Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Nexon's latest privacy transgression
#1
After yesterday's update, I took a closer look at the MapleStory client, as I usually do. This time, however, I noticed an anomaly: After connecting to a channel server, the client sends huge chunks of data (several kilobytes) to the server. While it is normal that there is much traffic directly after the connection was established, it's usually the server that sends much information (character data, keymaps, and all kinds of other things) to the client.

I took a closer look at the data being sent and found this:
http://pastebin.com/1hwVj0ma

The client sends a list with the paths of ALL running processes to the server. They split the list into several packets that are sized around 2000 bytes, and depending on your system configuration, about 5-6 such packets are sent. I find this highly intrusive - technically it's none of Nexon's business what kind of software I am running on my system. I'm fine with local checks (like HackShield's), but sending everything to the server, where they quite possibly save it, is a wholly different matter. Sadly, their Privacy Policy allows them to do just this - true to the motto "If you play our game we are allowed to log everything that takes place on your computer."

You might think HackShield has always done this - it has not. While it is true that HS collects the same kind of information (and more), they just store it in their encrypted log files. Nothing of it is sent anywhere, unless you use their AhnReport utility.

If you're interested in some technical information, here's what I collected:
 Spoiler

They want to achieve two things:
1) Find out if the game executable (not its memory!) has been tampered with. This is only the case when the client has been unpacked, and only few people are able to do this nowadays.
2) Find out if malicious processes are being executed, for example trainers.

In the end it's just another failed measure in an endless row of useless security checks. It's a piece of cake for both target groups to disable/fake this data, so there's only one victim: The players, because their privacy is compromised. Maybe they'll reconsider sending these packets when enough people complain.


Messages In This Thread
Nexon's latest privacy transgression - by TheHiddenOne - 2013-09-06, 02:41 PM
Nexon's latest privacy transgression - by LeoDirk - 2013-09-06, 02:53 PM
Nexon's latest privacy transgression - by Tyler - 2013-09-06, 02:54 PM
Nexon's latest privacy transgression - by LeoDirk - 2013-09-06, 03:02 PM
Nexon's latest privacy transgression - by LeoDirk - 2013-09-06, 03:19 PM
Nexon's latest privacy transgression - by Mazz - 2013-09-06, 04:59 PM
Nexon's latest privacy transgression - by Zelkova - 2013-09-06, 05:06 PM
Nexon's latest privacy transgression - by Niernen - 2013-09-06, 05:21 PM
Nexon's latest privacy transgression - by Zerard - 2013-09-06, 05:26 PM
Nexon's latest privacy transgression - by Zelkova - 2013-09-06, 05:28 PM
Nexon's latest privacy transgression - by Netto - 2013-09-06, 05:33 PM
Nexon's latest privacy transgression - by dowie - 2013-09-06, 06:06 PM

Forum Jump:


Users browsing this thread: