally, please try to contact the true owner of the account if you can. We will not be able to handle large numbers of reports to our technical support email. Such reports usually contain very minimal proof and it's hard for us to simply take such accounts offline. But if the true owner could change their passwords then the problem is solved without our intervention.

Live for Speed licenses are not for rental or loan to other users, so if we find accounts being used in this way we will remove their access to the online system.

EDIT: More information below: https://www.lfs.net/forum/post/2080549#post2080549
Password updated!
Password updated
#5 - Kova.
Only the game password, not the web one?
Password updated!!!!!
Up +
Quote from Kova. :Only the game password, not the web one?

It would be healthier to replace both.
Quote from Scawen :Dear LFS Racers,

We have seen evidence of people obtaining the GAME passwords of LFS racers. We don't know where they get the data, but there is no evidence of a breach of security on our servers. Passwords have not been obtained by brute force attack either. We suspect there are multiple sources, possibly including data from pirate master servers that no longer exist. Possibly some password guessing and possibly passwords could have been obtained by software supplied by unscrupulous LFS community members.

We have also received a report of a rental system in Turkey, run by some users that have obtained at least the GAME password of several LFS accounts and are renting them out for money (although some of these accounts may have been purchased legitimately rather than stolen).

If you have not changed your GAME password recently, please change it now, and make sure it is not related to any other passwords you use on the internet.

I'll have to take some more days off actual Live for Speed development in order to try to detect accounts that are being passed around.

If you have seen any account being used illegally, please try to contact the true owner of the account if you can. We will not be able to handle large numbers of reports to our technical support email. Such reports usually contain very minimal proof and it's hard for us to simply take such accounts offline. But if the true owner could change their passwords then the problem is solved without our intervention.

Live for Speed licenses are not for rental or loan to other users, so if we find accounts being used in this way we will remove their access to the online system.

You need to check a mail somebody sent to the lfstech mail. If you know what i mean. Contact us.
Updated password (from NENE87 ip) my brother
Isn't it a bit strange that the people who rent accounts and the owners of those accounts write under this article xd
Quote from dmrzn :Isn't it a bit strange that the people who rent accounts and the owners of those accounts write under this article xd

Exactly
changed lfs game and web password
I think it would be much better if you send important developments and news like
Quote from Scawen :Dear LFS Racers,

We have seen evidence of people obtaining the GAME passwords of LFS racers. We don't know where they get the data, but there is no evidence of a breach of security on our servers. Passwords have not been obtained by brute force attack either. We suspect there are multiple sources, possibly including data from pirate master servers that no longer exist. Possibly some password guessing and possibly passwords could have been obtained by software supplied by unscrupulous LFS community members.

We have also received a report of a rental system in Turkey, run by some users that have obtained at least the GAME password of several LFS accounts and are renting them out for money (although some of these accounts may have been purchased legitimately rather than stolen).

If you have not changed your GAME password recently, please change it now, and make sure it is not related to any other passwords you use on the internet.

I'll have to take some more days off actual Live for Speed development in order to try to detect accounts that are being passed around.

If you have seen any account being used illegally, please try to contact the true owner of the account if you can. We will not be able to handle large numbers of reports to our technical support email. Such reports usually contain very minimal proof and it's hard for us to simply take such accounts offline. But if the true owner could change their passwords then the problem is solved without our intervention.

Live for Speed licenses are not for rental or loan to other users, so if we find accounts being used in this way we will remove their access to the online system.

I think it would be much better if you send important developments and news like this to users who want to be notified by e-mail.
Quote from Kova. :Only the game password, not the web one?

just in case, replace both.
Nice Face -> palm
game pw changed!
Dead banana
Im a brave person i dont change password!!!
hunter2
I changed my lfs web password and game password
On JaR we issued a bunch of perm bans when we saw some people with 5 or 6 "spare accounts"

I dont believe the hack scenario, but the renting one from scammed/gift/bought/2nd hand accounts seems more realist.

Actually this makes sense now for me, cause I just couldnt believe people would buy 6 s3 accounts to get them all perm banned on JaR.

I wont change my password now, if some wizard can hack accounts now (wich I dont believe at all), he would easy get my new password tomorrow.

Also this account borrowing business is probably running for monthes, so no need panic.
Quote from turbofan :On JaR we issued a bunch of perm bans when we saw some people with 5 or 6 "spare accounts"

I dont believe the hack scenario, but the renting one from scammed/gift/bought/2nd hand accounts seems more realist.

Actually this makes sense now for me, cause I just couldnt believe people would buy 6 s3 accounts to get them all perm banned on JaR.

I wont change my password now, if some wizard can hack accounts now (wich I dont believe at all), he would easy get my new password tomorrow.

Also this account borrowing business is probably running for monthes, so no need panic.

They make the people who use rented the accounts make money on TC and sell the TC money for irl money and make profit
I should explain that there are actually two separate issues here. They may be linked or partially linked, I don't know yet.

The first thing is a small number, around 20 that we know of, accounts in which the GAME password has been discovered by some means, that we don't know. We haven't heard this is widespread but we have seen repeated related attempts to use other licenses. At least some of these licenses are LFS users who have given no permission for anyone else to use their license.

The second thing is an illegal LFS license rental service based in Turkey. A certain group of users has actually purchased licenses and rents them out to other users. We don't know if they have also been using stolen licenses, but that is a possibility.

These two scenarios, that are definitely happening, have come to our attention in the last few days. Maybe they are entirely unrelated but people should make sure their WEB password and their GAME password are entirely unique and not used on other sites.
This thread is closed

Hackers alert / license rental
(189 posts, closed, started )
FGED GREDG RDFGDR GSFDG