Status
Not open for further replies.

Addressing the recent user account hack scare

Dear GBAtemp members and visitors,

It has come to our attention that over the past two days, a person has somehow been able to access a few user accounts on our forums. Shortly after, rumors started blossoming regarding a possible site/forum/database hack or a password leak. After an extensive search into server logs and lookup tools we have no reason to believe that any part of our site has been compromised.

At this point, as several people have suggested already, we believe that the reason this intrusion happened is because another site (an illegal ROM/ISO download site) was recently hacked and the password database was exposed to the public. Since a portion of our members was also registered on that site, possibly using the same password, this could explain the recent scare.

Even though we have no reason to believe our site has been compromised, we have taken a series of measures to reinforce account security on GBAtemp. Firstly, we have reviewed security on the server and all components of our site to make sure everything is up to date and secure. Some components of the forum software have been updated and following this update, one or two add-ons have ceased functioning. If you see anything that isn't working as expected, please use our Site discussions and suggestions forum to report the issue.

At this point, we recommend all our members to change their password and enable two-factor authentication. We are sending out e-mails to all our members to inform them of this situation and to recommend them to change their password. We strongly recommend using a unique and complex password, not just here but on every site you are registered to.

If you have any information that may help us get a better grasp on the situation, please get in touch with a member of the staff. Thank you for your understanding!

The staff
 

the_randomizer

The Temp's official fox whisperer
Member
Joined
Apr 29, 2011
Messages
31,284
Trophies
2
Age
38
Location
Dr. Wahwee's castle
XP
18,969
Country
United States
Last edited by the_randomizer,
  • Like
Reactions: Patxinco

mathieulh

Well-Known Member
Member
Joined
Feb 28, 2008
Messages
378
Trophies
0
Website
keybase.io
XP
897
Country
France
Then what do you suggest, not use any kind of authentication? Because that's what it sounds like.

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

That's not not what I suggest at all,

Use something you know:
- -A password, typically long, with lower, upper case, special characters and numbers,
I personally achieve this using mnemotechnics to recall long sentences in Japanese with characters stowed in between

Use something you own:
- -A Secure Access Module or a Hardware Security Module to store secrets to cryptography challenges used during
two factor authentications, would it be symetrical keys (OTP based) or private keys (PGP, U2F).
This exists in the from of a smart card, a (typically compatible with Android smartphones) NFC device (Yubikey NEO, SIGILANCE...),
a USB device (Yubikey 4, Yubikey NEO, Nitrokey...).


Contrary to popular belief and despite convenience mitigation, a smartphone application does not constitute "something you own"
because unlike SAM or HSM designed to be tamper proof and physically separated from your endpoint, your smartphone
usually being the endpoint itself and connected to a network, is not, making it therefore all the more practical for an attacker
to exploit the device and extract the keys stored within the apps, as such it becomes "something you know" compromising the
purpose of the two factor authentication, especially if all the factors are stored/used on the same device.

There is no such thing as good security, there is only bad security and worse security, security is only as good as its weakest link
therefore one needs to render his assets as secure as possible, making it time and effort consumming for an attacker to target him.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBCAAGBQJYd9f1AAoJEKa4nBz3AlIIGbQH/35OHAPKBjoOJbOnzF5AsjXg
aYIxaN3kGvd/69pUrV9Tm0CAnJJwmZBOWpYaI8eUCJGQIth7flOyajHh15iMnJ1s
R4JW+yn1W15Ya63XPawcoQt4Fo+dzAdR+kKMYLnh6YtgC5Fsq3EPQt5414RGwfyp
6dQ1U137rqJFUoqGKFquazP2w0pWyD7x9lnOAZi8t82iL7u3x0J+pWjJuEr5pBKx
fcAjgZAHIWV3esooE1s3NB3ggMEwvCzX8Fkf2p4NSK+dI+C5CWbBR5SViAxqxoQn
3Eb0WTkOCunm3ggsQJWB7JlGNEe2r1ZR1FANnMMW8LKy/yh/kFUaUFgum8tkoyw=
=vBU3
-----END PGP SIGNATURE-----
 

the_randomizer

The Temp's official fox whisperer
Member
Joined
Apr 29, 2011
Messages
31,284
Trophies
2
Age
38
Location
Dr. Wahwee's castle
XP
18,969
Country
United States
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

