• Hey, guest user. Hope you're enjoying NeoGAF! Have you considered registering for an account? Come join us and add your take to the daily discourse.

It seems some GAF accounts have been compromised

Status
Not open for further replies.

Relix

he's Virgin Tight™
The passwords in GAF have to be encrypted and salted, its standard vBulleting stuff. Now if they are using MD5 or SHA its another story.

Probably guessable password or the same password in another compromised site. Happens all the time.
 
Okay, quick update on this just so people know what's going on.

We've spoken with gromph about this and there's currently no evidence of a breach on NeoGAF's servers. As best we can identify, this has been the result of users' accounts being accessed directly via their password. We're aware of who appears to be responsible (in fairly great detail) and we're doing what we can to mitigate the issue, but we can't necessarily prevent completely people's accounts being accessed using a guessed or brute-forced password.

Since this is coming up, this is a good opportunity to reiterate this: if you reuse passwords or use insecure passwords then your accounts are very likely to be compromised. Please use a unique password on NeoGAF that isn't used on any other sites (since otherwise a password leak on another site can lead to your account here being compromised); pick one that's long (12+ characters) and not based on dictionary words or identifiable personal information. Ideally, pick a random password and store it in a password manager. Everyone should consider this a good reason to change their password today.

I'll note that we're also aware of the issue of accounts registering just to send obscene PMs to other random users, and we're also doing what we can to mitigate that, but it doesn't seem to be connected to this issue.
 

NH Apache

Banned
Is this the thread we are confined to posting all the racist shit in, or is it all the threads? Asking for a friend. #PhantasmSquad #Kony2012
 

Stinkles

Clothed, sober, cooperative
I think it's a guesser. He's just trying top 100 passwords or something, very few accounts and all pretty oldschool. Change your password to something modern.
 

Sesuadra

Unconfirmed Member
when I read something like this I always have a little bit of hope that at least a mod or two or a few gaffer know my name by now and know that I would never throw around racist bs or other bullshit..

I know it is probably not that way..but hey maybe a few know me..lol.
 

kavanf1

Member
I've just had a PM about getting my "faggot head curb stomped and getting my throat slit," from a user with 0 post history.

I'm assuming this is from that lol.

I got a long one yesterday with the subject "fucking cunt, i'd gladly dismember and disembowel you, and feed your limbs to lions". User was already banned by the time I read it, so seems to be quick action being taken by admin.
 

Magwik

Banned
Changed my password
Apparently I forgot what it was
So I had to reset it via email only to find out I had forgotten that specific email password too
What a lovely day
 

Timan

Developer
I don't even remember my PW to change it. I use chrome for all this stuff. :(

Can use webinspector and change the input type=password to type=text and it'll display it in plain text for you to copy. But you should also be able to get it from settings if its a saved password.
 
Okay, quick update on this just so people know what's going on.

We've spoken with gromph about this and there's currently no evidence of a breach on NeoGAF's servers. As best we can identify, this has been the result of users' accounts being accessed directly via their password. We're aware of who appears to be responsible (in fairly great detail) and we're doing what we can to mitigate the issue, but we can't necessarily prevent completely people's accounts being accessed using a guessed or brute-forced password.

Since this is coming up, this is a good opportunity to reiterate this: if you reuse passwords or use insecure passwords then your accounts are very likely to be compromised. Please use a unique password on NeoGAF that isn't used on any other sites (since otherwise a password leak on another site can lead to your account here being compromised); pick one that's long (12+ characters) and not based on dictionary words or identifiable personal information. Ideally, pick a random password and store it in a password manager. Everyone should consider this a good reason to change their password today.

I'll note that we're also aware of the issue of accounts registering just to send obscene PMs to other random users, and we're also doing what we can to mitigate that, but it doesn't seem to be connected to this issue.
Appreciate the update :)
 

LiK

Member
Okay, quick update on this just so people know what's going on.

We've spoken with gromph about this and there's currently no evidence of a breach on NeoGAF's servers. As best we can identify, this has been the result of users' accounts being accessed directly via their password. We're aware of who appears to be responsible (in fairly great detail) and we're doing what we can to mitigate the issue, but we can't necessarily prevent completely people's accounts being accessed using a guessed or brute-forced password.

Since this is coming up, this is a good opportunity to reiterate this: if you reuse passwords or use insecure passwords then your accounts are very likely to be compromised. Please use a unique password on NeoGAF that isn't used on any other sites (since otherwise a password leak on another site can lead to your account here being compromised); pick one that's long (12+ characters) and not based on dictionary words or identifiable personal information. Ideally, pick a random password and store it in a password manager. Everyone should consider this a good reason to change their password today.

I'll note that we're also aware of the issue of accounts registering just to send obscene PMs to other random users, and we're also doing what we can to mitigate that, but it doesn't seem to be connected to this issue.

ok good, I use a unique pw for GAF so I'm good.
 

Lucumo

Member
Hm, when I was browsing GAF on my phone earlier, I got messages that my phone was infected with a virus and that I should install something. It also made a lot of noise (sounds etc).
I only browse GAF there, so maybe there is a problem here?
 
I wish there was a system that could prevent stuff like this. Like a thing that you could use to save unique passwords for every site without having to remember them yourself. Like a piece of paper but automatic and more secure somehow.

Too bad there isn't one, oh well
 

SyNapSe

Member
whatever happened.
.. it wasn't me

I feel like one of those celebrities on twitter now. I have a free path to go batshit crazy. I was hackdedid I say!
 

ChrisD

Member
My GAF account was made with an Email that I don't even have anymore, but the password I used is basically random stuff thrown together so I should be safe. Had to write it down somewhere just so I wouldn't forget it myself once the account finally got approved.
 

SyNapSe

Member
My GAF account was made with an Email that I don't even have anymore, but the password I used is basically random stuff thrown together so I should be safe. Had to write it down somewhere just so I wouldn't forget it myself once the account finally got approved.

If you let me know what it is then you won't have to worry about losing it. You know you want to! Let me relieve you of this burden. PM me
 
So, if someone's account got hacked, how do they then contact the mod to tell them that it was hacked or something? Is there an email that you're supposed to send someone?
 
Status
Not open for further replies.
Top Bottom