Hi Larian Studios!
This really wasn't the first thing i thought i was going to write about on your forum, but this is so serious that i can not ignore it.
I just created my account, and to my surprise i got my password sent to me in plain text. This is a really serious security risk. Passwords should NEVER be sent in any emails what so ever. Email can very easily be read by people who shouldn't have access to our passwords. And also, most emails are sent unencrypted. It's super easy to sniff the complete content of any email. That's why you should never send any sensitive information in an email. This is common knowledge.
In my case, i also had a friend over when i registered my account. He saw me open my email and we looked at each other and both said "seriously, they sent the password in plain text..." In this case, it's not "that" big of a problem that he saw it. I trust him and i'm sure he won't do anything. But still, i don't want him to know my password. And also, this particular password is now compromised. So what i will have to do now, is to change my password on the other forums that i use this password on. Fortunately, i use different passwords depending on what it's for, so it's not that many places where i have to change my password and not everything is compromised. But if you ask me (and most other people), i would say that NON of my passwords should've been compromised just because i registered an account on Larian Studios forums.
The fact that this problem exists is really bad, but it isn't the worst part. Even though this is a problem so obvious that i personally think there's no way Larian Studios could've missed it, it might still be possible.
You see, i'm kind of giving you the benefit of the doubt. But...
This was only a possibility up until the point where the user "Blauwmuts" pointed it out in a forum post two YEARS ago. A post that you guys have read and responded to. Any serious company would've said, "Damn, we really need to patch this asap!". But you didn't care that much. Did you? A serious security problem, and you just say "The forum software will be upgraded in the not too distant future" and "password security will be addressed then.".
Do I need to mention that I am very disappointed?
First of all, this was as i said earlier, noticed two years ago. And the problem still exist. But more importantly, you say that password security will be addressed later when it's time to upgrade the forum software?! So security clearly isn't a big deal for you guys. But for me and most people, security is something important.
All of this makes me wonder how the rest of your security is. Is our passwords at least encrypted in your databases or is it stored in plain text in there too? Is your "Larian Vault" where i'm supposed to get my serial key for my game later on any more secure?
Larian Studios. I'm really sorry about this kind of "angry" and "upset" first post from me, but this problem and the fact that you have ignored it for at least two years actually made me both angry and upset. I expected more from you. And i still do expect more from you.
Your company is getting big and you seriously can not ignore this kind of problems. I hope that you will actually take this serious this time and that you will address this issue asap. This should've been addressed two hours after "Blauwmuts" reported it the first time. Not two years later...
Last edited by FireZtreaM; 18/12/15 07:32 PM.