NOTICE SECURITY NOTICE - everybody read

Discussion in 'Site Help and Suggestions' started by retro, Oct 29, 2016.

  1. retro

    retro Resigned from mod duty 15 March 2018

    Joined:
    Mar 13, 2004
    Messages:
    10,354
    Likes Received:
    822
    Please remember to regularly review your security - not just on this site, but the Internet in general. Here are some tips:

    • Use STRONG passwords (long - numbers, uppercase characters, lowercase characters AND symbols)
    • Use DIFFERENT passwords on different sites
    • Use two-step verification
    • Change your passwords REGULARLY
    • Your data is potentially at risk on any site for which you create a login. CHECK to see if you're on any leaked databases
    You can turn on two-step verification here. I would recommend using the app as your e-mail can be hacked! If you must use e-mail verification, make sure you DON'T have the same password for the site as your e-mail!

    I'd highly recommend entering your e-mail at www.haveibeenpwned.com to see if you are on a compromised database. These include MAJOR sites like Myspace, LinkedIn, Adobe, Dropbox and quite a few gaming sites.

    Here is a guide to making strong passwords, with a handy generator.

    It has come to our attention that there have been numerous users logging in from shared IP addresses. This is quite possibly a malicious login - perhaps where someone has gained your information from a leaked database. You REALLY need to change passwords to any site listed on the above link, and make sure you don't use the same password for your e-mail, PayPal, eBay, Amazon or ASSEMbler accounts!

    We may have to start banning some of these suspicious proxy addresses, which would result in some users being affected. Ultimately, you shouldn't need to use a proxy to access the site. If your company blocks access to the site, remember you're supposed to be working on company time, not looking at a gaming forum!
     
  2. D_Ban

    D_Ban Robust Member

    Joined:
    Aug 11, 2008
    Messages:
    289
    Likes Received:
    348
    Thanks for posting this. It's shocking how much of our data is leaked these days.
     
  3. PixelButts

    PixelButts Site Soldier

    Joined:
    Aug 19, 2014
    Messages:
    2,665
    Likes Received:
    1,808
    It's funny how I was just trying to update my stuff yet I cant remember my current password.

    Shows how much I truly care. Time to fix it.

    Edit: man that was the worst password ever
     
    DeChief and D_Ban like this.
  4. XboxSurgeon

    XboxSurgeon Site Supporter Since 2013

    Joined:
    Nov 18, 2013
    Messages:
    2,109
    Likes Received:
    923
    But Retro.....hey....

    The boss makes a dollar and I make a dime, and that's why I DICKBUTT on the company time....

    ....c'mon man....
     
  5. Errorjack

    Errorjack Gears of War Collector

    Joined:
    Jun 2, 2012
    Messages:
    237
    Likes Received:
    37
    With the recent malicious attacks on my accounts, it is a good reminder for others to make sure their accounts are secure. Thanks admins for the help!
     
    D_Ban likes this.
  6. D_Ban

    D_Ban Robust Member

    Joined:
    Aug 11, 2008
    Messages:
    289
    Likes Received:
    348
    Forgot to say, Don't forget to remind users to download backup codes and keep them somewhere safe.. OFFLINE.

    You can generate 10 random security codes which act as a second password. Don't leave these where others might find. Put them on a bit of paper or on something in a safe place.

    If you lose them you could be locked out of your account also.

    These codes can only be used once, You can however generate 10 new one's once used up.
     
    Last edited: Oct 29, 2016
    retro likes this.
  7. sp193

    sp193 Site Soldier

    Joined:
    Mar 28, 2012
    Messages:
    2,217
    Likes Received:
    1,052
    I hope that this doesn't include users who are behind a transparent proxy server that is deployed by our ISPs. We don't have a choice (and neither do some of us know about it).
    Personally, I know that I am behind one because of how I wasn't able to use a lot of filesharing websites (IP address in use, which isn't even mine) and a moderator was telling me that my traffic comes from the US (which is, really, really far from where I am).
     
  8. D_Ban

    D_Ban Robust Member

    Joined:
    Aug 11, 2008
    Messages:
    289
    Likes Received:
    348
    Pretty sure it's limited to web proxy's/VPN's/Tor in the case of an ISP proxy checks can be made I guess.
     
  9. ToXZiN 1

    ToXZiN 1 Spirited Member

    Joined:
    Sep 22, 2015
    Messages:
    179
    Likes Received:
    50
    Not sure if this would throw a red flag or not but I use a load balancing router and combine 2 ISP's. So one time I click a page and the next time I click one I could have a completely different IP.
     
  10. retro

    retro Resigned from mod duty 15 March 2018

    Joined:
    Mar 13, 2004
    Messages:
    10,354
    Likes Received:
    822
    We would check data first, and I'm talking about specifically suspect proxies where a number of users have logged in and they're all over the place. And you always show up as in Asia.

    All in the same state and similar IPs. If you were in California at one time and suddenly in New York half an hour later, then in Florida an hour later, that would be suspect.
     
  11. MonkeyBoyJoey

    MonkeyBoyJoey 70's Robot Anime GEPPY-X (PS1) Fanatic

    Joined:
    Mar 1, 2015
    Messages:
    1,738
    Likes Received:
    312
    Thanks for the heads up! Just enabled two-step verification and changed my password as a precaution. Hopefully those affected can get control of their accounts again.
     
    D_Ban likes this.
  12. CrAzY

    CrAzY SNES4LIFE

    Joined:
    Nov 25, 2006
    Messages:
    1,737
    Likes Received:
    48
    Using different passwords might be a pain, but it will save your ass in the end.
     
    D_Ban likes this.
  13. Digmac

    Digmac Removed for Not Reuploading Juiced Fast Enough

    Joined:
    Aug 19, 2013
    Messages:
    750
    Likes Received:
    512
    Time to start coming up with new passwords. Thanks for the heads up and tips to keep us safe @retro
     
  14. thedarkpersian

    thedarkpersian RetroGemCollector

    Joined:
    Oct 31, 2014
    Messages:
    276
    Likes Received:
    100
    I'm on it, thanks for the reminder.
     
  15. modrobert

    modrobert Rising Member

    Joined:
    Jul 23, 2005
    Messages:
    68
    Likes Received:
    21
    In Bangkok I'm behind a similar transparent proxy enforced by the ISP as sp193 mentioned, we are 2.3 million users sharing about four different IP addresses when accessing the web. Sure, it can be avoided by using other proxies or the TOR network (which dynamically changes IP address and country frequently BTW, depending on the exit node).

    If a site admin wants to know the current TOR exit nodes so they can be whitelisted from permanent ban, it's here:

    https://check.torproject.org/exit-addresses

    I think we should promote the use of TOR since the ISP's are behaving so bad in general regarding censorship enforced by government, and for privacy reasons.
     
    Last edited: Oct 30, 2016
  16. truemaster1

    truemaster1 Enthusiastic Member

    Joined:
    Nov 10, 2015
    Messages:
    512
    Likes Received:
    225
    thanks i already found a copromised email
     
  17. sanni

    sanni Intrepid Member

    Joined:
    May 30, 2008
    Messages:
    653
    Likes Received:
    77
    Thanks for the reminder, password changed :)

    I wish there was a function in Chrome where it could automaticly change all the stored passwords, like automaticly log into each site that has been saved, change the password, update the password. Then you could just do that once a month and would never be hacked unless ofc google or your pc gets compromised xD
     
  18. Bad_Ad84

    Bad_Ad84 The Tick

    Joined:
    May 26, 2011
    Messages:
    8,566
    Likes Received:
    1,308
    @retro Is this post implying there was a breach of this site?
     
    Digmac, -=FamilyGuy=- and Syclopse like this.
  19. james2452

    james2452 X360

    Joined:
    Jan 8, 2014
    Messages:
    527
    Likes Received:
    503
    All my passwords are small and easy to remember. I better make a harder one for my ebay and paypal account.. I lost one on betaarchive so i just made a new account... I do not trust using my pc to buy stuff online, it keeps loading japanese sites. I had 2 pc inffected (killed) from going on the internet. Watch out what you download is all i can say.
     
  20. retro

    retro Resigned from mod duty 15 March 2018

    Joined:
    Mar 13, 2004
    Messages:
    10,354
    Likes Received:
    822
    As mentioned before, I highly recommend against logging into the site using TOR. There's no reason for you to hide your true IP from us - only ASSEMbler and I can see it, anyway.

    As said above, if you're behind an ISP proxy, it's not an issue. It's where you dart all over the World and log in with the same IP as 10 other users. That becomes suspect. This would include the use of TOR.

    It's implying users need to make better passwords and not reuse them ;)
     
sonicdude10
Draft saved Draft deleted
Insert every image as a...
  1.  0%

Share This Page