Edit 4 (October 15): They finally admitted that it is an “issue with their security”. Change your password as soon as possible if you haven’t done so yet! No need to panic or anything. As far as we know (from the person who found the security breach), the passwords are hashed and potentially even salted. So they can’t just be copied and pasted! ;) Still, the issue still means that people did have access to your user information (user name, password, email address), so take it seriously enough and don’t sit on your old password just because you finally managed to memorise it. ;)
Yesterday, I stumbled over a post on the German subforum of the inofficial Lotro community (you can read everything without signing up, by the way!). You can find the thread here and a rough English translation here. All in all, it seems that there could be/could have been a security issue on the official Lotro forums. The forum database could have been “open” and granted access to usernames and passwords. The user who reported about it on the inofficial forums had apparently posted on the official forums prior to that but that posting got deleted. No reply from Turbine to him or to anybody else who asked about it.
Then yesterday evening (European time), the Lotro forums went down. Several hours later, we got one tweet about it: “The LOTRO Forums are currently unavailable. We do not have an ETA for their return at this time.”
The official forum tells us this: “The LOTRO Forums are currently down for maintenance. Thank you for your patience.
Please follow us on Twitter @LOTRO or like us on Facebook to receive updates during the maintenance.”
The thread on the inofficial forum has people saying that when they asked if they should change their passwords etc. on Lotro’s Facebook page, that the postings got deleted really fast. That’s weird, if you ask me. I also went to their Facebook page to get more information and oddly enough, I didn’t find any mentioning of the forums being offline at all. Not even mentioning of said forum maintenance. So the only message we’ve gotten so far is the one on the official forums directing us to Twitter and Facebook. And Twitter is the only of the two with at least one short message.
Security issue or not, that’s not a good way to inform your customers of what’s going on! I think it’s weird to take down the forums for maintenance and keep them offline without telling us when they could come back and, most importantly, without telling those worried about security issues that there’s nothing to worry about.
My advice would be to change your Lotro password soon. And if you’ve made the mistake of using your Lotro password on other websites/for other accounts as well: Change those as fast as possible! One shouldn’t have the same password for different accounts anyway. Who knows which site gets hacked next?
Edit: Just found this thread – again, German, sorry. It seems that the user “freundlich” who first wrote about the security issue had proof by posting user data (username, IP address, email address and password hash – Valandir says they’re salted) on the inofficial forum (which got deleted by the moderators). For now, everything points to a security issue.
Edit 2: Here’s a link for the Dutch-speaking Lotro players.
Edit 3: We finally got an update from Turbine: “We have identified a potential issue in the forum system. As a precautionary measure we have disabled our forums while we investigate. We will bring the forums back online when we complete our work. We thank you for your patience.”
Edit 4 (October 15): They finally admitted that it is an “issue with their security”. Change your password as soon as possible if you haven’t done so yet! No need to panic or anything. As far as we know (from the person who found the security breach), the passwords are hashed and potentially even salted. So they can’t just be copied and pasted! ;) Still, the issue still means that people did have access to your user information (user name, password, email address), so take it seriously enough and don’t sit on your old password just because you finally managed to memorise it. ;)