Forum Breach

Post » Sat Aug 13, 2011 11:10 pm

But wouldn't that be common sense though?

First thing I did after I logged in was change my password from the one Bethesda sent me

It's certainly not as bad as sending the password you selected yourself, but it's still not a secure approach. The correct solution would have been to send a single-use URL. Unencrypted passwords should never be sent across an unsafe medium, especially when they are not explicitly marked as temporary, and especially after you've just suffered two breaches and know there are people hunting for your hide.
User avatar
vanuza
 
Posts: 3522
Joined: Fri Sep 22, 2006 11:14 pm

Post » Sat Aug 13, 2011 6:51 pm

On the bright side, even though the avatars are gone, the Bethesda Softworks logo under your name is still working!


Ah, thanks. When I saw everything just said "blahblahblah's photo", I though my internet was dead. XD
User avatar
Gavin boyce
 
Posts: 3436
Joined: Sat Jul 28, 2007 11:19 pm

Post » Sun Aug 14, 2011 3:36 am

:poke:


http://www.youtube.com/watch?v=rwp60eYuie0
User avatar
Klaire
 
Posts: 3405
Joined: Wed Sep 27, 2006 7:56 am

Post » Sat Aug 13, 2011 3:44 pm

Well, I can't remember which email I used for Johnny3Tears.
:facepalm:
User avatar
luis ortiz
 
Posts: 3355
Joined: Sun Oct 07, 2007 8:21 pm

Post » Sat Aug 13, 2011 5:54 pm

I feel naked without my Stealth Suit :sadvaultboy:
User avatar
Mandy Muir
 
Posts: 3307
Joined: Wed Jan 24, 2007 4:38 pm

Post » Sat Aug 13, 2011 7:25 pm

Only good thing to come out of this is that I finally set up keepass and changed all my passwords. *sigh* Now I have to use a stupid program to log in to the simplest of sites. I feel horribly dependent.
User avatar
Love iz not
 
Posts: 3377
Joined: Sat Aug 25, 2007 8:55 pm

Post » Sat Aug 13, 2011 12:39 pm

Oh god. My eye is gone. I can't see without my eye! I'm blind! Help! Ahhhh!

:ahhh:


Damn it man! Hold yourself together! Remember your other eye! Remember your other eye!
User avatar
Tamara Dost
 
Posts: 3445
Joined: Mon Mar 12, 2007 12:20 pm

Post » Sat Aug 13, 2011 7:28 pm

I miss Bill Murray. :)

I'm really glad Beth is very open about this. It's the right way to handle the situation.
User avatar
Lindsay Dunn
 
Posts: 3247
Joined: Sun Sep 10, 2006 9:34 am

Post » Sat Aug 13, 2011 4:36 pm

The Forum is breached!? MAN THE BATTLEMENTS! Mr Max_aka_NOBODY fire the torpedos! Mr Expresate I want the shields at full power! :toughninja:

This had better not have been another one of those "We're hacking you because we want more Skyrim information", "we're hacking you because the Skyrim CE price is too high" or god forbid, an attack by the fanatical Notch fans. Good thinking with wiping everyone's passwords for safety.
User avatar
Jose ordaz
 
Posts: 3552
Joined: Mon Aug 27, 2007 10:14 pm

Post » Sat Aug 13, 2011 5:04 pm

The Forum is breached!? MAN THE BATTLEMENTS! Mr Max_aka_NOBODY fire the torpedos! Mr Expresate I want the shields at full power! :toughninja:


You seem confused, are we on a spaceship or a castle?
User avatar
Christine Pane
 
Posts: 3306
Joined: Mon Apr 23, 2007 2:14 am

Post » Sat Aug 13, 2011 8:01 pm

You seem confused, are we on a spaceship or a castle?


Dont get me on technicalities of what science fiction technology goes with what thing. I havent had my morning coffee yet. :wacko:

And its sweeping duty for you Mr Turns-the-Page!
User avatar
Eddie Howe
 
Posts: 3448
Joined: Sat Jun 30, 2007 6:06 am

Post » Sat Aug 13, 2011 1:47 pm

You seem confused, are we on a spaceship or a castle?

My familiarity with Lego would lead me to conclude "both".
User avatar
Jason White
 
Posts: 3531
Joined: Fri Jul 27, 2007 12:54 pm

Post » Sat Aug 13, 2011 8:51 pm

I'm inclined to believe the attack was prompted by the legal threats that were issued towards Minecraft's creator... seems about right considering the timeline... or it could just be a random attack for the lulz.
User avatar
Ann Church
 
Posts: 3450
Joined: Sat Jul 29, 2006 7:41 pm

Post » Sat Aug 13, 2011 11:18 pm

I feel naked without my Stealth Suit :sadvaultboy:

:hubbahubba:
User avatar
Alexis Estrada
 
Posts: 3507
Joined: Tue Aug 29, 2006 6:22 pm

Post » Sun Aug 14, 2011 2:32 am

Good thinking with wiping everyone's passwords for safety.

I just hope they wiped properly. Could get messy otherwise.
User avatar
Spencey!
 
Posts: 3221
Joined: Thu Aug 17, 2006 12:18 am

Post » Sun Aug 14, 2011 2:58 am

I feel naked without my Stealth Suit :sadvaultboy:

http://www.youtube.com/watch?v=BKPoHgKcqag
User avatar
Bryanna Vacchiano
 
Posts: 3425
Joined: Wed Jan 31, 2007 9:54 pm

Post » Sun Aug 14, 2011 1:55 am

I hope we get avatars back soon, it is so difficult to tell who is who without them.
User avatar
Leilene Nessel
 
Posts: 3428
Joined: Sun Apr 15, 2007 2:11 am

Post » Sat Aug 13, 2011 12:26 pm

Dont get me on technicalities of what science fiction technology goes with what thing. I havent had my morning coffee yet. :wacko:

And its sweeping duty for you Mr Turns-the-Page!

Would that be sweeping the floor or a baryon sweep?
User avatar
Mrs shelly Sugarplum
 
Posts: 3440
Joined: Thu Jun 15, 2006 2:16 am

Post » Sat Aug 13, 2011 4:30 pm

I hope we get avatars back soon, it is so difficult to tell who is who without them.


I still see your avatar in my head. :P
User avatar
BrEezy Baby
 
Posts: 3478
Joined: Sun Mar 11, 2007 4:22 am

Post » Sat Aug 13, 2011 8:02 pm

I hope we get avatars back soon, it is so difficult to tell who is who without them.

I'm going to image you all as My Little Ponies. :teehee:
User avatar
ladyflames
 
Posts: 3355
Joined: Sat Nov 25, 2006 9:45 am

Post » Sat Aug 13, 2011 10:26 pm

My familiarity with Lego would lead me to conclude "both".


This is possible... in Minecraft!
User avatar
Timara White
 
Posts: 3464
Joined: Mon Aug 27, 2007 7:39 am

Post » Sun Aug 14, 2011 3:32 am

1. You mean I can't use {)RMTJH(PR[)Tg$VTY_M$+YVayta5yH&+%^}*TH&_T$WT{yhs9ty5h[a04tRTG{W$H)HTV$+VTH$(VTY_+( VH%V(T{U as my password anymore? I kind liked it (yes, that is my old password for this forum)

2. There are two people on this forum right now: those that are worried and getting their accounts compromised, and those that have listened to something I've said since the last Data Privacy Day (along with those that already deployed such tactics beforehand)

3. Seeing all the recommendations of http://keepass.info/ (combined with http://keefox.org/ or https://chrome.google.com/webstore/detail/ompiailgknfdndiefoaoiligalphfdae for optimum effectiveness) and https://lastpass.com/ made my day. So nice to see other people spreading good practice.

4. For all those algorithm-based password generation users, you may want to redesign your root password just to be extra-safe and change it everywhere you used it.

5. For cryin' out loud Bethedsa, hire a http://en.wikipedia.org/wiki/Penetration_Tester!

6. Avatars being disabled means one of two thing: the avatar system was the point of attack by the hackers OR the syadmins are afraid that the avatars may have been compromised with malware (plenty of browser exploits exist that can infect computers via images). If it was the first, I wish you guys luck in fixing it. If you are afraid of the second, please just delete the image database and let us reupload. It's much safer and faster than trying to figure out if they are infected or not.

