Results 1 to 7 of 7

Thread: Security Flaw?????

  1. #1
    Fresh Spawn
    Join Date
    May 2014
    Posts
    8

    Security Flaw?????

    Someone is using my game centre to access my game.Changed my Apple ID/ passwords/ security questions but they still have access to my game centre?

    What's the point in having an Apple ID if u don't need to log in after you used the village once on your device once?
    I can sign out of game centre and still log into my village without entering my appleId/game centre account...

    when you load clash of clans all and are promoted to log into game centre, all you need to do is hit "cancel" and then you still have full access to the village!!! Surely this shouldn't be allowed?

    I hate the fact supercell are saying "game misuse" is an apple issue when clearly it's a flaw in the game!

    i have posted this in new ideas forum because I think if you are logged out of game centre you should need to log back into game centre before accessing the village again
    Attached Images Attached Images

  2. #2
    Pro Member ragerrodent's Avatar
    Join Date
    Jan 2014
    Posts
    573
    This idea would work for some people but not for all. I for instance play on my moms ipad. It's her game center account and her password. I don't know it so I wouldn't be able to play unless I got her to log me in every stinking time which is more than 20 times a day generally.
    Elder of clan: Xristos Kingdom; In-game name: Ragerrodent
    Lvl. 110
    TH 10
    Max trophy count: 2854 "Nobody's invincible...I start to crack at about 400 to 1"

  3. #3
    Fresh Spawn
    Join Date
    May 2014
    Posts
    8
    I wouldn't say log in every time just once with the correct username and password. If settings->game centre-> Apple ID and password aren't correct! then you should be able to play the game and edit the village.

  4. #4
    He who has not yet claimed his title dahimi's Avatar
    Join Date
    Sep 2012
    Location
    Hello Kitty Adventure Island
    Posts
    10,807
    The problem is game center is not required. Basically when you create a village, it creates a key which is used to authenticate your game with the server to link your village to the device.

    This key is always stored on your device, but if you use game center a copy is stored there also.

    One solution that someone has already suggested is that they could require a pin to be entered before the village could be played. I could see that being a major source of a wide range of issues though.

  5. #5
    Senior Member
    Join Date
    Feb 2014
    Location
    Kindersley, Canada
    Posts
    284
    Make the pin an option then. Whoever wants it can have it. Just like a "collect all" resources button

  6. #6
    Forum Superstar Ytiev's Avatar
    Join Date
    Jan 2014
    Location
    Call me Ytiev
    Posts
    3,498
    Quote Originally Posted by Scottsms View Post
    Someone is using my game centre to access my game.Changed my Apple ID/ passwords/ security questions but they still have access to my game centre?

    What's the point in having an Apple ID if u don't need to log in after you used the village once on your device once?
    I can sign out of game centre and still log into my village without entering my appleId/game centre account...

    when you load clash of clans all and are promoted to log into game centre, all you need to do is hit "cancel" and then you still have full access to the village!!! Surely this shouldn't be allowed?

    I hate the fact supercell are saying "game misuse" is an apple issue when clearly it's a flaw in the game!

    i have posted this in new ideas forum because I think if you are logged out of game centre you should need to log back into game centre before accessing the village again
    1: It's not SC's problem it's yours or Apple
    2:read this
    Supercell only supports one account per device. Apple considers an iOS device to be a single user device. If a village is authorized to it (either by starting a game, or loading it via gamecenter) it is permanently authorized to that device. The Gamecenter password is only needed the very first time you load the game. Once a device "Owns" the game, changing the Gamecenter password, logging out of gamecenter, even deleting the app doesn't remove your game from that device. If you sell or trade your iOS device, doing a factory reset is the only way to ensure the next user can not play your game. If you authorize your game to someone else's device, even a factory reset may not remove it, as they can do an iCloud or iTunes backup/restore of their device to include your village.

    Gamecenter in relation to Clash of Clans is designed to attach YOUR village from YOUR device to allow you to move YOUR village to a new device YOU own. It is not an authentication method to log into and out of different devices, it's a transfer mechanism. You should never load your village onto a device you do not control. Once a village is loaded onto a device, it is permanently authorized and playable from there. Neither Apple, nor Supercell can remove a village from a device which was properly loaded at one point. It is not legally or technically possible. Once a device is authorized, the device can not be blocked or restricted.


    Morale of the story is NEVER load your village on a device not owned/controlled by you, allow someone else to log onto your device with a different Gamecenter, or give out your Gamecenter account info to anyone.


    So, knowing the above, 100% of the time folks claim to be h@cked, or someone is playing their game, it boils down to:


    A) a family member plays on the iOS device without you knowing it
    B) you gave your gamecenter password to a friend who used it to load your game
    C) you gave your gamecenter password to one of those 3rd party gem sites
    D) you logged onto a friends iOS device to play at one point, thinking logging out of gamecenter or deleting the app will prevent them from playing it (it doesn't)
    E) you sold/traded/gave away an iOS device you had once played the game on without doing a factory reset and they still have access to your CoC village.
    F) a friend logged in with a clean gamecenter answered the prompts and transferred your village to their GC, and loaded it on their device later (if your village wasn't attached to your own gamecenter)
    G) Someone sent you a "Free" account - while logging into this new gamecenter you actually transfer you village to this empty gamecenter account and they can then load it on their device. (If your village wasn't attached to your own gamecenter)


    If it's your little brother playing, it's easy to solve, if it's an ex-best friend who can now play your game, there are not a lot of options.

  7. #7
    Fresh Spawn
    Join Date
    May 2014
    Posts
    8
    I like the idea of using a pin.

    So if someone guesses your password or security info and has loaded the village to their device... There's nothing that can be done??

    I have spoke to apple supervisor over the phone and his only suggestion for now is to stay logged out of game centre and play the game (logged out) while he looks into it. But after reading
    " Neither Apple, nor Supercell can remove a village from a device which was properly loaded at one point. It is not legally or technically possible. Once a device is authorized, the device can not be blocked or restricted."
    I don't feel very confident about any support I may receive towards the issue.

    It's really annoying, I don't want to spend any more gems in the game, because this other person using my village keeps leaving my clan and I'm unable participate in clans wars or request troops.

    thanks for the reply ultradragonmaster, it's the best piece of info I've had yet other than "it's an apple problem, contact apple support"
    Last edited by Scottsms; May 22nd, 2014 at 06:56 AM.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •