• Ever wanted an RSS feed of all your favorite gaming news sites? Go check out our new Gaming Headlines feed! Read more about it here.
Status
Not open for further replies.
Response from the team

B-Dubs

That's some catch, that catch-22
General Manager
Oct 25, 2017
32,711
Official Staff Communication
Let's clear this up: Our tech team investigated claims of a data breach and found no evidence of such on our end. We have no reason to believe our database has been compromised. What appears to have happened is that a determined troll gained access to a small number of accounts through known-leaked passwords (from breaches on other sites) and/or brute forcing weak passwords. One of the IPs used by the troll in question, not to mention the writing style, matches those used by a banned member who has long been engaged in alt right harassment against our community.

With all of that in mind we declined to engage the troll. What we did do is force the affected accounts to reset their passwords, and each of those individuals was contacted to inform them of what happened. We also updated our General Guide with recommendations on personal and account security.

Again, we have no reason to believe there has been a data breach, but both here and everywhere all members should take care to use strong passwords that are unique to each site.
 
Last edited by a moderator:

Kinthey

Avenger
Oct 27, 2017
22,249
We have no reason to believe our database has been compromised. What appears to have happened is that a determined troll gained access to a small number of accounts through known-leaked passwords (from breaches on other sites) and/or brute forcing weak passwords. One of the IPs used by the troll in question, not to mention the writing style, matches those used by a banned member who has long been engaged in alt right harassment against our community.

But how did the troll get those email addresses?
 

Deleted member 5086

User requested account closure
Banned
Oct 25, 2017
4,571
Yeah, if you don't have access to the email you originally signed up with, that means 2FA is not an option for you, I guess? I asked a mod about this predicament ages ago but they couldn't help.
Our 2FA works through apps like Authy and Google Authenticator, and not through email, so it should still be an option. We'll look into what's possible regarding changing emails.
 

MinusTydus

The Fallen
Jul 28, 2018
8,189
This Sophia person seems very confident that this leak is true.

For their sake as a journalist, it better be true, otherwise they may have just ruined their credibility going forward, which IMO is everything.
Sophia Narwitz

Journalist at RT with bylines elsewhere. Primary writer for Colin Moriarty.

LMFAO
 

Naga

Alt account
Banned
Aug 29, 2019
7,850
I didn't even know there was 2FA on Era...
But yeah, both the explanation (brute forcing/other passwords breached) makes sense, especially given the alt-right's obsession with this website, and the usual tips for those situations (2FA, change password etc).
 

Deleted member 3812

User requested account closure
Banned
Oct 25, 2017
8,821
A heads up, 2FA using app authentication is more secure than email 2FA because if someone has access to your email and has a password to a site that does email-based 2FA they will have access to that site's user account because the 2FA code is emailed to you.

Fortunately, I see that ERA has app based 2FA which gives you a rotating 2FA code that changes frequently.
 

Baji Boxer

Chicken Chaser
Member
Oct 27, 2017
11,374
I checked how long it would take to brute force my password and learned a new number: "duodecillion"
 

Chopchop

Member
Oct 25, 2017
14,171
that is fucking weird. I guess that reinforces why I don't speak directly about who I am then
It's a good practice in general. This is a public forum, and there's no telling how many lurkers are reading your posts.

It's not terribly hard for someone to search a single person's posts and put together a profile of their information. Some people just have nothing better to do with their lives than to do shit like this, and it's both scary and sad.
 

CyberWolfBia

Member
Apr 5, 2019
9,910
Brazil
apparently someone used my account to post some things here... I got a panic attack and changed my passwords in every e-mail that I got, including the one associated with my Era account...
 

Gentlemen

Member
Oct 25, 2017
9,497
They're the one who discovered the ESA leak and got them to remove the personal info of everyone at E3, so they have some credibility.
They also publicly posted the URL containing the personally identifiable information of hundreds of people, aligning her actions more closely with kiwi farms target painters than a professional security researcher and journalist.

she's a partisan crank, nothing more.
 

Mgs2master2

One Winged Slayer
The Fallen
Oct 25, 2017
2,861
They also publicly posted the URL containing the personally identifiable information of hundreds of people, aligning her actions more closely with kiwi farms target painters than a professional security researcher and journalist.

she's a partisan crank, nothing more.

This. All of it
 

Mathieran

Member
Oct 25, 2017
12,852
It really goes beyond stalking too. people have been doxxed and swatted *just for being a ResetEra member*
There are a nonzero number of psychopaths with a chip on their shoulder looking for any morsel of personal information shared here.
People like the "journalist" in the OP enable this behavior, especially with their actions during the E3 breach.
It's a good practice in general. This is a public forum, and there's no telling how many lurkers are reading your posts.

It's not terribly hard for someone to search a single person's posts and put together a profile of their information. Some people just have nothing better to do with their lives than to do shit like this, and it's both scary and sad.

Yeah I suspect someone could find out who I am if they did a little leg work but at least it's not too apparent.
 

Zan

One Winged Slayer
Member
Oct 25, 2017
9,414
Thanks to this thread, I signed up for a password managment service. Not sure if it'll help, but whatever.
 

Gaardus

Member
Oct 27, 2017
2,591
apparently someone used my account to post some things here... I got a panic attack and changed my passwords in every e-mail that I got, including the one associated with my Era account...
If you aren't already, I strongly encourage you to use a password manager like LastPass or Bitwarden. It can create unique, randomly generated passwords for each of your accounts and handle filling in login info, so the only password you need to memorize is the one for your password manager account.
 

CyberWolfBia

Member
Apr 5, 2019
9,910
Brazil
If you aren't already, I strongly encourage you to use a password manager like LastPass or Bitwarden. It can create unique, randomly generated passwords for each of your accounts and handle filling in login info, so the only password you need to memorize is the one for your password manager account.
thanks for the suggestion.. now I'm really scared, I'll try everything I can to protect my data..
 

TaySan

SayTan
Member
Dec 10, 2018
31,370
Tulsa, Oklahoma
I searched and looks like my account wasn't compromised here and nothing wasn't posted by someone else. Going to look into getting a password manager just in case.

Trolls with nothing better to do out there.
 
May 9, 2018
3,600
For password managers I also recommend using KeePass (KeePassXC for Mac), which creates a database that is an individual file on your computer that can be backed up to any cloud service. (and can be configured to make it impossible to brute force; you can use Argon2 for the password hash which is already very strong)
 
OP
OP
Falchion

Falchion

Member
Oct 25, 2017
40,873
Boise
Thanks to all the staff working behind the scenes on this, it seems like everything is well in hand! Also at the very least, this was a good opportunity to get more users to implement 2FA.
 

Gunny T Highway

Unshakable Resolve - One Winged Slayer
Member
Oct 27, 2017
16,990
Canada
Thanks for the quick responses. Also friendly reminder to those who have not please set up the 2FA here as well as everywhere you can.
 

B-Dubs

That's some catch, that catch-22
General Manager
Oct 25, 2017
32,711
Members have raised some concerns that leaving this thread open will create new targets for off-site trolls. We've answered all questions to the best of our knowledge. Again, we'd like to remind everyone that using 2FA and strong/unique passwords is a good precaution to always take.

If you have any concerns about the privacy of your account, please contact administration and we will be happy to help.
 
Status
Not open for further replies.