Jump to content
  • Sign Up

Exitlag and other VPN


Recommended Posts

Seeing a lot of Locked account posts spring up recently due to people just using a VPN to lower their ping from being in other countries.

One of the most popular ones is Exitlag. Most of the OCX players I know use it. A VPN is basically a necessity at this point for any OCX player to enjoy this game properly. Whatever security checks are in place need to be looked at. I'm sure support is already sick of getting these tickets and their time could be better utilized with more serious matters.

  • Like 1
  • Thanks 2
Link to comment
Share on other sites

@"Vegeta.2563" said:Seeing a lot of Locked account posts spring up recently due to people just using a VPN to lower their ping from being in other countries.

One of the most popular ones is Exitlag. Most of the OCX players I know use it. A VPN is basically a necessity at this point for any OCX player to enjoy this game properly. Whatever security checks are in place need to be looked at. I'm sure support is already sick of getting these tickets and their time could be better utilized with more serious matters.

the error 3023 (account blocked due to getting caught in security sweep) is really a random thing as long as you made your account (and bought your expansions) from your country --> then logging in from another country or another IP address can trigger it.

my suggestion is to not try switching servers/nodes often and just stick to one that works and has the best ping for you in your VPN but even then you still risk getting "soft-banned" and having to contact support to unlock it -- i use a paid VPN that isnt made for gaming but more for privacy (Mullvad) used only 1 location/node and i still got hit by the block back in 2019.

ever since then i just used my actual IP just to play gw2, everything else i do goes through the VPN

Link to comment
Share on other sites

@Astyrah.4015 said:

@"Vegeta.2563" said:Seeing a lot of Locked account posts spring up recently due to people just using a VPN to lower their ping from being in other countries.

One of the most popular ones is Exitlag. Most of the OCX players I know use it. A VPN is basically a necessity at this point for any OCX player to enjoy this game properly. Whatever security checks are in place need to be looked at. I'm sure support is already sick of getting these tickets and their time could be better utilized with more serious matters.

the error 3023 (account blocked due to getting caught in security sweep) is really a random thing as long as you made your account (and bought your expansions) from your country --> then logging in from another country or another IP address can trigger it.

my suggestion is to not try switching servers/nodes often and just stick to one that works and has the best ping for you in your VPN but even then you still risk getting "soft-banned" and having to contact support to unlock it -- i use a paid VPN that isnt made for gaming but more for privacy (Mullvad) used only 1 location/node and i still got hit by the block back in 2019.

ever since then i just used my actual IP just to play gw2, everything else i do goes through the VPN

The problem is routing from Australia is a hit or miss. Sometimes Ashburne1 has better connection than 2 or 3, and sometimes it doesn't. However accounts with 2FA attached to the them have to allow the use of those IPs to access. Normally locking accounts cuz an unwanted IP address got into the account would be perfectly fine, but the fact that accounts with 2FA are getting locked is a poor design in place.

  • Like 1
Link to comment
Share on other sites

@Vegeta.2563 said:The problem is routing from Australia is a hit or miss. Sometimes Ashburne1 has better connection than 2 or 3, and sometimes it doesn't. However accounts with 2FA attached to the them have to allow the use of those IPs to access. Normally locking accounts cuz an unwanted IP address got into the account would be perfectly fine, but the fact that accounts with 2FA are getting locked is a poor design in place.

exactly! the only time you should get a 3023 error or get your account temporary blocked is if you fail the 2 factor authentication (either the email or sms code).

that's what the system for is anyway but the fact that some people suffer even if they confirm account security is just bad design to be honest.

  • Like 2
Link to comment
Share on other sites

I'm on NordVPN about 2 weeks in, since my game had been unplayable since the Exalted vendor drop (getting ping spikes at 4000ms and hitting contant 500-800ms). I received the notification this morning that my account had been blocked for security purposes. Had dropped a tix to support about the block.

This softblock design needs a serious relook at given that some players legitly require VPN in order to play. My problem with this is that the game HAD been playable at 270ms for me before the Exalted drop and was not constantly spammed with Error 42, and it is intermittent in timing when it happens.

  • Like 1
Link to comment
Share on other sites

  • 1 month later...
  • 2 months later...
  • 1 month later...

And this is like the most stupid thing. No one should be automatically permabanned for using VPN. People have 2FA and stuff, just verify them via SMS and email.

It is almost mandatory to use VPN in 2021 if you want to secure yourself online and it should not be punished by botched scripts.

  • Like 3
Link to comment
Share on other sites

My account was blocked for security purposes and I do use Exitlag to connect to NA from China.

 

In the support ticket, the CS team said my password has been compromised and a third party have gained access to my account and asked me to add 2FA.

 

The issue is my password takes 2 million years to crack (security.org), I already have 2FA AND I use Dashlane premium to generate passwords.

 

Edit: I wrote to Exitlag about the issue and their response was hilarious.

 

"I'm Anderson from ExitLag support team.

You are the first person to notify this issue.

We provide for several users of the same game, if it was a general problem, we would be aware"

 

P.s. I work in the cybersec field.

Edited by codedbykush.2019
  • Like 2
  • Confused 1
Link to comment
Share on other sites

3 hours ago, codedbykush.2019 said:

My account was blocked for security purposes and I do use Exitlag to connect to NA from China.

 

In the support ticket, the CS team said my password has been compromised and a third party have gained access to my account and asked me to add 2FA.

 

The issue is my password takes 2 million years to crack (security.org), I already have 2FA AND I use Dashlane premium to generate passwords.

 

Edit: I wrote to Exitlag about the issue and their response was hilarious.

 

"I'm Anderson from ExitLag support team.

You are the first person to notify this issue.

We provide for several users of the same game, if it was a general problem, we would be aware"

 

P.s. I work in the cybersec field.

Ooo..see if that website you checked your password on stores the passwords it could very well be broken.

 

Regardless a botched script shouldnt be banning folks using a vpn. Use the verification to make sure its them and call it a day. Bans shouldnt be left up to a script anyways. 😕

  • Like 1
  • Thanks 2
Link to comment
Share on other sites

3 hours ago, codedbykush.2019 said:

My account was blocked for security purposes and I do use Exitlag to connect to NA from China.

 

In the support ticket, the CS team said my password has been compromised and a third party have gained access to my account and asked me to add 2FA.

 

The issue is my password takes 2 million years to crack (security.org), I already have 2FA AND I use Dashlane premium to generate passwords.

 

Edit: I wrote to Exitlag about the issue and their response was hilarious.

 

"I'm Anderson from ExitLag support team.

You are the first person to notify this issue.

We provide for several users of the same game, if it was a general problem, we would be aware"

 

P.s. I work in the cybersec field.

 

Probably because not many GW2 players report it to ExitLag VPN support as the problem lies with ArenaNet, not with the VPN itself.

  • Like 3
Link to comment
Share on other sites

20 minutes ago, TheQuickFox.3826 said:

 

Probably because not many GW2 players report it to ExitLag VPN support as the problem lies with ArenaNet, not with the VPN itself.

I can see two issues.

 

1. IPs used by Exitlag might get flagged for various reasons including spam, fraud, etc.

 

2. Guild Wars 2 security sweep aren't properly set for the use of gaming data tunneling.

  • Haha 2
Link to comment
Share on other sites

35 minutes ago, Dante.1763 said:

Ooo..see if that website you checked your password on stores the passwords it could very well be broken.

 

Regardless a botched script shouldnt be banning folks using a vpn. Use the verification to make sure its them and call it a day. Bans shouldnt be left up to a script anyways. 😕

Well, I didn't type in my exact password, I use typed something in a similar pattern.

 

I'm a bit smarter than to not to trust any online service.

 

I understand what you meant.

Edited by codedbykush.2019
  • Haha 2
Link to comment
Share on other sites

3 hours ago, codedbykush.2019 said:

My account was blocked for security purposes and I do use Exitlag to connect to NA from China.

 

In the support ticket, the CS team said my password has been compromised and a third party have gained access to my account and asked me to add 2FA.

 

The issue is my password takes 2 million years to crack (security.org), I already have 2FA AND I use Dashlane premium to generate passwords.

 

Edit: I wrote to Exitlag about the issue and their response was hilarious.

 

"I'm Anderson from ExitLag support team.

You are the first person to notify this issue.

We provide for several users of the same game, if it was a general problem, we would be aware"

 

P.s. I work in the cybersec field.

 

Oh boy...