That's not not what I suggest at all,

Use something you know:
- -A password, typically long, with lower, upper case, special characters and numbers,
I personally achieve this using mnemotechnics to recall long sentences in Japanese with characters stowed in between

Use something you own:
- -A Secure Access Module or a Hardware Security Module to store secrets to cryptography challenges used during
two factor authentications, would it be symetrical keys (OTP based) or private keys (PGP, U2F).
This exists in the from of a smart card, a (typically compatible with Android smartphones) NFC device (Yubikey NEO, SIGILANCE...),
a USB device (Yubikey 4, Yubikey NEO, Nitrokey...).


Contrary to popular belief and despite convenience mitigation, a smartphone application does not constitute "something you own"
because unlike SAM or HSM designed to be tamper proof and physically separated from your endpoint, your smartphone
usually being the endpoint itself and connected to a network, is not, making it therefore all the more practical for an attacker
to exploit the device and extract the keys stored within the apps, as such it becomes "something you know" compromising the
purpose of the two factor authentication, especially if all the factors are stored/used on the same device.

There is no such thing as good security, there is only bad security and worse security, security is only as good as its weakest link
therefore one needs to render his assets as secure as possible, making it time and effort consumming for an attacker to target him.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBCAAGBQJYd9f1AAoJEKa4nBz3AlIIGbQH/35OHAPKBjoOJbOnzF5AsjXg
aYIxaN3kGvd/69pUrV9Tm0CAnJJwmZBOWpYaI8eUCJGQIth7flOyajHh15iMnJ1s
R4JW+yn1W15Ya63XPawcoQt4Fo+dzAdR+kKMYLnh6YtgC5Fsq3EPQt5414RGwfyp
6dQ1U137rqJFUoqGKFquazP2w0pWyD7x9lnOAZi8t82iL7u3x0J+pWjJuEr5pBKx
fcAjgZAHIWV3esooE1s3NB3ggMEwvCzX8Fkf2p4NSK+dI+C5CWbBR5SViAxqxoQn
3Eb0WTkOCunm3ggsQJWB7JlGNEe2r1ZR1FANnMMW8LKy/yh/kFUaUFgum8tkoyw=
=vBU3
-----END PGP SIGNATURE-----

Well I don't have the funds to get a secure USB flash drive, so yeah, but I'm not going to be totally paranoid about security either, as it's a waste of energy.
 

mathieulh

Well-Known Member
Member
Joined
Feb 28, 2008
Messages
378
Trophies
0
Website
keybase.io
XP
897
Country
France
Well I don't have the funds to get a secure USB flash drive, so yeah, but I'm not going to be totally paranoid about security either, as it's a waste of energy.

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

It all comes down to how much you value your security and online privacy.
To me, it's worth spending the money on a $60 secure dongle.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBCAAGBQJYd9l4AAoJEKa4nBz3AlIIV8AIAIbnsAp6zjoeDF/T6YywoN9J
ogsfje9eizB6vRJ6qlqTjMD2/Pj9+kidypeLc9cqjizo25Jap3bYnelouvWmpeFp
XvyYL6NsdvPXCiyFRwm5fgLTK1HB4PuZtrvW5G/9IWexXllbYTt3EoBpwnMmjESY
nlsCOTTwRf1HA4nv467hXDPrkQxGQTofD6/IYUTqqdfVnh1YTuR1MRfLMjmoDgDJ
Wu4Ud1xkrdd+FW+QYrUG27c8R3u+WmvQK9wxFTu3G9UVYFeFSkCYCPe4iNey/iaj
P2gcJ4GI/dd+G8TobK4o0hkefKZHI+j5cRqq74GeWTy/f3YXVZXtoig6SrQQYH0=
=tqYk
-----END PGP SIGNATURE-----
 

Slattz

Easygoing Fairy
Member
Joined
Nov 21, 2015
Messages
1,259
Trophies
1
XP
1,787
Country
Ireland
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

It all comes down to how much you value your security and online privacy.
To me, it's worth spending the money on a $60 secure dongle.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBCAAGBQJYd9l4AAoJEKa4nBz3AlIIV8AIAIbnsAp6zjoeDF/T6YywoN9J
ogsfje9eizB6vRJ6qlqTjMD2/Pj9+kidypeLc9cqjizo25Jap3bYnelouvWmpeFp
XvyYL6NsdvPXCiyFRwm5fgLTK1HB4PuZtrvW5G/9IWexXllbYTt3EoBpwnMmjESY
nlsCOTTwRf1HA4nv467hXDPrkQxGQTofD6/IYUTqqdfVnh1YTuR1MRfLMjmoDgDJ
Wu4Ud1xkrdd+FW+QYrUG27c8R3u+WmvQK9wxFTu3G9UVYFeFSkCYCPe4iNey/iaj
P2gcJ4GI/dd+G8TobK4o0hkefKZHI+j5cRqq74GeWTy/f3YXVZXtoig6SrQQYH0=
=tqYk
-----END PGP SIGNATURE-----

No offense, but I don't think most people want to see the PGP stuff everytime you post, it's quite 'loud'... At least put the PGP signature in a spoiler or something.
 

mathieulh

Well-Known Member
Member
Joined
Feb 28, 2008
Messages
378
Trophies
0
Website
keybase.io
XP
897
Country
France
No offense, but I don't think most people want to see the PGP stuff everytime you post, it's quite 'loud'... At least put the PGP signature in a spoiler or something.

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Is that better?
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBCAAGBQJYd9vPAAoJEKa4nBz3AlIIt9sH/0fkanJdxpPPfgSkuylrmZC1
ojzLgi2/MLekvmqyJqv2WxNWigXZT8bnhFYiwR5e5AIISBwTeE9dQAzWlgcaOP+h
I/UN38JPk0ql/5V5LIJ71/WuL205EJwiTx/I6/63R1BK4Oqzui9tOm/7hvWzLFKH
48CV57T68hs9nVtaRtmXwWnQkM2QR04a9FAukgTjKBXnalBr4edpsNYWsPTl+Ha4
jP7RrpIMk6+EfX9Z+msvQoYDcHq7WvHBSmj+vwVXzJdZn6HsPfq10AQXeyyIBjHj
GrBzoX9SY2dOVZsbbbyU0X4BN8+AKXK3SUN6Dph1chnR8AUncqdv/UIf+Hh7T7k=
=cNqZ
-----END PGP SIGNATURE-----
 
  • Like
Reactions: Slattz

Kithron

Member
Newcomer
Joined
Apr 30, 2012
Messages
17
Trophies
1
Age
38
XP
430
Country
United States
Thank you for the information, changed my own password and enabled 2FA with my favorite app named Authy.
 

Slattz

Easygoing Fairy
Member
Joined
Nov 21, 2015
Messages
1,259
Trophies
1
XP
1,787
Country
Ireland
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Is that better?
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBCAAGBQJYd9vPAAoJEKa4nBz3AlIIt9sH/0fkanJdxpPPfgSkuylrmZC1
ojzLgi2/MLekvmqyJqv2WxNWigXZT8bnhFYiwR5e5AIISBwTeE9dQAzWlgcaOP+h
I/UN38JPk0ql/5V5LIJ71/WuL205EJwiTx/I6/63R1BK4Oqzui9tOm/7hvWzLFKH
48CV57T68hs9nVtaRtmXwWnQkM2QR04a9FAukgTjKBXnalBr4edpsNYWsPTl+Ha4
jP7RrpIMk6+EfX9Z+msvQoYDcHq7WvHBSmj+vwVXzJdZn6HsPfq10AQXeyyIBjHj
GrBzoX9SY2dOVZsbbbyU0X4BN8+AKXK3SUN6Dph1chnR8AUncqdv/UIf+Hh7T7k=
=cNqZ
-----END PGP SIGNATURE-----
Yea, thats good :D. Thanks for actually taking my advice, I honestly thought a fight would break out or something :ha:
 

