Dark0ne Posted December 8, 2015 Author Share Posted December 8, 2015 In response to post #31635470. #31635895, #31636295 are all replies on the same post.Arthmoor wrote: Good to know about the planned security enhancements, but if I may suggest, please offer something more than 2FA through a smartphone. Some of us don't have one, can't afford one, or don't want to provide that number to anyone over the internet for privacy reasons. I fall into the "can't afford" category for what it's worth, so some other method to enable this would be greatly appreciated.Dark0ne wrote: I hope we can also implement some sort of system similar to how Facebook and Steam send access codes via email when an unrecognised login is received.Detonate wrote: I agree, i dont use this, sites that demand it, i dont visit. "We just had a security breach, where they stole your email, now please give us your phone number as well", no thanks!!To clarify; the concept of 2FA is that it's an optional security extra. It's not a forced requirement. Link to comment Share on other sites More sharing options...
Nazenn Posted December 8, 2015 Share Posted December 8, 2015 Minor minor thing, two factor authentication is great, except I don't have a smart phone to work with the google system XD I didnt comment on the last thread because there was a 100 people saying the same thing I wanted to which comes down to this: You guys do an amazing job, not just with this, but with everything to do with the site and the users and making sure this place is a safe place to be, and I cannot thank you for that enough. You guys do a great job on security, but if multi billion dollar corporations like microsoft can be hacked, theres no way we can ever expect a small company like yourself to never have an issue, and the fact that you almost NEVER have issues is incredible, so thank you, and THANK YOU for being open and honest about this stuff. Link to comment Share on other sites More sharing options...
westsidekidd Posted December 8, 2015 Share Posted December 8, 2015 In response to post #31633595. #31634115, #31635085, #31636985, #31639010, #31639185 are all replies on the same post.westsidekidd wrote: Dark0ne for president! This is how to handle a mini crisis. Good work. Keep it up! johnsondelbert1 wrote: to bad he is britishstarfis wrote: Then for the queen? Ehm king!IrishVixen wrote: Then Dark0ne for Prime Minister!stainglasshart wrote: Hear hear! :)SenyaTirall wrote: We should just usurp Kim Jong-Un's title of Supreme Planetary Potentate and apply it to Dark0ne. Then he can land a human on the Sun like they did.Actually i meant president of the internet. The internet needs in fact a president. ;) Link to comment Share on other sites More sharing options...
derekthedj Posted December 8, 2015 Share Posted December 8, 2015 Y'all modder hackees need Keepass Link to comment Share on other sites More sharing options...
anubispriest Posted December 8, 2015 Share Posted December 8, 2015 (edited) In response to post #31633595. #31634115, #31635085, #31636985, #31639010, #31639185, #31639560 are all replies on the same post.westsidekidd wrote: Dark0ne for president! This is how to handle a mini crisis. Good work. Keep it up! johnsondelbert1 wrote: to bad he is britishstarfis wrote: Then for the queen? Ehm king!IrishVixen wrote: Then Dark0ne for Prime Minister!stainglasshart wrote: Hear hear! :)SenyaTirall wrote: We should just usurp Kim Jong-Un's title of Supreme Planetary Potentate and apply it to Dark0ne. Then he can land a human on the Sun like they did.westsidekidd wrote: Actually i meant president of the internet. The internet needs in fact a president. ;)I thought Dark0ne already had the title of "InterUniverse Nexus Upholder of Righteousness"? Wouldn't, therefor, Kim Jong-Un be beneath? Edited December 8, 2015 by anubispriest Link to comment Share on other sites More sharing options...
Bess Posted December 8, 2015 Share Posted December 8, 2015 Thank you, Dark0ne, for all the information and for your continuing clear and timely communication. I've been a member for almost nine years -- yes, a change to my password was definitely long past due! Link to comment Share on other sites More sharing options...
ElderScrollsFan001 Posted December 8, 2015 Share Posted December 8, 2015 (edited) In response to post #31632815. #31633835 is also a reply to the same post.Dark0ne wrote: I promised I'd update you all on the possibility of a database breach on Nexus Mods that I announced yesterday morning and I am here with relatively "good" news.I am now in possession of the database dump, that was first reported on Reddit, via university security networks, and I can confirm several things. First, the database dump is "old", with the last member in the database having registered on July 22nd 2013. If you're one of the 4.2 million users who registered on Nexus Mods after this date, your details are not included in this database dump and are therefore considered "safe". Second, the database dump isn't a complete database rip. The dump contains user IDs, usernames, email addresses, hashes and salts, and that's it. It does not contain cracked passwords i.e. anyone with access to the dump would need to attempt to crack the hashes and salts themselves in order to get any sort of use out of them on the site.From this we can conclude a further two things. Firstly, that it's relatively safe to assume that whoever made this dump no longer has access to our database. Why? Because if they did, they'd have released a much more up-to-date dump of our member database. It would make sense they no longer have any access, considering we've patched up a lot of holes, applied countless security updates and switched to a far more secure database cluster system since July of 2013.Second, if you've updated your password since July 2013, your account on the Nexus sites should be safe and secure, as they will not have your new hashes/salts/password information. If you have not updated your password recently, please do so now as I am now personally confident that there have been no recent breaches of our network or databases. Similarly, if you still use the password you were using in July 2013, or before that date, on any other sites or services you should update them immediately.I would like to thank the HPE Security Research team who have personally helped me with this investigation and who securely provided me with the database dump as part of this investigation. Their help has been invaluable.My previous news post also mentioned three compromised mod author accounts that had uploaded a suspicious file in place of legitimate mods on the site. I have been in contact with one of the owners of the compromised accounts personally, along with another individual who I know was compromised recently, and both were using extremely simple passwords. Passwords that would take a simple cracker mere seconds to crack. This helps to confirm that whoever is using this information is going for high-profile, but extremely easy accounts to crack.To my knowledge, we have not seen any further suspicious activity in the file database at this time.The malicious file that was uploaded, "dsound.dll", has been sent away to the malware research team at HPE Security Research to find out what it does and, hopefully, spread the word so it can be flagged by anti-virus software appropriately. Once again, a big thank you to the HPE Security Research team. They've provided an excellent service.While we would like to force everyone to update their passwords so we can be completely in the clear when it comes to this breach, the only way we could force a password update is to make everyone's password invalid on the site and force you to do a password recovery via your email address. While that might be OK for our newer members (who this doesn't even affect), I imagine there are thousands, if not hundreds of thousands of users on this site who have signed up with email addresses they no longer have access to and would, instantly, become completely locked out of their accounts with no way of gaining entry back. So we have a bit of a conundrum in this respect, and I'm not entirely sure what to do.In spite of the fact we think that we're "in the clear" on the possibility of a recent breach, we're not going to sit back and pretend like we couldn't be doing more. This scare has given us a real kick up the backside, so we're putting aside our work on the front-end for our NMM Profile Sharing at this time so we can focus on some improvements.In the short-term, we've already begun work on more verbose logging of user actions on the site, especially in regards to logging the IP addresses you login with and use when performing major actions, such as uploading or removing files to the database. This should allow us to more easily analyse and spot suspicious activity on the sites when it occurs. If someone who previously used a static IP address for years starts making wild changes to all their files using IP addresses traced back to TOR, it's safe to say we're going to find that suspicious and will react accordingly.We're also working on a system that will allow us to notify you, the users, when something as important as this comes up again. As it is, we have the functionality to send "full page notifications" to individual users when we want to make sure a user gets a message. Imagine a Private Message, but one you're forced to view and tick a box saying you've read the message, before you can browse the site again. While we can send these to individual users, we can't send this en-masse to every user of the sites, so we're going to modify this system so I can send out site-wide alerts and notifications for these important matters. You'll know when this system is finished because you will receive a notification (hopefully in the next few days) with information contained in these news posts and a reminder to change your password.Following on from that, beginning next week we're going to bring forward work we had planned for the middle of next year in regards to our forum system. We aim to devolve more functionality away from our off-the-shelf Invision Board forums and into our own custom coded system that will allow us to have complete control over the member database and login security. Essentially, transitioning away from account security being controlled via the forums to account security being controlled via our own custom coded systems. Not only will this mean you no longer need to visit the forums to change your details, but it will also allow us to implement much stronger encryption of user data, Two-Factor authentication (no details as yet, but right now we're leaning towards Google Authenticator that will allow you to generate secure codes from your smart phones) and lots of our own custom touches that should make things a lot more secure in the backend. Idea being that even if the worst were to happen and another dump was released to the public, we'd make it absolute hell for anyone looking to crack the data.And lastly, I'd like to thank you all for your response to this mini-crisis. Your words of understanding, support and encouragement, both publicly and via the outpour of private messages I've received have helped to stem the horrible feelings of disappointment in the announcement of this leak and provided me with added resolve to work my absolute hardest to get this sorted. I've said it plenty of times before, but I'll say it again; it really does make a massive difference when the people you're looking to do good by are as understanding and supportive as this community is.zcul wrote: I think, it's the way of being open for informing the community of any gaps and giving a pre-caution, instead of covering up anything as politicians tend to do. The Nexus team I think are not politicians. So far, thank you for informing us in time, regardless the possibility it could take effect on users or not. Better safe than sorry ... :smile: very good to know I've chang mine twice scine joining so hopefully all is good Edited December 8, 2015 by ElderScrollsFan001 Link to comment Share on other sites More sharing options...
SgtMajRet Posted December 8, 2015 Share Posted December 8, 2015 Dark0ne, Thank You for the update! Happy things are not as dire as we all thought. I have been around here a long time and don't plan on going anywhere. I very rarely post anything, but just wanted to say thanks. I also want to wish you a Happy Holiday Season! Keep up the great work. Link to comment Share on other sites More sharing options...
umiluv Posted December 8, 2015 Share Posted December 8, 2015 Thank you for the transparency! Definitely better safe than sorry and thank you for trying so hard to protect our information. =) Link to comment Share on other sites More sharing options...
Zharre Posted December 8, 2015 Share Posted December 8, 2015 (edited) Thank you for the update. I admit to being slack. Really, REALLY slack. I've had the same, super simple password on this site for years - probably since I signed up in '05 (after already being a long term user of Morrowind Chronicles, then TESNexus!). Was a super simple password I once used for a lot of forums I used to frequent, and I guess I just never got around to updating it here, despite this being a bit more than one of the many faceless forums I would browse & seldom, if ever, post on. Now my password is updated, strengthened, and no longer identical to any other that I have ever used. Thank you for being such a reliable site. I don't just come here because of the fantastic way you handle mods, but because of the confidence I have that any issues will be handled appropriately. I greatly appreciate Nexus, ergo, I greatly appreciate all you do. Thank you. Edited December 8, 2015 by Zharre Link to comment Share on other sites More sharing options...
Recommended Posts