7. This wasn't anonymous or LulzSec to the best of my knowledge.

8. WIth being able to PM mods to get your password reset, this seems like an awesome opportunity to hone my social engineering skills :P (read: I hope every precaution is being taken to verify the identity of the members asking for a password reset this way)

why cant the internet have no hackers ]:

Because without hackers there would be no Internet. Hackers created it.

Again?

My take - put in some .htaccess files, use that to block SQL exploits, block anything except know PHP files being executed.

htaccess can't block SQL exploits

So why all the hack attempts? Any ideas?

http://onemansblog.com/2007/03/26/how-id-hack-your-weak-passwords/

I simply cannot fathom the mentality of a hacker.

Company makes them angry. They take down their websites/services. They claim to be fighting for the users. The users suffer because they took down the service. The users don't get mad at the company, they get mad at the hackers.

How hackers cannot see this "fight the man" mentality they have, only really hurts the users I don't understand.

Anyway, if it was people from the Minecraft community that just makes them look bad. I don't recall suing Notch, personally. So, thanks for taking down my favorite forum. <_<

You're confusing hacktivists with hackers. Hackers can hack for countless reasons. For profit, for fun, out of hatred, to secure things (pen testing FTW!), etc. The hackers who hacked us this time probably isn't fighting for users or anything like that, but are just pissed and don't care who gets in the crosshairs, or hacked us for money (see the above link "How I'd hack your weak passwords")


..and then my hard disk crashed -no joke, it did..

so I have this serious high-tec device integrated with the rest of the core PC architecture that's infallible.. I have all my passwords written down on a piece of paper and taped to the side of my computer tower. It's old school, but that's how I roll

That's why you back it up, like you should all important data.

Plus, your method is vulnerable to keylogging. KeePass on the other hand, has numerous methods of nullifying keloggers.

I got as brilliant new password via email. No worries about putting down a brand new password.

Using the password you get in the email is the stupidest thing you can do. Email, first of all, isn't a secure mode of communication and secondly, it's not that great of a password. Thirdly, if you don't delete the email that is yet another window for your account getting compromised.

Eh. The one good thing out of this is that it's given me a reason to stop using the same two passwords everywhere and switch over to random-character passwords.

They weren't exactly terribly easy to guess, but the new ones will (hopefully) be harder, not to mention they're different for each place. All written down on a piece of paper in my wallet and kept in a notepad document in a secret place on my PC that nobody will ever find (porm folder ;) :P ) just in case.

I can't even begin to tell you how stupid it is to have your passwords in an unencrypted text document. There are countless viruses and other forms of malware that exist solely to track down and upload such documents.

Be smart, use KeePass.

Come on! You just suffered a breach and you send me a new password in a plain text email? I expected better of you, folks. Anyone who recovered their account, make sure to switch to a new password rather that use the one you were emailed!

I know, I was pretty pissed when I saw that.

The Forum is breached!? MAN THE BATTLEMENTS! Mr Max_aka_NOBODY fire the torpedos! Mr Expresate I want the shields at full power! :toughninja:

This had better not have been another one of those "We're hacking you because we want more Skyrim information", "we're hacking you because the Skyrim CE price is too high" or god forbid, an attack by the fanatical Notch fans. Good thinking with wiping everyone's passwords for safety.

:sad:
User avatar
Amelia Pritchard
 
Posts: 3445
Joined: Mon Jul 24, 2006 2:40 am

Post » Sun Aug 14, 2011 12:14 am

Okay, I'm back. Glad to be back, too.
User avatar
Sophh
 
Posts: 3381
Joined: Tue Aug 08, 2006 11:58 pm

Post » Sun Aug 14, 2011 3:03 am

Any word on when we get our Avatars back, I miss my SNES controller. :cryvaultboy:
User avatar
danni Marchant
 
Posts: 3420
Joined: Sat Oct 07, 2006 2:32 am

Post » Sat Aug 13, 2011 12:26 pm

I hope this incident today wasn't because of somebody being unhappy that ZM S M over one W. Two wrongs don't make a right, doesn't matter how unhappy they are at Zenimax.
User avatar
Darlene DIllow
 
Posts: 3403
Joined: Fri Oct 26, 2007 5:34 am

PreviousNext

Return to Othor Games