Results 1 to 9 of 9

Thread: Security Warning Regarding the Neopets Mobile App

  1. #1
    *squeak*
    Bat's Avatar
    Joined
    Nov 2012
    Posts
    4,040
    Userbars
    152
    Thanks
    2,147
    Thanked
    46,694/3,563
    DL/UL
    34/1
    Mentioned
    1,769 times
    Time Online
    644d 1h 41m
    Avg. Time Online
    3h 41m

    Security Warning Regarding the Neopets Mobile App

    In light of recent alleged "wifi hacking" incidents involving Neopets accounts, I took a look at the code for the NeoExplorer (Neopets Mobile) app to see if the Neopets team did anything to address security issues. Unfortunately, the app has the same holes that the website itself has - it communicates using plain old-fashioned HTTP, without any protection for your account's cookies or credentials.

    Since many of us are going to be using the Neopets Mobile app on our phones and tablets, we will likely be taking those devices out from the protection of our home wifi and into the dangerously unpredictable wireless networks of our everyday lives. Please exercise caution when using Neopets Mobile in caf�s, coffee shops, offices, restaurants, stores and so on. The Neopets team has not seen fit to protect your account, or your username and password from being stolen when you're using this app, and you never know if someone might be out there running packet captures!



    Ha! Thanks, @(you need an account to see links). I should've summarized.

    In conclusion: don't use the app when you're on public wifi. It's not safe. Use cellular data or home wifi only!
    Last edited by Bat; 01-21-2019 at 02:57 PM.

  2. The Following 45 Users Say Thank You to Bat For This Useful Post:

    Alcremie (01-21-2019),Bioluminescence (01-21-2019),Blue-tooth (01-21-2019),Bridge (01-21-2019),Corliss (01-21-2019),Delibird (01-21-2019),Doge (01-21-2019),Erik. (01-21-2019),Fell (01-21-2019),Fiore (01-21-2019),Fishbox (01-21-2019),Forever (01-21-2019),Gato (01-21-2019),genesis (01-21-2019),Goddammit (01-21-2019),Gremlin (01-21-2019),Harle (01-21-2019),Him (01-21-2019),♥ Hydrapple ♥ (01-21-2019),I_royalty_I (01-23-2019),j03 (01-21-2019),kadoatie (01-22-2019),kior (01-21-2019),Meepit (01-23-2019),melbenoist (01-23-2019),Menine (01-21-2019),Midas (01-21-2019),Misha (01-21-2019),Phelsuma (01-21-2019),Pinecone (01-21-2019),♥ PrettySarcastic ♥ (01-21-2019),Purrina (01-29-2019),pururun (01-21-2019),rainbeaux (01-21-2019),Rosie (01-21-2019),Sakuras (01-21-2019),shadowcat (01-21-2019),Sharkie (01-23-2019),Shiro (01-21-2019),Stardew (01-21-2019),Stardust (01-26-2019),Styx (01-21-2019),Synth Salazzle (01-23-2019),TimeLord (01-21-2019),Yikiru (01-21-2019)

  3. #2
    Saiyan Race
    j03's Avatar
    Joined
    Dec 2011
    Posts
    13,756
    Userbars
    176
    Thanks
    5,936
    Thanked
    33,185/6,626
    DL/UL
    23/36
    Mentioned
    3,871 times
    Time Online
    564d 11h 59m
    Avg. Time Online
    3h 12m
    TL;DR - Don't use the app outside of your home wifi unless you have cellular data.


    Sent from my iPhone using Tapatalk
    (you need an account to see links)
    (you need an account to see links)(you need an account to see links)

    ------------------------
    [02/24/2013] Stealth CORE is made into the first standalone Neopets auto-player.
    ------------------------


  4. The Following 13 Users Say Thank You to j03 For This Useful Post:

    Blue-tooth (01-21-2019),Delibird (01-21-2019),Gremlin (01-21-2019),loserchild (01-21-2019),melbenoist (01-23-2019),motherfucker (01-21-2019),punkie (01-21-2019),Purrina (01-29-2019),rainbeaux (01-21-2019),Stardew (01-21-2019),Stardust (01-26-2019),Synth Salazzle (01-23-2019),TimeLord (01-21-2019)

  5. #3
    Mardan's Avatar
    Joined
    Oct 2018
    Posts
    71
    Userbars
    1
    Thanks
    4
    Thanked
    34/14
    DL/UL
    4/0
    Mentioned
    1 time
    Time Online
    1d 16h 1m
    Avg. Time Online
    1m
    I'm mystified by how they keep doing this.
    Not using https is pretty much a web2.0 practice.

