Bitcoin Forum

Other => Meta => Topic started by: Souldream on May 26, 2015, 01:30:50 PM



Title: Forum security breach ?
Post by: Souldream on May 26, 2015, 01:30:50 PM
I received this ...  from

Return-Path: <noreply@bitcointalk.org>
Received: from bitcointalk.org (node-186-2-165-183.reverse.x4b.me. [186.2.165.183])

=> ??? All infos from the server are in wild ?

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

You are receiving this message because your email address is associated
with an account on bitcointalk.org. I regret to have to inform you that
some information about your account was obtained by an attacker who
successfully compromised the bitcointalk.org server. The following
information about your account was likely leaked:
 - Email address
 - Password hash
 - Last-used IP address and registration IP address
 - Secret question and a basic (not brute-force-resistant) hash of your
 secret answer
 - Various settings

You should immediately change your forum password and delete or change
your secret question. To do this, log into the forum, click "profile",
and then go to "account related settings".

If you used the same password on bitcointalk.org as on other sites, then
you should also immediately change your password on those other sites.
Also, if you had a secret question set, then you should assume that the
attacker now knows the answer to your secret question.

Your password was salted and hashed using sha256crypt with 7500 rounds.
This will slow down anyone trying to recover your password, but it will
not completely prevent it unless your password was extremely strong.

While nothing can ever be ruled out in these sorts of situations, I do
not believe that the attacker was able to collect any forum personal
messages.

I apologize for the inconvenience and for any trouble that this may cause.
-----BEGIN PGP SIGNATURE-----

iF4EAREIAAYFAlVhiGIACgkQxlVWk9q1keeUmgEAhGi8pTghxISo1feeXkUMhW3a
uKxLeOOkTQR5Zh7aGKoBAMEvYsGEBGt3hzInIh+k43XJjGYywSiPAal1KI7Arfs0
=bvuI
-----END PGP SIGNATURE-----


Title: Re: Forum security breach ?
Post by: DannyHamilton on May 26, 2015, 01:33:17 PM
I received this ...  from

Return-Path: <noreply@bitcointalk.org>
Received: from bitcointalk.org (node-186-2-165-183.reverse.x4b.me. [186.2.165.183])

=> ??? All infos from the server are in wild ?

Possibly.

At least the following:

Quote
- Email address
 - Password hash
 - Last-used IP address and registration IP address
 - Secret question and a basic (not brute-force-resistant) hash of your
 secret answer
 - Various settings


Title: Re: Forum security breach ?
Post by: Dannie on May 26, 2015, 01:59:55 PM
In case you haven't read it yet, you should take a look at theymos's official report on the incident on https://bitcointalk.org/index.php?topic=1067985.0.

Vod reported getting a spam email, so it is likely the email address list has already been sold. :(
Received my first spam email last night.   :-[



Title: Re: Forum security breach ?
Post by: philipma1957 on May 26, 2015, 02:02:19 PM
@ op  I just spent 2 days changing passwords  on 100+ sites.   I am not done and need to pm Theymos about my main account (this one) later today.



@ danny h

I no longer have a paid signature.  As I have decided Danny H. has a good point about paid signatures


Title: Re: Forum security breach ?
Post by: R5D4 on May 26, 2015, 02:20:23 PM
 >:( >:( >:( >:( >:(

i didnt remember my password - but i think this forum here, will be attacked more and more, so i wanna leave it... - how can i delete my profile ? (to get out of the attack line.... I dont need more pishing shit on my emailadress !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!


Title: Re: Forum security breach ?
Post by: Jeff on May 26, 2015, 02:30:36 PM
I don't want my account here any more.  Could you please delete my account?  Or send me an email with instructions to do it.  I don't see any way of doing it myself.

Thanks


Title: Re: Forum security breach ?
Post by: heredoggeedoggee on May 26, 2015, 02:46:43 PM
I agree with Jeff. I would like to delete my account, could someone provide instructions on how to do so? I saw no such option under the profile section of the site.

