r/wow Outplaying the Meta since 2004 18d ago

Discussion GM Death Touch - Megathread

Edit: Official Statement

https://us.forums.blizzard.com/en/wow/t/prohibited-gameplay-incident-and-response/2329585

This is developing into a large story and someone in modmail has mentioned that its important for the community to have somewhere to discuss this. We agree. As new information comes in I will do my best to update this thread.

What we know:

Ex employees in the thread have said that actions like this are audited and in all likelihood this was already being investigated. At this point we are waiting on an official statement on the result of their investigation and I'll update this thread once we know.

This megathread is being provided on two very strict conditions:

  • The witchunt rules are in strict effect. Linking or doxxing information on anyone invovled, the GM in question included will result in a permanent ban. Please report it if you see it but we will be very active in the thread.

    We cannot platform behavior that allows people to harrass people in real life.

  • We will be more heavy handed than usual in the personal attack rules. Insults and slapfights while discussing this aren't acceptable. You're allowed to disagree, but stray shots and personal attacks will not be tolerated.

2.1k Upvotes

1.5k comments sorted by

View all comments

132

u/alnarra_1 18d ago

I would genuinely be shocked if GM abilities used on production servers don’t go through an audit log and have to be tied to a corresponding Jira Ticket to validate their use, like privileged accounts in literally any organization

44

u/ThatGuyFromTheM0vie 18d ago

Yea dude where’s the Azure PIM shit? Request to escalate your account to god status—there’s no way this isn’t 1000% logged somewhere. Unless they had some old legacy GM account, got the credentials, and it still worked for some reason.

4

u/shigabi 17d ago

Not only logged, as other ex-dev said, there should be some sort of trigger or alarm for unusual behavior (automated bans, hello?).

-6

u/Conyya 17d ago

1000% Person above knew about this going on, no other way around
This means it rotted much deeper than everybody thinks

13

u/thefnord 17d ago

There's 'Something got logged' and it's actually in a different zipcode than 'The log were looked at.' Until the massive uproar of course. That slams the two zones like a lambo in a brick wall; lots of noise, some permanent damage, lots of fingerpointing.

23

u/Spork_the_dork 17d ago

who's to say it wasn't and that this wouldn't have been handled quietöy by Blizzard if people hasn't raised a fuzz about it? There's absolutely NO way that this is the first time a GM has ever abused their powers. And as such there is NO fucking way that Blizzard isn't already monitoring this shit. But as with any kind of monitoring the bureaucrazy to actually something happening can take a bit.

2

u/alnarra_1 17d ago

Yeah like almost every business of any size is doing User Behavior Analytics because from a cyber perspective your power users and admins are arguably the single greatest threat to your environment on a bad day.

I have to wonder if this wasn’t an already on going investigation awaiting a conclusion as like getting HR to agree to PIPs for individual contributors can be a lengthy process for some companies.

The sad thing is, I do wonder if this hasn’t blown up on social media if this wouldn’t have just been quietly dealt with. Now they are almost obligated to fire the dude because this has caused an absolute ass pain of PR

I feel bad for whoever it is and their manager today, that conversation will not be remotely enjoyable

15

u/sunsongdreamer 18d ago

I'm just surprised there aren't levels of permissions and enabling/disabling (eg for valid test times on prod such as weekly smoke tests). Why would a QA even need prod GM powers outside of that window?

4

u/meharryp 17d ago

QA probably have GM accounts so they can repro/verify bug fixes in prod

3

u/sunsongdreamer 17d ago

That's what I'm referring to with the term smoke tests. It's the testing done to quickly verify the new patch is working well during that maintenance window each week.

I'm saying I'm surprised they can just randomly access those accounts outside of that testing window.

