Add level cap to events

I shared all of the instances of hacking brought up in here with the team and they looked over them! Its hard to break it down for each item since every vulnerability is a bit different but in general we’re migrating more things to server validation which should help resolve a lot of these issues. Since a lot of these issues have to do with core networking code we’ll migrate them into server validation bits at a time.

So this won’t be a fix where we hit everything at once, but the higher priority systems where more damage can be done by bad actors will be migrated first. I believe some of that work will be shipping before the end of the year but I don’t want to say which of the issues it will impact in case the bad actors are monitoring this thread.

I’ll bring up the level requirement for events request as well but usually we like to avoid patchwork solutions like that which would negatively impact a huge number of innocent players. In this case lower level players, who haven’t done anything wrong, just to keep a very low number of hackers out. The real solution is to harden all of these systems against hacks rather than giving the community the means to exclude wide swaths of players from their events. In which case the most dedicated hackers might get around anyway by leveling up accounts quickly or stealing accounts from those with very insecure passwords and no 2FA. (related - everyone here should turn on their 2FA)

As I see updates internally about these security updates shipping I’ll try to post back in here to update everyone. Also reminder that our next Creator AMA is on Wed Nov 6th so if you want an update there plz ensure its a top liked / upvoted question for us here. If it is maybe I can talk someone from the security team into showing up to give a more detailed reply.

3 Likes