Thanks


Title: Re: Forum security breach ?
Post by: gabranth on May 26, 2015, 02:59:08 PM
Another security breach stole my random password and alt email scary.


Title: Re: Forum security breach ?
Post by: heredoggeedoggee on May 26, 2015, 03:02:05 PM
Did some homework and I'm back with disheartening news. According to several posters in the Meta Section, it seems like there is no way to delete your own account nor to get it deleted. The best advice given is to change all your account details and walk away. This is, my opinion an unacceptable alternative, especially in the face of a hack like the one the forum just experienced.

Source: https://bitcointalk.org/index.php?topic=1068627.0


Title: Re: Forum security breach ?
Post by: monsterlynn on May 26, 2015, 03:19:27 PM
 ???

Can't remember my password to change it and the reminder button, it does nothing.

I'd like to just delete my account and start over with a new one (not on these boards that often).

Got my first spam moments ago.  :-[


Title: Re: Forum security breach ?
Post by: RodeoX on May 26, 2015, 03:22:30 PM
If you want to get rid of your account I think you will have to delete your posts one by one, then set your password to an impossibly long one and forget it.


Title: Re: Forum security breach ?
Post by: sms906 on May 26, 2015, 05:49:27 PM
I got the same message today, and I never use bitcoin, and for some idiotic reason, I can not find a way to delete my forum account, nor is there any way to contact anyone about it. I've been to my account settings, but there is no option to 'delete account' there. This is stupid, imo.


Title: Re: Forum security breach ?
Post by: Baticusdt on May 26, 2015, 07:43:33 PM
Yeap i just now received E-mail how my e-mail & account have been breach. Jeez thanks a lot. So i always been right humanity stinks to high heaven


Title: Re: Forum security breach ?
Post by: hckdmyb on May 26, 2015, 08:11:28 PM
I recvd the same email, then i get an email from cryptsy saying there has been a failed ateempt at my password.

Luckily theyre different.


Title: Re: Forum security breach ?
Post by: vm1990 on May 27, 2015, 12:11:38 AM
Did some homework and I'm back with disheartening news. According to several posters in the Meta Section, it seems like there is no way to delete your own account nor to get it deleted. The best advice given is to change all your account details and walk away. This is, my opinion an unacceptable alternative, especially in the face of a hack like the one the forum just experienced.

Source: https://bitcointalk.org/index.php?topic=1068627.0

you know if thats true then this place breaks EU law. "the right to be forgotten" its the same law that force facebook to add a delete button... just saying :)

as for deleting account remove all info and delete anything you dont want people seeing. randomly generate a long ass password and leave the account


Title: Re: Forum security breach ?
Post by: grue on May 27, 2015, 01:45:04 AM
Did some homework and I'm back with disheartening news. According to several posters in the Meta Section, it seems like there is no way to delete your own account nor to get it deleted. The best advice given is to change all your account details and walk away. This is, my opinion an unacceptable alternative, especially in the face of a hack like the one the forum just experienced.

Source: https://bitcointalk.org/index.php?topic=1068627.0

you know if thats true then this place breaks EU law. "the right to be forgotten" its the same law that force facebook to add a delete button... just saying :)

as for deleting account remove all info and delete anything you dont want people seeing. randomly generate a long ass password and leave the account
the forum operates outside of the EU, so I doubt anything will happen.


Title: Re: Forum security breach ?
Post by: R5D4 on May 27, 2015, 09:46:18 AM
LET US REMOVE OUR ACCOUNTS !!!

Update:

Ok, now i changed my mailadress to a throw away temponary-one, and my password to password...

- but ACC Delete would be much better... - i mean: what if people, who wanna be deleted, start offend people and linking porn here, just to be deleted ?

This here should not be a prison for parts of personal data - when people like to bury them, let them do it ! - Not, cause a law says , but because the people  are the one who make those laws... - Users are people too !