  6. #4
    *hair toss*
    Flordibel's Avatar
    Joined
    Jun 2017
    Posts
    2,394
    Pronouns
    She/they
    Userbars
    82
    Thanks
    2,907
    Thanked
    9,606/1,916
    DL/UL
    58/0
    Mentioned
    402 times
    Time Online
    82d 2h 31m
    Avg. Time Online
    47m
    Thanks for the heads-up!

  7. #5
    Crazy Cat Lady PrettySarcastic's Avatar
    Joined
    Jun 2015
    Posts
    2,205
    Pronouns
    she/her
    Userbars
    56
    Thanks
    4,494
    Thanked
    6,592/1,484
    DL/UL
    47/0
    Mentioned
    392 times
    Time Online
    163d 21h 6m
    Avg. Time Online
    1h 12m
    The security practices of this company are atrocious. The last thing they need is another database breach, and the lack of care they are taking really doesn't give me faith such a thing is impossible.

    Thanks for the heads up. <3




    graphics by Flordibel & Menine <3

  8. The Following 2 Users Say Thank You to PrettySarcastic For This Useful Post:

    Bioluminescence (01-23-2019),Styx (01-21-2019)

  9. #6
    k80's Avatar
    Joined
    May 2014
    Posts
    664
    Userbars
    8
    Thanks
    145
    Thanked
    360/175
    DL/UL
    4/0
    Mentioned
    55 times
    Time Online
    22d 2h 27m
    Avg. Time Online
    8m
    Ugh this company, I swear.

    Non-tech person here; Is it difficult to switch an older site/DB like Neo to https or just laziness? I've gotten the feeling that the entire site is just a big patchwork quilt of old code ready to fall apart if you look at it wrong. And a tiny skeleton crew to repair it if it does. Breaks my heart. I love Neo but it gets very frustrating.

  10. #7
    *squeak*
    Bat's Avatar
    Joined
    Nov 2012
    Posts
    4,040
    Userbars
    152
    Thanks
    2,147
    Thanked
    46,694/3,563
    DL/UL
    34/1
    Mentioned
    1,769 times
    Time Online
    644d 1h 41m
    Avg. Time Online
    3h 41m
    Quote Originally Posted by k80 View Post
    Ugh this company, I swear.

    Non-tech person here; Is it difficult to switch an older site/DB like Neo to https or just laziness? I've gotten the feeling that the entire site is just a big patchwork quilt of old code ready to fall apart if you look at it wrong. And a tiny skeleton crew to repair it if it does. Breaks my heart. I love Neo but it gets very frustrating.
    It could be done, but it won't be easy, and will probably damage the Neopets experience for some time.

    There area considerable amount of flash files, forms, images, links, scripts, stylesheets and XHR requests on the site that would have to be checked after a changeover like that. The JSON or XML responses from XHR requests as well as pages resulting from clicked links or form submissions may also need a bit of reprogramming if the Neopets team validates whole referer addresses instead of just the path after the host name. There may also be addresses for external resources hard-coded into flash animations and games, which will require those flash files to be recompiled after changing. Each of the apps they've released for phones and tablets would need new compilations due to address changes as well - there are hard-coded http addresses all over the place in those!

  11. The Following User Says Thank You to Bat For This Useful Post:

    k80 (01-30-2019)

  12. #8
    *hair toss*
    Flordibel's Avatar
    Joined
    Jun 2017
    Posts
    2,394
    Pronouns
    She/they
    Userbars
    82
    Thanks
    2,907
    Thanked
    9,606/1,916
    DL/UL
    58/0
    Mentioned
    402 times
    Time Online
    82d 2h 31m
    Avg. Time Online
    47m
    Is it standard practice to hard-code http or https nowadays?

  13. #9
    *squeak*
    Bat's Avatar
    Joined
    Nov 2012
    Posts
    4,040
    Userbars
    152
    Thanks
    2,147
    Thanked
    46,694/3,563
    DL/UL
    34/1
    Mentioned
    1,769 times
    Time Online
    644d 1h 41m
    Avg. Time Online
    3h 41m
    Quote Originally Posted by Demeter View Post
    Is it standard practice to hard-code http or https nowadays?
    Standard practice should be to future-proof your solution as much as possible, otherwise you end up in the same predicament that Neopets is currently faced with. It may have been excusable to some in the 2000s, but having ignored the need for https after all this time is just irresponsible, and as @(you need an account to see links) put it - lazy.

  14. The Following 4 Users Say Thank You to Bat For This Useful Post:

    Corliss (01-23-2019),Flordibel (01-23-2019),Stardust (01-26-2019),Styx (01-23-2019)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •