|
Your donations keep RPGWatch running!
RPGWatch Forums » General Forums » RPGWatch » Security Breach

Default Security Breach

January 14th, 2019, 03:00
I visited the Codex some years ago, just not to my liking. I'll hang around here until they kick me out!
Carnifex is offline

Carnifex

SasqWatch

#41

Join Date: Oct 2011
Location: Holly Hill, FL.
Posts: 15,222
Mentioned: 66 Post(s)

Default 

January 14th, 2019, 03:04
Originally Posted by Ragnaris View Post
I did not resort to visiting the, well, other place.
Me neither. There are more than enough other places of internet to occupy my interest(s).
--
Toka Koka
joxer is offline

joxer

joxer's Avatar
The Smoker
Original Sin 1 & 2 Donor

#42

Join Date: Apr 2009
Posts: 23,468
Mentioned: 230 Post(s)

Default 

January 14th, 2019, 09:09
Hash by itself is weak. You have to toss in some salt. Still if the algorithm is known it becomes weak for folks using weak passwords. Anyway there are many papers on the topic but brush up on your math. The best intercept is before the hash.

Originally Posted by rjshae View Post
If you aren't already, you might consider investigating SHA-3 for secure hashing, although SHA-2 is still pretty good.
you is offline

you

Lazy_dog
RPGWatch Donor
Original Sin 2 Donor

#43

Join Date: Oct 2006
Location: usa - no longer boston
Posts: 7,758
Mentioned: 63 Post(s)

Default 

January 14th, 2019, 09:50
Originally Posted by Capt. Huggy Face View Post
I know you didn't ask me, but I couldn't finish that review. I thought it was a load of pretentious tripe. And the Codex turns my stomach. It's just chock full of toadies so desperate to appear undenIably clever but not really having the chops. It's like 6th-grade chess club over there.
I can't finish their review most of the time…

purpleblob

Guest

#44

Posts: n/a
Mentioned: Post(s)

Default 

January 14th, 2019, 10:33
Originally Posted by azarhal View Post
I got one too, in my spam folder…but I had accounts on all the thing listed. :/
This is a security check if the mail can be found in https://haveibeenpwned.com/. The data in there is real and means that your account has been a subject of a leak at some point in time. If you didn't change the passwords on those sites, it would be wise to do so. Also on sites that you use the same passwords, if any. One can also subscribe on that site for security updates if a new leak is added.

On a different tune - I would rather like two factor authentication implemented on RPGWatch.
Bundyo is offline

Bundyo

Watchdog
Original Sin 1 & 2 Donor

#45

Join Date: Nov 2006
Posts: 110
Mentioned: 0 Post(s)

Default 

January 14th, 2019, 14:38
Originally Posted by Bundyo View Post
I would rather like two factor authentication implemented on RPGWatch.
Which one? SMS with giving away my phone number? Never. Just no. I refused to do it on Steam and I constantly click skip everywhere that's bugging me with that notoriety.
https://www.kaspersky.com/blog/2fa-p…l-guide/24219/
https://www.cnet.com/how-to/why-you-…-verification/

I'd rather leave a site or service before accepting SMS authentication.
--
Toka Koka
joxer is offline

joxer

joxer's Avatar
The Smoker
Original Sin 1 & 2 Donor

#46

Join Date: Apr 2009
Posts: 23,468
Mentioned: 230 Post(s)

Default 

January 14th, 2019, 17:12
Originally Posted by joxer View Post
Which one? SMS with giving away my phone number? Never. Just no. I refused to do it on Steam and I constantly click skip everywhere that's bugging me with that notoriety.
https://www.kaspersky.com/blog/2fa-p…l-guide/24219/
https://www.cnet.com/how-to/why-you-…-verification/

I'd rather leave a site or service before accepting SMS authentication.
The one in Steam doesn't work with SMSes - you need to use their mobile app for authentication. It is actually a form of time-based OTP (TOTP), so you can authenticate with any OTP generator that supports it, for instance KeePassXC.
Bundyo is offline