 

Your password will not take 2 million years to crack. You need to understand that means nothing and that the website is just using a basic entropy hash based on an exhaustive search space. Because of this, you just let everyone know your password is at least 13 characters in length, knowing this would drastically reduce the search space and as such time needed to brute force. You also told everyone you use Dashlane for this, and unless they have changed their algorithm for generators it can't use dictionary words, meaning those can also be removed from the tables even further reducing the total search space. However again, none of this means anything and the page tells you nothing about total search space size, entropy, or even hash rate they are using to come up with these numbers. They are search space calculators, they are not password strength indicators.

 

Account hacking is done by lowest hanging fruit, the only time someone is going to waste time with brute force are state actors etc and are targeted attacks. People stealing game accounts etc are just buying password/user lists that are scraped or stolen by other methods. They will then often run those lists with mutations across all the user accounts.

 

If someone did find out your password, even with 2FA doesn't mean your account wont be locked after so many tries and fails, if you are in the "cybersec field" you should know this.

 

Your account has a network link, meaning you can link your account to the IP of the VPN server you connect to, this way it will know it is you and not someone from outside the country etc trying to log into your account. If you are just using the VPN on auto and letting it connect to whatever random node it wants, you should know this is going to happen, and you should be glad those things are in place.

  • Like 5
  • Haha 1
Link to comment
Share on other sites

22 minutes ago, TinkTinkPOOF.9201 said:

 

Oh boy...

 

Your password will not take 2 million years to crack. You need to understand that means nothing and that the website is just using a basic entropy hash based on an exhaustive search space. Because of this, you just let everyone know your password is at least 13 characters in length, knowing this would drastically reduce the search space and as such time needed to brute force. You also told everyone you use Dashlane for this, and unless they have changed their algorithm for generators it can't use dictionary words, meaning those can also be removed from the tables even further reducing the total search space. However again, none of this means anything and the page tells you nothing about total search space size, entropy, or even hash rate they are using to come up with these numbers. They are search space calculators, they are not password strength indicators.

 

Account hacking is done by lowest hanging fruit, the only time someone is going to waste time with brute force are state actors etc and are targeted attacks. People stealing game accounts etc are just buying password/user lists that are scraped or stolen by other methods. They will then often run those lists with mutations across all the user accounts.

 

If someone did find out your password, even with 2FA doesn't mean your account wont be locked after so many tries and fails, if you are in the "cybersec field" you should know this.

 

Your account has a network link, meaning you can link your account to the IP of the VPN server you connect to, this way it will know it is you and not someone from outside the country etc trying to log into your account. If you are just using the VPN on auto and letting it connect to whatever random node it wants, you should know this is going to happen, and you should be glad those things are in place.

 

You have made a lot of assumptions about how I checked my password strength, how the gamer data packet tunnel works and my area of expertise. Some of the subject matter you're trying to discuss are decades old and pretty basic.

 

That's all I can say on a gaming forum.

 

  • Haha 2
  • Confused 1
Link to comment
Share on other sites

6 hours ago, codedbykush.2019 said:

My account was blocked for security purposes and I do use Exitlag to connect to NA from China.

 

In the support ticket, the CS team said my password has been compromised and a third party have gained access to my account and asked me to add 2FA.

 

The issue is my password takes 2 million years to crack (security.org), I already have 2FA AND I use Dashlane premium to generate passwords.

 

Edit: I wrote to Exitlag about the issue and their response was hilarious.

 

"I'm Anderson from ExitLag support team.

You are the first person to notify this issue.

We provide for several users of the same game, if it was a general problem, we would be aware"

 

P.s. I work in the cybersec field.

Highly unlikely had anything to do with Exitlag 🤣

 

  • Like 4
Link to comment
Share on other sites

6 minutes ago, codedbykush.2019 said:

 

You have made a lot of assumptions about how I checked my password strength, how the gamer data packet tunnel works and my area of expertise. Some of the subject matter you're trying to discuss are decades old and pretty basic.

 

That's all I can say on a gaming forum.

 

 

You stated them in your posts, I made no assumptions, unless you were lying.

 

What I talked about had nothing to do with any network traffic and only pertained to cryptography.

 

The subject matter I am talking about is the core of the issue of passwords. Rather than counter anything I stated with factual information, you just make generic statements based on your assertion that it's "old and basic", that isn't a rebuttal.

 

"That's all I can say on a gaming forum"....."gamer data packet tunnel" buzz word salad. It's a VPN, they have peering agreements with carriers to use nodes with lower latency over bandwidth often by means of MPLS , it's a QoS with a bias to specific games and latency that uses labels and paths rather than end point destinations with node to node calculated routing tables.

  • Like 5
Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...