mathieulh

Well-Known Member
Member
Joined
Feb 28, 2008
Messages
378
Trophies
0
Website
keybase.io
XP
897
Country
France
Yea, thats good :D. Thanks for actually taking my advice, I honestly thought a fight would break out or something :ha:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

To be honest, as it is, it might be breaking the signature, someone would need to manually append the content
of the spoiler to verify the post.

I hope this is enough, I am aware the whole PGP metadata can be annoying, it would be much better if forums had
built-in PGP support.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBCAAGBQJYd959AAoJEKa4nBz3AlII9eYIAKOknZJzv9fLg+edt1QOkHuu
yWzNDCZ45cfjkPTMIP3pG6UVF/uwKh/+YVsjE7ujIFtKIVp3hNWIYgxLy+hRT61O
CKhFyhIgp3HQHDItyd9IDqAG7wJpaHtvyLwoYuWPK20WEP0cPynlHnilFscfoVi4
O8y9AZ1RLsieOuXkAX/rn/ZifYg6STcE+xZJMKkimCW+hHc7PjWf0/ManUSAOV66
74sVKi41WuuhLXFal5T2DiOJ36r3jUkLNKHOzcrAs7k/F5tJqDeAfdpqKolI/+FA
+LIElNk/Sy4rfcfHUucdkwPYH2h5cczauyLPgOKu5Zv+bhMZZNKftwxOqkrWZa8=
=3MlM
-----END PGP SIGNATURE-----
 
D

Deleted User

Guest
A good idea to remember for secure passwords is that it's a lot harder to guess/brute-force a password that isn't in english. If you speak 2 languages, make your password in a different one/mix them.
Oohoho, NOBODY will guess my password if I make it in Esperanto!

....absolutely nobody.
 

Gizametalman

Banned!
Banned
Joined
Dec 18, 2015
Messages
974
Trophies
0
Age
30
Location
D.F. - Zona Cero.
XP
730
Country
Mexico
Ugh... not again.
Could anyone please answer this question:

If somehow the "hackers" has my email (the one I registered with in GBATemp) do you think they could possible get all those OTHER sites which I've used the same email account?
You know? Lots of personal information, like bank numbers, phone, how I managed to escape from La Migra, how I dismembered a human and eat it... ok, kiddig with this one.
But seriously, do you think that may be possible?
Because, if so, I'll be deleting all the accounts that I have in different sites.
¬_¬
 
  • Like
Reactions: Saiyan Lusitano

Joe88

[λ]
Global Moderator
Joined
Jan 6, 2008
Messages
12,736
Trophies
2
Age
36
XP
7,423
Country
United States
Ugh... not again.
Could anyone please answer this question:

If somehow the "hackers" has my email (the one I registered with in GBATemp) do you think they could possible get all those OTHER sites which I've used the same email account?
You know? Lots of personal information, like bank numbers, phone, how I managed to escape from La Migra, how I dismembered a human and eat it... ok, kiddig with this one.
But seriously, do you think that may be possible?
Because, if so, I'll be deleting all the accounts that I have in different sites.
¬_¬
if you used the same exact password on all those sites sites than yes
 
  • Like
Reactions: Deleted User

Gizametalman

Banned!
Banned
Joined
Dec 18, 2015
Messages
974
Trophies
0
Age
30
Location
D.F. - Zona Cero.
XP
730
Country
Mexico
if you used the same exact password on all those sites sites than yes
1234931504682.jpg


Meh, I don't have any friends anyways...
 
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    Psionic Roshambo @ Psionic Roshambo: https://m.youtube.com/watch?v=_NTF5_qgH0o