When creating your new passwords, please keep this XKCD comic in mind and maybe we'll all have secure, easy to remember passwords:
for what it's worth,
vBulletin.com got hacked as well. The hackers claim they got access to our moderator account due to that hack/breach.
http://www.vbulletin.com/forum/foru...7195-important-message-regarding-your-account
arn
MR's already offer numerous areas for support related content. However this thread resides within the News Discussion area so it's going to have the most opinionated and emotional comments out of the rest. It's not unique to MR's and it gets just as silly/heated in the Android/Windows/Linux/Photoshop forums as well.
for what it's worth,
vBulletin.com got hacked as well. The hackers claim they got access to our moderator account due to that hack/breach.
http://www.vbulletin.com/forum/foru...7195-important-message-regarding-your-account
arn
perhaps they'll improve their product!
Perhaps MR should have done the same thing vBullitin did.
"We take your security and privacy very seriously. Very recently, our security team discovered sophisticated attacks on our network, involving the illegal access of forum user information, possibly including your password. Our investigation currently indicates that the attackers accessed customer IDs and encrypted passwords on our systems. We have taken the precaution of resetting your account password. We apologize for any inconvenience this has caused but felt that it was necessary to help protect you and your account."
Really, what is the big deal if someone can log in using my info. What are they going to do? Post malicious, venomous comments in my name? Nobody would even notice with all the abuse that takes place daily on just about every online forum, it would just be more noise. If you want to help prevent things like this from happening in the future then try your best to be considerate of others and to be the best example that you can be. If this type of behavior catches on then all sorts of trouble will soon disappear.
Well, I got the email and literally right after (within 30 minutes) I had my twitter, gmail, and Facebook all hacked.![]()
Sucks to use the same email/username/password for everything. Hope you learned your lesson.
Really, what is the big deal if someone can log in using my info. What are they going to do? Post malicious, venomous comments in my name? Nobody would even notice with all the abuse that takes place daily on just about every online forum, it would just be more noise. If you want to help prevent things like this from happening in the future then try your best to be considerate of others and to be the best example that you can be. If this type of behavior catches on then all sorts of trouble will soon disappear.
Who said I did? Out of all of my accounts, only my gmail was the same as the forum and then they used the email to hack into everything else
So . short of having to write down all the different passwords for a lot of sites on a piece of paper (not very secure), use a password manager (more secure), or use PGP to encrypt a text file with all my passwords in it (very secure), are there any other solutions that are easy/simple to use without compromising security more than necessary?
Why is it that you believe password managers are less secure than PGP?
Well, I got the email and literally right after (within 30 minutes) I had my twitter, gmail, and Facebook all hacked.![]()
How am I supposed to know? Just coincidence that the email I use for this forum got hacked when I only use that email for this forum and my social media sites?So.... the stolen passwords have been cracked now?
Also, it's my understanding that "some" password managers sync to servers on the Internet. If that's true, unless they use end-to-end encryption between the server and user device, they would not be as secure as using PGP locally on the device.
Did your password consist of dictionary words? Because it looks like "the hacker" wasn't able to get Arn's password. He had to pay someone else to figure it out for him. Surely the dude didn't pay to get your password? I mean, what's in it for him for getting your social media sites?How am I supposed to know? Just coincidence that the email I use for this forum got hacked when I only use that email for this forum and my social media sites?
LastPass, 1Password, and KeePass, perform all encryption and decryption on the local machine. All servers ever get is an encrypted blob, and only the user has the key. Also, KeePass is free and open source, meaning outside developers can see exactly how it works and make sure there's nothing fishy going on.
See this post if you haven't already: https://forums.macrumors.com/posts/18357437/
Is that all that vBulletin did -- reset everyone's password? Regarding they being hacked, I don't see a Notice at the top of their forums (like MacRumors did), or anything on their Facebook or Twitter pages about it. Nothing on their main website either.Perhaps MR should have done the same thing vBullitin did.
"We take your security and privacy very seriously. Very recently, our security team discovered sophisticated attacks on our network, involving the illegal access of forum user information, possibly including your password. Our investigation currently indicates that the attackers accessed customer IDs and encrypted passwords on our systems. We have taken the precaution of resetting your account password. We apologize for any inconvenience this has caused but felt that it was necessary to help protect you and your account."