Old School Runescape

Old School Runescape Dev Tracker




25 Jan

Comment

Originally posted by schlamboozle

or have a habit of using various VPN's on web access only - but I have to say it looks suspicious

This shouldn't be suspicious at all and is deeply concerning as I use a VPN for other things but do log onto my accounts while connected to the VPN. Users like to torrent and stream unseen by their ISP or want protection from ddos if you use 3rd party communication software like Teamspeak.

The new email that the owner asked to be set to the account in this recovery request, is in itself suspicious, it has been used on 43 other RuneScape accounts

Sounds like OP was hijacked by a known hijacker that is overly familiar with jagex security protocols which seems more like a problem for you guys than a suspicion on OP.

EDIT: Since we have some idiots in here. At the end of the day. I don't want my account locked because I'm using a vpn to not be throttled or ddossed.

Just to clarify the VPN point - there is no issue at all with people using VPN's, and of course people do go on vacation, relocate for college, move home etc. - I was not trying to imply that these sort of moves cause us any concern.

When reviewing this case, the extensive logs ins from various countries just formed part of my assessment of the history of the account, it was also worth noting that all game play was fairly static, but the country variations only applied to web log ins.

It was a contextual observation, and I probably should have used the word 'unusual' rather then 'suspicious' - apologies if I unnerved any VPN users, sleep easy and 'Scape on, your use of VPN is not a concern :)

Comment

Just to clarify the VPN point - there is no issue at all with people using VPN's, and of course people do go on vacation, relocate for college, move home etc. - I was not trying to imply that these sort of moves cause us any concern.

When reviewing this case, the extensive logs ins from various countries just formed part of my assessment of the history of the account, it was also worth noting that all game play was fairly static, but the country variations only applied to web log ins.

It was a contextual observation, and I probably should have used the word 'unusual' rather then 'suspicious' - apologies if I unnerved any VPN users, sleep easy and 'Scape on, your use of VPN is not a concern :)

Comment

Originally posted by TheAdamena

Needing to get a bunch of upvotes on Reddit to get an actual response from the support team? Big yikes from me.

Would you prefer we just ignored it? The user did contact support in the recommended way and we dealt with it in 19 minutes.

Comment

Originally posted by FeI0n

This is pure speculation, But the appeal that looks like the owner was probably sent from a reverse proxy. Identical IP as owners + email clearly owned by a hijacker or someone who buys stolen accounts in volume, telling us the owner is likely infected with a rat. Anyone with sense who cared about their account enough to make a reddit post wouldn't be stupid enough to recover it to an email they knew would be scrutinized and they apparently had 43 accounts on in the past.

My bet would be the hacker sends appeals using the victims IP to confirm recovery information before attempting to sell an account.

That is possible, if they also have a lot of info about the account. That is why I used a mixed voice in my comment, and stopped short of blatantly calling it.

Comment

I'm sorry to hear you've had this experience, the wealth that has been removed is not lost on me and I do genuinely appreciate the impact of this hijacking.

That said, there is significant evidence that you have been lapse with your account security. For a start, there have been web log ins on your account from 9 various different countries going back to at least 2015. These log ins cross over a number of password changes by the account owner, so it's not a simple case of one password being known, even when the owner changes the pass other countries are still logging in. You could be well travelled, or have a habit of using various VPN's on web access only - but I have to say it looks suspicious.

When you were 'hijacked' the 'hijacker' knew your log in and password, they also knew your recovery email address and the password for that and any 2FA you had on the email address. The account wasn't a malicious recovery via Jagex, the hijacker simply knew the details.

... Read more
Comment

Originally posted by PewPewPokemon

What does ' The dragon hasta (KP) is no longer tradeable.' mean?

You can't trade Dragon hastae that have been poisoned using Karambwan paste


24 Jan

Comment

I swear every time I fix a bug like this with player kit another one pops up with a random combination of items :(

Comment

Originally posted by SyncingShiip

Does this mean we can kill them damn splashers on rats or does it only apply to other players?

Splashing rats in a PvP zone is not safe

Comment

Hey there,

Mod Kelvin from Player Experience here. It seems like there’s a bit of confusion going on regarding your account. No worries, I’ll do my best to clear this up!

I can see that your account was accessed by a third party, following which it was banned. It looks like you then regained access to your account (good to see!) and attempted to appeal the ban. However, in your original ban appeal, you didn’t supply the right information for the account in question, which resulted in a response from us explaining that your ban appeal didn’t lead to an existing account with a ban:

'You're receiving this email as you've recently tried to appeal a ban, however the information you've provided doesn't link to a RuneScape account that has been banned.'

It seems you may have misunderstood this and thought that the account you’d regained access to didn’t have a ban. It seems like a simple confusion regarding the wording in the email. 😊 I can see tha...

Read more
Comment

Originally posted by jesse1412

I assume this doesn't change boxing on npcs?

Correct :) only combat vs other players

Comment

Originally posted by SippinWindex

Overlapping clicks on the minimap orb no longer also count as clicking on the minimap.

Biggest QoL update. Nothing tilted me more than constantly opening and closing and reopening the map just to start running again.

I'm very happy to see this one too

Comment

Originally posted by Hankpwnz

Was just trolling friend :hug:

Appreciate all the hard work

Hard to tell sometimes

Comment

Originally posted by Hankpwnz

Yikes. $11 and our update rotated the spade, fixed anti santa panties and corrected poor grammar.

Sick game

I'm sorry to hear you're not happy with the update. We feel it's important to clean up these little things from time to time and now seemed appropriate with the first big launch of the year just behind us and lots of things ahead.

Comment

Originally posted by borky__

hey /u/jagexgambit can we please find out what the f**k is going on with aus servers your maintenance TRIPLED THE f**kING PING and nobody has said a single f**king word as to what's going on.

thanks

We're looking into it