Jump to content

Database Breach - An Update


Dark0ne

Recommended Posts

  • Replies 547
  • Created
  • Last Reply

Top Posters In This Topic

Thanks for all the info and I appreciate your and the entire teams response. So, I just changed my password and renewed my membership while I was there.

I'm in the same boat as others here, in regards to no Cell phone, Smart or otherwise, so that means of authentication would definitely pose problems for me as well. Also, I don't care for nor use Chrome.

I know there is a lot for you and the team to consider and I have absolute faith and confidence in your ability to find the best solutions for the problems that this presents, you have demonstrated that in years past.

I have the utmost Respect for You and the Staff and whatever you determine to be the best course of action or means to address these issues, I will, of course, support you in that decision.

Thanks again for your Immediate response and candor in dealing with this. Thanks also for having the BEST site to get MODS, and more.

 

Best Wishes,

James

 

Link to comment
Share on other sites

In response to post #31635470. #31635895, #31636295, #31639400, #31641690, #31641935, #31642435 are all replies on the same post.


  Reveal hidden contents


Agree... This wonderful community has people from every corner of this world, from every layers of society, left and right, sad and happy, crazy and... more crazy. So I hope you find a solution that fits everybody.
But first of all I think you need to "force" us to make sure that we, as users, has provided you with updated information.
For the day will come, when you get up in the morning, and 5 minutes later had to lock-down all of nexus, force-reset all admin- and users-passwords, and take it all off-line, to prevent more damage.
Then you would need a backup info-channel to broadcast to users, that you (or your team) know, and are working on it. A small corner over at Reddit, maybe? I would like to know what this official backup-channels are, and what usernames to look for.

Your site has become dear to me, and it hurts me when something are not going as planned. Because I know how hard you work for this, Dark0ne.
I have some thoughts about how to update the contact info on us users, since my work are much about the same, data-cleansing.
So I offer my help, in any way I can.
Link to comment
Share on other sites

In response to post #31660700.


  Reveal hidden contents


Maybe a dumb question, but I presume any of us, "I", could go there and check it out?
If so, Great info.

Edit; I went to the site, as recommended, did a check and so far, I'm good. Thanks for the tip.
BTW, I got my answer, ;) Edited by Lokie7
Link to comment
Share on other sites

In response to post #31656575.


  Reveal hidden contents


irrelevant, the database dump was from prior to 2013. If a computer wanted to decipher your password from scratch it would take at least 60 million years.
Link to comment
Share on other sites

In response to post #31635470. #31635895, #31636295, #31639400, #31641690, #31641935, #31642435, #31659140 are all replies on the same post.


  Reveal hidden contents


Some people here apparently doesn't know how it works... The mentioned solution with Google Authenticator is NOT about sending you SMS, calls, or whatever. It is about an app you have in the phone or on PC (Google is using a well-known standard and there are multiple compatible solutions.) And this app/program in PC generates one time passwords based on current time.

So if they decide to use Google Auth, it is probably the best option in terms of compatibility. Of course, it would be nice to add also a support for Yubikey, or some other dongle solution.
Link to comment
Share on other sites

Hi Dark0ne,

 

Until now, I have been a free user while blocking all the ads you guys rely on.

This breach made me realise which financial assets are required to just be able and deliver a solid and secure platform for us modders, and how little I appreciated this.

 

I felt really bad not to do something, so I decided to at least show my support by becoming a Nexus Supporter. it's not much, but it's something (insert meme here ;) )

 

Good luck hunting them down, and I hope you guys can implement measures towards a secure environment.

Link to comment
Share on other sites

In response to post #31635470. #31635895, #31636295, #31639400, #31641690, #31641935, #31642435, #31659140, #31662135 are all replies on the same post.


  Reveal hidden contents


The use of Google Authenticator also means moving login details to a non-EU headquartered company, which can cause some problems for EU companies with the recent move to abolish the US Safe Harbor provisions. Not a decision to be taken lightly, but alternatives are available.

I'd be happy to discuss some other potential pitfalls, and provide advice Dark0ne, as per the PM I sent you (which I know must be well buried! lol).
Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.

×
×
  • Create New...