PackAPunchedMick
Member
What the fuck.
Good job!
Good job!
Yeah, I was trying to figure out when I signed up for an account since I have no record of registering to the Witcher forums.
Change your password if you use it on any other site. If you used the same one for your GOG account then someone has your password for that too!
CD Projeckt should have done more than make a forum post and notify all of their users by of the breach, old database or not.
Somewhat related question: Are unique passwords still as important these days, with 2PA?
I don't have a CDPR account but I have GOG account. Should I be worried? I don't have CC data in there though. Does GOG have 2FA? Edit: it does and I have it. Good. I'm changing my password anyway.Speaking of which, aren't GOG and CDPR accounts shared nowadays?
I don't have a CDPR account but I have GOG account. Should I be worried? I don't have CC data in there though. Does GOG have 2FA? Edit: it does and I have it. Good. I'm changing my password anyway.
I'll give them a break because it's evidently from an old database before they switched to the gog.com based system but these companies need to do better. MD5 is just not good enough.
http://forums.cdprojektred.com/forum/en/the-witcher-series/news-aa/7248610-important-unauthorized-access-to-the-forums-data
It's says on the forum it's a salted md5 hash which is not encryption at all (its a hashing alg) and is not really secure enough at all.
I'll give them a break because it's evidently from an old database before they switched to the gog.com based system but these companies need to do better. MD5 is just not good enough.
http://forums.cdprojektred.com/forum/en/the-witcher-series/news-aa/7248610-important-unauthorized-access-to-the-forums-data
Uh wow yikes. So all they need to do is figure out what or how the salt was generated. Break one and you break them all.