we should get compensation for having our wallets exposed, maybe bonus sp or a couple extra billion
that is what i said earlier today
Or an offer for a free character name change?
Unless youāre space uber-rich, I donāt think this exploit will significantly affect oneās target profile. It was likely the precursor to a whaling operation, and I expect a wave of contract spam to follow, aimed at the 0.1-1%.
As space lower-middle-class myself, Iām not terribly worried about someone learning my pathetic wallet balance.
me neither, i spend it whenever i am above 30 mil, i went broke on a leshak a while ago
Thatās just weird. How can someone gain access to the wallet or create a snapshot of it just by sending a donation? And above all, are we now supposed to believe that it really only affected the wallet?
I vote for a free namechange for all affected characters as a compensation.
the blog states they modified their clients.. there was a 5th name.
Stroopwafel says they donāt believe it was tied to ESI usage.
nooooo, i dont want to change my name, i want skill points or isk
That is very disconcerting. It obviously wasnāt done just for curiosity. What Iām wondering is, how they got the names. 2/3 of my characters were affected, and I canāt see a common denominator as of yet. Only 2 were possibly online at the time. Even one of my characters whom I hadnāt logged on since February-March was affected (no kb record on him, or other publicly available records). So where did they take the character names from? There were a million of them! You donāt just pull that out randomly, you need a database of character names.
I donāt want to change the name of my character. I want security that vulnerable/private information about my characters is not accessible to third parties through something as simple as donations of 0 isk and the like.
They technically forced a characterās wallet balance to āchangeā even though in reality it didnt. And since it āchangedā, they were then somehow able to āreadā that change or the updated value on their end.
Names are easy. There is an ESI endpoint that returns public details given a characterID. You could either brute force IDs through that or scrape them from zkill/evewho/anyone else already enumerating them.
Speculating from the limited FC commentary, my guess is that the balance was sent back as a response to the donation, but the Eve client has no way to report or display this so it just goes into the void. A modified client or just snooping the resulting network traffic could make that value visible.
Cheat Engine can read memory very easy.
Now I understand why they updating Python. I wonder how many updates are actually security holes being fixed.
Didnāt realize that that dumpster profiles everyone, even characters that have no kb or any public records.
I guess I will now be getting a lot of phone calls from Ukraine.
They said it had nothing to do with the updates
There is no version of python that would or could prevent someone from being able to access the balance if it is being sent to the client.
I know, my point is, there must be worse stuff around.
Only one of mine (me). I donāt have a sample size large enough to postulate a theory, but Hatch is one of only two characters I own that are affiliated with a big null bloc (and the second, only tangentially). Iād be curious how many of those affected were in large alliances, and how many were in random one-man corps, NPC corps, etc.
If I were gathering intel for a whaling operation, Iād definitely focus on the waters of nullsec. That is, after all, where youāll find the biggest whales.
EDIT: Of course, thinking more on that, Iād probably also want to obscure my intended target(s), so Iād scatter the shots to create noiseā¦
it happened to me as well
The funny thing is that i had a 2 1/2 year break and just recently (~maybe 2 weeks) looked back into the game to see if it is worth to upgrade from alpha to omega again. All my 3 accounts recieved this ādonationā.
Cant say that im now hyped to upgrade to omega again ![]()