• Ever wanted an RSS feed of all your favorite gaming news sites? Go check out our new Gaming Headlines feed! Read more about it here.
  • We have made minor adjustments to how the search bar works on ResetEra. You can read about the changes here.
Status
Not open for further replies.
Response from the team

B-Dubs

That's some catch, that catch-22
General Manager
Oct 25, 2017
32,781
Official Staff Communication
Let's clear this up: Our tech team investigated claims of a data breach and found no evidence of such on our end. We have no reason to believe our database has been compromised. What appears to have happened is that a determined troll gained access to a small number of accounts through known-leaked passwords (from breaches on other sites) and/or brute forcing weak passwords. One of the IPs used by the troll in question, not to mention the writing style, matches those used by a banned member who has long been engaged in alt right harassment against our community.

With all of that in mind we declined to engage the troll. What we did do is force the affected accounts to reset their passwords, and each of those individuals was contacted to inform them of what happened. We also updated our General Guide with recommendations on personal and account security.

Again, we have no reason to believe there has been a data breach, but both here and everywhere all members should take care to use strong passwords that are unique to each site.
 
Last edited by a moderator:
May 9, 2018
3,600

krae_man

Master of Balan Wonderworld
Member
Oct 25, 2017
9,604
Recently I logged into a local used media stores site where you can set up a wish list and be emailed when said movie/game becomes in stock and google gave me a pop up that said "This email/password combo is in known data breaches".

That was a cool popup. Hackers can have my wish list if they somehow care.
 
Oct 25, 2017
15,172
I mean in the hypothetical that there actually was a data breach wouldn't that mean gaf would have the same exact breach since they use the same forum system. Too bad this person Isn't making that public, could be saving hundreds of hundreds. ;)
 

Chessguy1

Member
Oct 25, 2017
3,803
This Sophia person seems very confident that this leak is true.

For their sake as a journalist, it better be true, otherwise they may have just ruined their credibility going forward, which IMO is everything.
 

Megasoum

Member
Oct 25, 2017
22,569
Even if the thing is a giant troll, perfect opportunity to remind people that EVERYBODY should be using a password manager and 2 factor for every website you go to.

There's really no excuses in 2020... It's free and super easy to use.

Also it's weirdly satisfying to sign up to websites using a ridiculously complex 30 characters password haha.
 

mugurumakensei

Elizabeth, I’m coming to join you!
Member
Oct 25, 2017
11,330
Stating the number of rounds of bcrypt won't make the passwords any easier to crack; it just hints that it's infeasible to even try.

well it can tell you how much computing power you should buy to try to brute force now 10 rounds will take an absurd amount of computing power and 2FA is likely enabled by most users so shouldn't be an issue
 

DownUnderCoder

Administrator
Dec 15, 2018
636
Recently I logged into a local used media stores site where you can set up a wish list and be emailed when said movie/game becomes in stock and google gave me a pop up that said "This email/password combo is in known data breaches".
This site now does a similar compromised password check. It is actually part of the NIST password standards to check for compromised passwords when changing them.
 

DoubleTake

Member
Oct 25, 2017
6,529
Look guys we're actually important enough for trolls to fake a password breach for our site!

Back pats all around lol
 

Hecht

Blue light comes around
Administrator
Oct 24, 2017
9,735
This Sophia person seems very confident that this leak is true.

For their sake as a journalist, it better be true, otherwise they may have just ruined their credibility going forward, which IMO is everything.
Don't think there's any worry about ruining what you don't have.
 

Komo

Info Analyst
Verified
Jan 3, 2019
7,110
Also I should mentioned Xenforo literally doesn't store passwords lol? It's almost always been using bcrypt, and or allowing custom solutionjs.
 

Stop It

Bad Cat
Member
Oct 25, 2017
6,352
This Sophia person seems very confident that this leak is true.

For their sake as a journalist, it better be true, otherwise they may have just ruined their credibility going forward, which IMO is everything.
They work for Russia Today.

Using the word journalist in regards to them is an insult to the term.
 

The Adder

Member
Oct 25, 2017
18,125
This Sophia person seems very confident that this leak is true.

For their sake as a journalist, it better be true, otherwise they may have just ruined their credibility going forward, which IMO is everything.
They aren't a journalist and neither their audience nor employer cares about integrity or credibility.
 

Komo

Info Analyst
Verified
Jan 3, 2019
7,110
Recently I logged into a local used media stores site where you can set up a wish list and be emailed when said movie/game becomes in stock and google gave me a pop up that said "This email/password combo is in known data breaches".

That was a cool popup. Hackers can have my wish list if they somehow care.
This was something new they added actually both Firefox and Mozilla will alert you if you account info for any login matches hashes for public and private leaks.

www.computerworld.com

Google launches leaked-password checker, will bake it into Chrome in December

The company plans to add a hacked-password alert system into its browser by the end of year; Firefox aims to do much the same thing this month.
 

Mgs2master2

One Winged Slayer
The Fallen
Oct 25, 2017
2,862
This Sophia person seems very confident that this leak is true.

For their sake as a journalist, it better be true, otherwise they may have just ruined their credibility going forward, which IMO is everything.

She doesn't care. Look who she writes for and the content she creates. This is exactly what she wants and does.
 

Kasey

Member
Nov 1, 2017
10,822
Boise
Not going to link to this crap, but if you want to know who this person is, this is what she published recently on Russia Today:

lolqrj5s.jpg
Oh shit Era is a Jewish conspiracy!!!
 

signal

Member
Oct 28, 2017
40,200
Can we puhleeease change our emails to gmail or something free once registered with a non-free one 🙏
 

SuperHans

Member
Oct 27, 2017
1,602
This was something new they added actually both Firefox and Mozilla will alert you if you account info for any login matches hashes for public and private leaks.

www.computerworld.com

Google launches leaked-password checker, will bake it into Chrome in December

The company plans to add a hacked-password alert system into its browser by the end of year; Firefox aims to do much the same thing this month.
This is really useful. I've a lot of work ahead of me. I've the same email address for nearly 20 years.
 

Instro

Member
Oct 25, 2017
15,030
Not sure who is the bigger loser. The person wasting time trying to gain access to accounts on a gaming forum, or the person "reporting" on it.
 

cognizant

Member
Dec 19, 2017
13,756
Can we puhleeease change our emails to gmail or something free once registered with a non-free one 🙏

Yeah, if you don't have access to the email you originally signed up with, that means 2FA is not an option for you, I guess? I asked a mod about this predicament ages ago but they couldn't help.
 

B-Dubs

That's some catch, that catch-22
General Manager
Oct 25, 2017
32,781
The troll is still using hijacked accounts to post in here. We've removed the posts since, obviously, the proper account holders aren't responsible.
 
Status
Not open for further replies.