2011-09-06, 07:06 AM
I have no idea how NEXON's internal infrastructure is set up, so I'm just going to be going out on a limb here, but, do you think they could have gotten access to a password hash database? I know some setups use those...basically, that would enable them to "bruteforce" a huge list of hashes and combine matches for optimum results. If their bruteforcing is based on the old 12 character system, that wouldn't be hard at all to get hundreds of matches a day. Which, on that same token, if someone were to update to a 13^ character password, it would render their script useless on those accounts. A small chance, but anything to reduce a chance of getting hacked is better than nothing, right? And it's not like NEXON is going to publicize the exploit after they fix it, so we never will know what actually happened unless the people with the script tell us.

