news.volyx.in

Hacking 700M Electronic Arts accounts (battleda.sh)

902 points by mooreds · 639 days ago · 154 comments on HN

Article summary

A vulnerability in Electronic Arts' system was reported and patched, but the details of the exploit and its potential impact are being discussed. The report was made 4 months before the patch was applied, which some commenters find concerning. The vulnerability could have been used for various malicious purposes, including unbanning accounts, stealing usernames, or causing chaos. The fact that the reporter did not receive a bug bounty is also a topic of discussion.

Main themes

  • Vulnerability exploitation
  • Bug bounty programs
  • Account security
  • Malicious usage
  • Reporting vulnerabilities
  • Gaming industry security

What commenters say

  • The delay in patching the vulnerability is unacceptable and could have led to significant exploitation.
  • A bug bounty program would have incentivized the reporter and potentially prevented the vulnerability from being exploited.
  • The vulnerability could have been used to create a lucrative business by offering unbanning or username stealing services.
  • Selling exploits or using them for malicious purposes can lead to severe consequences, including legal action.
  • Some companies may not offer bug bounties due to fear of being seen as encouraging hacking or due to a lack of understanding of the importance of vulnerability reporting.
  • Using VPNs and Tor can provide some level of anonymity, but it is not foolproof and can be bypassed by investigators.
  • The lack of a bug bounty program can lead to a situation where vulnerabilities are not reported and are instead exploited or sold on the black market.
  • The gaming industry needs to take security more seriously and implement measures to prevent and respond to vulnerabilities.