3 ms·
Having been an Online Architect brought in for a couple of major EA projects (other than this one) I can tell you that they have a very robust and secure centra
by nettdata 15y ago
Having been an Online Architect brought in for a couple of major EA projects (other than this one) I can tell you that they have a very robust and secure centralized user account system available.
The problem comes when you have so many different game teams with varying experience in online security that are allowed to basically implement it as they see fit, and basically "proxy" the account generation/creation process to that centralized user account system. While the underlying system is very capable, the individual game team's end-user offering can be less than optimal, shall we say.
This particular password issue is not an EA-wide thing, to be sure.
- drinian 15y agoIf it's so robust, then why were these hacked passwords being stored unsalted?
- Natsu 15y agoOr using MD5, for that matter....
- nettdata 15y agoIf your car has 6 gears, why are you only using one? Again, it's all about the implementation. Some game teams opt to do their own storage of user information rather than rely on the remote service call to the centralized system. In some cases, like the two projects I worked on, the central system doesn't store all of the user data you need, so you end up storing some in the local system, extending the centralized one. "Some" teams opted to build their own rather than take advantage of the one that existed. (For what it's worth, there is a lot of "build it ourselves" mentality in some teams). This particular team have a few "interesting" things that they've done beyond the user authentication. Their authorization and entitlement implementations left more than a few of us from other teams scratching our heads as to how they opted to utilize the centralized EA service. It was less than ideal, and did cause some issues for a few other teams. I don't want to get into it too much, but I guess if there's one message I'd like to share it's that EA is not one big company, but rather a whole bunch of individual development teams working on their own things. As much as there is an attempt to centralize a lot of knowledge and services, it's by no means a given that everyone's doing the same or right thing. Just because one team totally screwed the pooch on stuff like this, doesn't mean others have as well. A lot of the teams have some leeway and discretion when it comes to what technologies or internal services they use, and sometimes that's a good thing, sometimes it's not.
- Havoc 15y agoEven better somewhere in the EA/BFBC2 account creation process it _allows_ you to use special chars, but when you actually login via the game it fails with a useless error message ("Unable to login. Please try again."), leaving you clueless as to the reason. Googling it tells you to switch of your firewall etc.
- yuhong 15y agoReminds me of this: http://blogs.msdn.com/b/oldnewthing/archive/2006/07/13/664448.aspx http://blogs.msdn.com/b/oldnewthing/archive/2006/07/13/66444...
- random42 15y agoAs an end user, I could not care less about how robust the underlying architecture is or who inside the EA hierarchy is screwing things up. Bottomline is, weak passwords are being stored as unsalted md5 hashes, which is problematic.
- nettdata 15y agoI agree completely, and if I implied otherwise, that wasn't my intent at all. I'm just trying to shed some light that it's not ALL of EA's games, as the headline of the article implies. There are tools and services in place to allow game teams to implement proper passwords and authentication, and they weren't used in this case.
- decadentcactus 15y agoIsn't this the password reset form on EA.com? I encountered it the other day as well. Also, I wondered why EA doesn't use a form of openid via the user account. It has so many games, they all require EA logins, but as we've seen, different sites have different (often bad) implementations. A one-click EA openid would work wonders.