Bundyo

Watchdog
Original Sin 1 & 2 Donor

#47

Join Date: Nov 2006
Posts: 110
Mentioned: 0 Post(s)

Default 

January 14th, 2019, 19:42
Originally Posted by you View Post
Hash by itself is weak. You have to toss in some salt. Still if the algorithm is known it becomes weak for folks using weak passwords. Anyway there are many papers on the topic but brush up on your math. The best intercept is before the hash.
Yep. Ideally the password change page would include strength testing with an option for two-factor authentication and Captcha, then force everybody to change to the new standard.
rjshae is offline

rjshae

rjshae's Avatar
Periapt vs Paronomasia
RPGWatch Donor

#48

Join Date: Mar 2012
Location: Seattle
Posts: 5,325
Mentioned: 20 Post(s)

Default 

January 14th, 2019, 20:46
Yes but for a forum like this that is probably overkill. I mean the most they will get is your email but then again if they stole the database they have your email…

Originally Posted by rjshae View Post
Yep. Ideally the password change page would include strength testing with an option for two-factor authentication and Captcha, then force everybody to change to the new standard.
you is offline

you

Lazy_dog
RPGWatch Donor
Original Sin 2 Donor

#49

Join Date: Oct 2006
Location: usa - no longer boston
Posts: 7,758
Mentioned: 63 Post(s)

Default 

January 14th, 2019, 20:54
Since the link posted here allows you to change passwords with only access to the old password… doesn't that put inactive / rarely used accounts at risk? Because they may not change their password in time?
Cacheperl is offline

Cacheperl

Cacheperl's Avatar
SasqWatch

#50

Join Date: May 2012
Posts: 2,316
Mentioned: 17 Post(s)

Default 

January 14th, 2019, 21:13
Originally Posted by Bundyo View Post
The one in Steam doesn't work with SMSes - you need to use their mobile app for authentication. It is actually a form of time-based OTP (TOTP), so you can authenticate with any OTP generator that supports it, for instance KeePassXC.
To use Steam phone malware for authentication you need to give them your phone number.
It's called Steam Guard and the first thing it asks you is to provide them the phone number so they can sell it to 3rd parties.
--
Toka Koka
joxer is offline

joxer

joxer's Avatar
The Smoker
Original Sin 1 & 2 Donor

#51

Join Date: Apr 2009
Posts: 23,468
Mentioned: 230 Post(s)

Default 

January 14th, 2019, 21:47
I'm so sick of every damn Web-based account I have hounding me for my phone number, which I never give them.
Capt. Huggy Face is offline

Capt. Huggy Face

Capt. Huggy Face's Avatar
Aging Gamer
Original Sin 1 & 2 Donor

#52

Join Date: Sep 2010
Posts: 4,489
Mentioned: 18 Post(s)
+1:

Default 

January 15th, 2019, 00:40
I'm one of those troglodytes who doesn't own a mobile/cell phone, so I can't do any form of SMS !! Ah the joys of being old!!!!
--
If God said it, then that settles it!!

Editor@RPGWatch
Corwin is offline

Corwin

Corwin's Avatar
On The Razorblade of Life
Super Moderator
RPGWatch Team

#53

Join Date: Aug 2006
Location: Australia
Posts: 12,766
Mentioned: 72 Post(s)

Default 

January 15th, 2019, 00:41
Originally Posted by Corwin View Post
I'm one of those troglodytes who doesn't own a mobile/cell phone, so I can't do any form of SMS !! Ah the joys of being old!!!!
Then we are the last two on Earth without one.
HiddenX is offline

HiddenX

HiddenX's Avatar
The Elder Spy
RPGWatch Team
Original Sin 1 & 2 Donor

#54

Join Date: Oct 2006
Location: NRW/Germany
Posts: 15,147
Mentioned: 124 Post(s)

