1. #1
    Registered User DonnyJepp's Avatar
    Join Date
    December 2002
    Location
    Carebear Countryclub
    Posts
    825

    Angry Rogue Officer, very bad situation I hope others can avoid

    Well, the worst possible thing happened to our clan on Saturn last night. One of our officers "lost control" of his account and it was used to loot and rob us clean. Total losses: 15 million credits and several million worth of stuff in the clan cabs.

    The "player" that owns the character posted a statement:

    "I haven't played that char in many months. I logged in to him soon as I read this and lo and behold, he had no credits, no armor, no weapons, nothing. I didn't do that, but if it is required for my rank to be lowered, I do understand....I will check around on my friends, see if anyone got on my computer while I wasn't home. I'll do my best to try and figure this one out myself."


    Needless to say we have booted him and his alts but the consensus is that this behavior is unlike the individual we had come to know and promoted to officer rank. And, this statement from him doesn't explain everything such as how the looter gained apartment access, suffice to say that security has been a little lax lately as what few of us remain have mostly been out having as much fun as possible, and also dealing with RL issues, instead of slogging through the piss-poor clan-management interface. My suspicion is that our officer shared his account and our apartment password with a roommate at some time in the last few months, and that individual signed in at an opportune time to make the heist.

    So basically, we're screwed, we probably have no recourse but to learn from our mistakes. Obviously we have just now cleaned up our house a bit, booted a bunch of known/unknown inactives, etc. If anyone has any productive ideas for us, please post them. Let the general topic of this thread be related to how to securely manage a clan given the limited tools at our disposal. We had 20+ officers (out of 140+ characters on the roster,) all it took was 1 rogue for it to get all screwed up. I guess what it comes down to, again and again, is:

    *DON'T SHARE YOUR ACCOUNT INFORMATION, DOING SO CAUSES PEOPLE TO GET SCREWED.

    *CHANGE YOUR NC ACCOUNT PASSWORD REGULARILY.

    *DON'T SAVE THE PASSWORD ON YOUR NC CLIENT NO MATTER HOW UNLIKELY IT SEEMS THAT SOMEONE MIGHT USE IT.

    *CHANGE YOUR CLAN APARTMENT PASSWORD REGULARILY (I recommend bi-weekly).

    *AUDIT REGULARILY (no less than monthly) THE ROSTER OF PLAYERS WITH MONEY ACCESS.


    Thanks for your time,

    DJ

  2. #2
    greendonkeyuk's Avatar
    Join Date
    February 2003
    Location
    Nottingham, UK
    Posts
    1,887

    Default

    dont store anything of value in your clan appt.

    dont store any money in your clan bank account.

    Have the clan leader store it in stock x and him give it to people as he sees fit.

    have him store any equipment the clan needs in his cabs, if he cant be on ALL the time (which noone expects for obvious reasons) then allocate one or two people to act on his behalf.

    Ie give them access to funds for the clan.


    The problem that youve encountered is nothing new, our clan has been raided twice, all the money cleaned out and all items taken.

    The first time it happened the 6 people in the clan were all pretty new and we learned our lesson, hell we were recruiting anyone who wanted to come along just to get ourselves off the ground!!

    The second time, all we lost was a few drone bps and some battlevests and other crap which nooone wanted to store in their appts. just bits our noobs may need. the only people who we let have access to the clan appt/money rights were people wed been playing with for months and trusted. it worked so far for us. we never keep a lot of money in the clan fund at all now.

    We preffered to spread it evenly across our runners accounts.
    (the tax man cant catch us then )

    Seriously though if this has happened to you then i would really consider having your security tighter than fort knox on inspection day.
    Today i am mostly actually glad that hacknet week has started.

  3. #3
    Registered User Beefheart's Avatar
    Join Date
    August 2002
    Location
    New York City
    Posts
    1,135

    Default

    Smells Fishy


    He was a clan officer, and that particular character had money withdrawl rights, but he haddn't played that character in "months" ? If he had all 4 of his alts in the clan was it necessary to give one that he would play so casually such a high rank ? All I'm saying is, is that it sounds like when in counter-strike the server admin would detect a player running a hack and before they got booted they'd cry that it was their brother/mother/father/friend/mother theresa that must have used their computer and installed the hack. People, in this virtual game sometimes get a little emotional and unpredictable over in-game BS, so don't give your buddy a halo just yet, anyone is capable of anything no mater how well you THINK you know them.

  4. #4
    Registered User Vash th3 Flash's Avatar
    Join Date
    November 2002
    Location
    Billings, Montana
    Posts
    466

    Default

    Originally posted by Beefheart
    Smells Fishy


    He was a clan officer, and that particular character had money withdrawl rights, but he haddn't played that character in "months" ? If he had all 4 of his alts in the clan was it necessary to give one that he would play so casually such a high rank ? All I'm saying is, is that it sounds like when in counter-strike the server admin would detect a player running a hack and before they got booted they'd cry that it was their brother/mother/father/friend/mother theresa that must have used their computer and installed the hack. People, in this virtual game sometimes get a little emotional and unpredictable over in-game BS, so don't give your buddy a halo just yet, anyone is capable of anything no mater how well you THINK you know them.
    Ditto, but I only have one thing to add to that. DON'T TRUST ANYONE TOO MUCH.
    I'm surrounded by idiots and I'm one of them.

    To be stupid, selfish, and have good health are three requirements for happiness, though if stupidity is lacking, all is lost. Gustave Flaubert (1821 - 1880)



  5. #5
    Registered User Darth Slayer's Avatar
    Join Date
    January 2003
    Location
    Ass End of the Universe.
    Posts
    900

    Default

    My old clan got done 2 times first and second times where tough we'd just started storing bp's when we where done the second time so nothing irreplaceable was stolen. I used to keep the clan rares and constructed items so we always where alright on that account. As for clan money well I always kept a close eye on the purse strings and tended only to promote ppl I trusted to a position where they could get money.

  6. #6
    Registered User
    Join Date
    September 2002
    Location
    aggies sellar LEVELING!
    Posts
    191

    Default

    heh, my clan apt has been looted like 3 times now, one time we knew who it was because he sold it all in plaza 1, he denied everything, the fucking cunt, also he denied other things that i whitnesed the stupid cunt (one of the thing i hate most is people lieing, so excuse my french) and the other 2 times we just dont know what happened, weve never had money stolen, becuase we dont really have much monkey, every now and then someone take like 20k, but that is totally exceptable to us.

    i suggest that if u hold good items in your clan apt dont really let people in there till there like rank 10+ in clan (or if ur a bigger clan just until u know u can trust them etc)
    [ Signature removed for violation of the forum rules - Nidhogg (empty your PM box) ]

  7. #7
    Account not active yet
    Join Date
    December 2002
    Location
    Pepper Park
    Posts
    5,808

    Default

    I agree with bfeeheart.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •