Jump to content

Forced Password Resets


Dark0ne

Recommended Posts

In response to post #41097055. #41098705, #41108050, #41131275, #41131535, #41138630, #41173615, #41174715, #41181405, #41185030, #41185770, #41187610 are all replies on the same post.


  Reveal hidden contents


It's not randomness that makes passwords secure--in fact, it makes it less secure since you're inclined to write it down. Human difficult != machine difficult.

You want a secure password? Make it a sentence, or a phrase (not a single word--they're easily subject to dictionary attacks.) Throw in some numbers/special characters if you really feel froggy.

Keep it simple, but keep it 10-15 characters. And to make it easy to remember and unique, you can include the site's name.

Something like "JoinedNexusMods4-20-16" would take centuries to be brute forced with current technology.

Link to comment
Share on other sites

  • Replies 181
  • Created
  • Last Reply

Top Posters In This Topic

  • Community Manager
In response to post #41163350.


  Reveal hidden contents


You might want to do a bit more research on this topic because hashing and salting is exactly what we did.

All it takes is enough processing power, and time, to crack hashes and salts. And that's exactly what has happened after 3 years. Edited by Dark0ne
Link to comment
Share on other sites

Ten years ago ( some of our accounts go back much further than that) a simple password for a site like Nexus was sufficient. After all, there was no money to be had for the effort and the worst you could do was use a hijacked account to troll the site. Then, the criminal scum discovered that many of the members were dumb enough to use the same password on other accounts where they could steal real money. Not many as the majority of the users on a game site were young enough that they didn't have credit cards. But those kiddies grew up and many still didn't change their simple easy to crack passwords. But now they had jobs, money, bank accounts and credit cards. Now cracking a password on Nexus still didn't get them any money directly, but it might get them access to other accounts where they could steal some money. And access to social media accounts where they could harvest a lot of personal info that scammers and spammers will pay for.

 

I have a very close friend who posted her telephone number on an open FB post to someone. She has been swamped with spam and scam phone calls on that number. As many as 7 and 8 a day. That phone number was likely harvested by a scraper that reads thousands of FB posts every second looking for data like phone numbers, email addresses, mailing addresses and any other valid personal information. The scraper then sold her verified phone number, along with hundreds of others for about 5 cents per number, That doesn't sound like much, but they likely sold her number in a package that included around 10,000 already verified good numbers making them $500 from each of a dozen or so scammers making their total haul around $6 to 7k

 

Change your password if you haven't already - AND do not post private info on any public forum.

Link to comment
Share on other sites

Hi, I have a little bit of a problem now. My password got force-changed (I already changed it after the breach) and now I can’t get a new one because, one week ago, I accidently delated the e-mail-address I use for my account (and couldn’t get it back, it was one address of a mailaccount with multiple addresses) and now I can’t change the e-mail-Address because for this I have to login (into the forum?) first, for that I need a new password what I can’t get because of the mailaddress.

Anyone knowing what to do now?

And before you ask, I can write this because I was on ‘Remember me’ and didn’t got locked out of this page (up to now), but I don’t know if I can get a support-ticket without logging into the forum because there it is said you should log in or else you will most likely be ignored

 

Edited by Matereniam38
Link to comment
Share on other sites

In response to post #41204165.


  Reveal hidden contents


It doesn't matter either way at this point as the news post says that the plain text has been retrieved and is being sold. Whether that's from decryption, or after the password hashes have been brute-force reversed doesn't matter now.

Would be nice to know how password data is currently stored for the site though.
Link to comment
Share on other sites

In response to post #41204165. #41205440 is also a reply to the same post.


  Reveal hidden contents


Since they are using IP.Board for forums it's probably salted with the username, and brute forced by now.
Link to comment
Share on other sites

In response to post #41166720.


  Reveal hidden contents


A question concerning the data breach 3 years ago... when Nexus removes an account due to it being banned, is the data simply deleted, or do they scrub the data with the equivalent of a digital file shredder?

I ask because, if they're persistent enough, hackers can recover even removed accounts. Edited by MadnessEternal
Link to comment
Share on other sites

When this breach came to light I said you should do a full password reset, to be on the safe side and was ignored. And the encryption on the stolen password database was broken at least a year ago, it's not a recent thing. Hopefully if this happens again you will be more realistic proactive ad not pretend things will be all right. Edited by Zombie_Hunter
Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.

×
×
  • Create New...