Jump to content

Forced Password Resets


Dark0ne

Recommended Posts

Just realised how close I came to being a victim of this hack. I joined Nov 2013. Nicely done with the auto change of passwords. It's nice to see the lengths you'll go to to protect the community.
Link to comment
Share on other sites

  • Replies 181
  • Created
  • Last Reply

Top Posters In This Topic

I must be amazingly lucky. I haven't changed my password until just a few minutes ago and I went to go check my email to see if anything was wrong or out of place, but everything was fine even though I did create my account in June of 2013. I dodged the mini nuke I guess. I'm glad I saw this now, though. Thank you. Edited by LTJoeDark
Link to comment
Share on other sites

In response to post #41124910. #41125555, #41125870 are all replies on the same post.


  Reveal hidden contents


The problem is that people use the same password on multiple sites. An email address and a password could get them into multiple gmail or whatever accounts. A bank statement in the email and they may be into the bank account with the same password. It's bad to use the same password, but people do, and that's why there is still value to the data even though Nexus took steps to protect the site.
Link to comment
Share on other sites

In response to post #41092740. #41123235 is also a reply to the same post.


  Reveal hidden contents


They got ahold of a 3 year old database. The breach was more recent.
Link to comment
Share on other sites

In response to post #41097055. #41098705, #41108050 are all replies on the same post.


  Reveal hidden contents


That's a good way to pick a username, but not at all a secure password. Search for "strong password generator" and bump it up to around 32 characters and store it with KeePass, a free/open source password manager.
Link to comment
Share on other sites

In response to post #41097055. #41098705, #41108050, #41131275 are all replies on the same post.


  Reveal hidden contents


Got me looking at KeePass's built in generator.

1¼Ñ'K½¤ÑÂÝÇëbÀÇDÿÅ`üæ{ëçÓvëÄòA"ð
^ one of the passwords it came up with. That one is pretty dang secure :)
Link to comment
Share on other sites

I wonder what's going to happen to the inactive mod authors here, I just happen to poke my head in every now and again so I changed mine as soon as the news popped up but i'm not creating anything atm and have little reason to hang around much at all so if it happens again while i'm away...

 

Also there are authors who have been here for years with their original passwords and I doubt very highly we will hear from again and their content is still hosted here, so what happens to them? Sure they can can get email msg but I get that for every fkin thing that happens on the forums thanks to a mysterious notifications glitch (which hasn't been fixed for a looong time) and I ignore every email notification from this site these days and it's likely others will too who get this.

Link to comment
Share on other sites

Let me see if i've gotten this right. If i've changed my password here on Nexus after the breach(i joined in 2012) and befor they decrypted the infomation, i'm in the clear? Or am i still in danger if anyother sites i use has the same password as i used here on Nexus befor the breach? If any of those is the case, then i've little to worry about, as the important sites and servies all have different passwords and are only used on that site and nowhere else. Edited by jackienspy
Link to comment
Share on other sites

In response to post #41099430. #41111490 is also a reply to the same post.


  Reveal hidden contents


Dictionary attacks run on the assumption of single modified words (like the troubador example above) or common word combinations, not on every possible combination of every possible word.

If you choose 4 random words and use them in a random order, it's perfectly fine (although most password strength checkers require additional symbol categories and will bounce the password back)
Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.

×
×
  • Create New...