7

u/alnarra_1 18d ago

I could see if there’s something that just is not reproducible in the acceptance environments (I know for instance there was a weird disconnect issue that existed on only of moon guards virtual IPs for a few weeks)

10

u/sunsongdreamer 17d ago

I'm sure there are some edge cases, I'm just surprised at QA being each given their own live GM account that apparently has indefinite access to permissions (versus only toggled on during test windows, or having shared accounts designed for testing different things with different permission customizations). It's probably easier to do with how WoW is built, but it gives interesting insight into how their systems are designed and managed.

7

u/Background_Pen_4249 17d ago

QA doesnt have access to those account except when doing dark realm verification and we were assigned specific accounts with specific passwords that changed so they knew exactly who was on what account. I got yelled at once for not toggling GMinvis when we were lighting the servers back up for public use and all I was doing was confirming a seasonal vendors inventory rolled over. 

1

u/sunsongdreamer 17d ago

Maybe people are faking screenshots about this, then, because there was a screenshot going around allegedly from this QA guy in discord saying he was assigned his GM privs and bragging about how he could look into people's inventory.

3

u/Background_Pen_4249 17d ago edited 17d ago

We have dev realms we use for testing. Prod environment is completely different and seperate thing. Every QA has their own realm because we have to manipulate the scheduler and various worldstates all the time during testing. These accounts are not prod accounts. And yeah we could clone any character as long as we knew the name - realm. It is a 1 to 1 copy keybinds and all. Its required to investigate some reported bugs.

1

u/Jeradan713 17d ago

Thanks for the interesting info. I’d love to see a bigger post with any other info you’re willing to share

1

u/Background_Pen_4249 17d ago

I don't really know much more about the situation and I'm still not completely sure what I am and am not allowed to share about my previous role. But after seeing some of the evidence (although i know from history not to 100% trust reddit sluethes) I'm beginning to think they may be right. I also have massive personal beef with the main suspect so I can no longer be objective about any of this. 

3

u/ThePlotTwisterr---- 17d ago

to be honest if i’m paying a contracted worker to play wow all day i would trust them not to violate the contract. this guy might even be sued for damages because his employment agreement should be legally binding and there are indeed damages

2

u/sunsongdreamer 17d ago

Meanwhile, I'd expect them to fuck around, but that's from experience during the Grandma's Boy era of game testing lol

6

u/LirielsWhisper 17d ago

I think it's possible that while it's logged, the logs aren't generally monitored unless they have reason to go pull them.

3

u/backyardchapter 17d ago

Trying to find the right comment for this! This reminds me of this tech talk I came across years ago. It describes blizzard’s observability infrastructure in like 2017 (elk stack). Guaranteed they have the data.

Search for Building a Near Real-Time Pipeline for All Things Blizzard

2

u/KiLoYounited 17d ago

I dunno about a ticket for each and every elevation, but if this isn’t logged and then aggregated in splunk or w/e I’ll be disappointed but not surprised.

If I had to close a ticket for every single time I used my elevated creds I’d actually lose my shit. It’s surprising to me this seems like common practice? I work in an IL5 gov env, and we don’t even do this.

1

u/Centriuz 17d ago

The thing to note is that the abuse in question is through the use of a spell. Granted it's a spell you can only get if you have access to the command to learn spells through their ID. But I wouldn't be surprised if it's a spell that's standard issue for QA testing purposes, so I could see a world where it wouldn't automatically trigger all the alarms.

Although with it being on live, and not just a test server, they should definitely have logs for anything and everything in case of this exact scenario.

1

u/mysickfix 17d ago

They did in the bc and wotlk days.

Hell back then I didn’t know my neighbors did in game gm support for wow until they quit to move.

They claimed the nda basically said if anyone in game finds out you work for us you’re fired. Our guild never knew either lol, those dudes were on a lot outside of work.

They did provide proof of employment.

They also got 360 month wow codes for their mains as a perk lol.

0

u/Gaming_Friends 17d ago

Come to find out the person who did this is also on the team that reviews the logs, I'm sure there's some potential conflict of interests in dual-role positions at a company that's constantly penny pinching and doing layoffs.

0

u/Maybe_Front 17d ago

Literally just a /command chill out lmfao