Default 

January 15th, 2019, 01:02
Originally Posted by Cacheperl View Post
Since the link posted here allows you to change passwords with only access to the old password… doesn't that put inactive / rarely used accounts at risk? Because they may not change their password in time?
No, as changing your password means you are sent an email, with a link you need to click in order to activate the change.
--
In the beginning the Universe was created. This has made a lot of people very angry and been widely regarded as a bad move. Douglas Adams
There are no facts, only interpretations. Nietzsche
Some cause happiness wherever they go; others whenever they go. Oscar Wilde
Myrthos is offline

Myrthos

Myrthos's Avatar
Cave Canem
Administrator
RPGWatch Team

#55

Join Date: Aug 2006
Location: Netherlands
Posts: 10,613
Mentioned: 202 Post(s)

Default 

January 15th, 2019, 03:50
Originally Posted by HiddenX View Post
Then we are the last two on Earth without one.
Three!
--
Doing Let's Plays Reviews in English now. Latest Video: Encased
Mostly playing Indie titles, including Strategy, Tactics and Roleplaying-Games.
And here is a list of all games I ever played.
Kordanor is offline

Kordanor

Kordanor's Avatar
Wastelander

#56

Join Date: Jun 2012
Posts: 4,320
Mentioned: 45 Post(s)
+1:

Default 

January 15th, 2019, 23:52
Just trying to say that there is no need for a phone number and SMSes for two factor authentication and increased security. A simple TOTP generator can be used for authentication (which does basically the same as your bank login tokens) - like how for instance 2FA is implemented in the completely OSS Mastodon and GitLab.
Bundyo is offline

Bundyo

Watchdog
Original Sin 1 & 2 Donor

#57

Join Date: Nov 2006
Posts: 110
Mentioned: 0 Post(s)

Default 

January 16th, 2019, 13:54
I'm not going to write a mod for vbulletin myself, so I would just select this one: https://www.dragonbyte-tech.com/stor…ntication.314/
--
In the beginning the Universe was created. This has made a lot of people very angry and been widely regarded as a bad move. Douglas Adams
There are no facts, only interpretations. Nietzsche
Some cause happiness wherever they go; others whenever they go. Oscar Wilde
Myrthos is offline

Myrthos

Myrthos's Avatar
Cave Canem
Administrator
RPGWatch Team

#58

Join Date: Aug 2006
Location: Netherlands
Posts: 10,613
Mentioned: 202 Post(s)

Default 

January 17th, 2019, 03:22
Not familiar with that specific mod but I've implemented TOTP with QR code for in-house tools and now that I'm familiar with it I would be willing to use it here. I dont like email or sms variants because it can be annoying to get to when needed. Not putting my phone number out there regardless as I get enough spam on my phone and is harder to ignore than email.

There are many free clients for TOTP from Microsoft, Google, Red Hat, including ones for Windows and iOS. Desktop clients are hard to use with just QR code as no camera but with the uri and copy+paste they are fine.

Also I thought self-salting systems like argon2, bcrypt or scrypt are current security hashing recommendations though bcrypt is no longer generally recommended but better than sha+salt. But again its not like my bank account info is stored here so not too worried either way.
figment is offline

figment

figment's Avatar
Keeper of the Watch
Original Sin 1 & 2 Donor

#59

Join Date: Apr 2010
Posts: 690
Mentioned: 0 Post(s)
+1:

Default 

January 18th, 2019, 00:12
Thanks Myrthos.

Account is restored.
Dagar is offline

Dagar

Watcher

#60

Join Date: Oct 2006
Posts: 84
Mentioned: 1 Post(s)
RPGWatch Forums » General Forums » RPGWatch » Security Breach

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

All times are GMT +2. The time now is 09:30.
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2022, vBulletin Solutions Inc.
vBulletin Security provided by DragonByte Security (Pro) - vBulletin Mods & Addons Copyright © 2022 DragonByte Technologies Ltd.
User Alert System provided by Advanced User Tagging (Lite) - vBulletin Mods & Addons Copyright © 2022 DragonByte Technologies Ltd.
Copyright by RPGWatch