Bitcoin Forum
May 24, 2024, 01:08:48 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Why are so many accounts being reported as hacked?  (Read 206 times)
Jet Cash (OP)
Legendary
*
Offline Offline

Activity: 2716
Merit: 2457


https://JetCash.com


View Profile WWW
May 17, 2018, 06:56:37 AM
 #1

The forum login doesn't appear to be particularly vulnerable to me, and the use of a decent anti-virus package should provide some additional protection. My instinct is to believe that most of the hacked accounts are sold accounts, but I'm not sure that reporting them would be of much benefit.

The other alternative is a lack of sensible precautions. Leaving a computer logged into Bitcoin Talk whilst you go to the 'loo, or some other place, would seem to be pretty stupid if you are posting from a location with other computer users nearby. Allowing your browser to supply passwords is fine if you are sure nobody else will use your machine, but if you are in a dormitory, and leave your machine unattended, then it may not be the most sensible thing to do.

So do we have a profile of the people who are losing their accounts? Are most of them posting from educational establishments or libraries?

Offgrid campers allow you to enjoy life and preserve your health and wealth.
Save old Cars - my project to save old cars from scrapage schemes, and to reduce the sale of new cars.
My new Bitcoin transfer address is - bc1q9gtz8e40en6glgxwk4eujuau2fk5wxrprs6fys
bitperson
Full Member
***
Offline Offline

Activity: 210
Merit: 119


View Profile
May 17, 2018, 07:00:44 AM
 #2

My guesses would be phishing (the lookalike .to site, with its high placement in Google results, seems like a perfect way to collect Bitcointalk passwords) and password stealing malware disguised e.g. as altcoin wallets.

How to ask questions the smart way
When you’re happy with the answers in a thread you have started, please click ‘lock topic’ to prevent spam.
1AWrZWnN4ThpGB5z24WTzsoZRMqvLpDGYU
actmyname
Copper Member
Legendary
*
Offline Offline

Activity: 2562
Merit: 2504


Spear the bees


View Profile WWW
May 17, 2018, 07:05:45 AM
 #3

Account sale -> Report as hacked -> Easy scam, especially with the new email resets.

TheQuin
Hero Member
*****
Offline Offline

Activity: 2576
Merit: 882


Freebitco.in Support https://bit.ly/2I9BVS2


View Profile WWW
May 17, 2018, 07:09:36 AM
Last edit: May 17, 2018, 10:29:58 AM by TheQuin
 #4

Two big reasons I know of:

a) The forum was hacked back in 2015 and the encrypted database is available on the darknet. Accounts with weak passwords are vulnerable to being brute forced.

b) The .to and other phishing sites masquerading as mirror sites. They often show up on a Google search ahead of the real site.

freebitcoin.TO WIN A  LAMBORGHINI!..

.
                                ▄▄▄▄▄▄▄▄▄▄███████████▄▄▄▄▄
                    ▄▄▄▄▄██████████████████████████████████▄▄▄▄
                    ▀██████████████████████████████████████████████▄▄▄
                    ▄▄████▄█████▄████████████████████████████▄█████▄████▄▄
                    ▀████████▀▀▀████████████████████████████████▀▀▀██████████▄
                      ▀▀▀████▄▄▄███████████████████████████████▄▄▄██████████
                           ▀█████▀  ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀  ▀█████▀▀▀▀▀▀▀▀▀▀
                   ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
hilariousetc
Legendary
*
Offline Offline

Activity: 2800
Merit: 3030


Join the world-leading crypto sportsbook NOW!


View Profile
May 17, 2018, 07:15:12 AM
 #5

Account sale -> Report as hacked -> Easy scam, especially with the new email resets.

Well it would be an easy scam if people ever got their accounts back. Those that didn't change their passwords since the forum breach is the main reason. Most people probably get them hacked by either downloading malware or logging onto phishing sites.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
demonic098
Jr. Member
*
Offline Offline

Activity: 252
Merit: 2

Ximply for president!!!


View Profile
May 17, 2018, 07:39:09 AM
 #6

Two big reasons I know of:

a) The forum was hacked back in 2015 and the encrypted database is available on the darknet. Accounts with week passwords are vulnerable to being brute forced.

b) The .to and other phishing sites masquerading as mirror sites. They often show up on a Google search ahead of the real site.

Good day Quin Wink

For A. I don't think brute force will work well here, In our login form we have a captcha and that will prevent brute force + we have a limit on incorrect passwords.

For B. The phishing site has a captcha error so I think it wouldn't work anymore(hopefully). Plus an experienced member here has a "hairstrand" of a chance get phished by that site because a lot of members here is aware of that phishing site but we should still spread the word.

I hope one of those accounts that have been hacked share his/her statement here Wink.

Buy me a drink ETH: 0xED47aFa721e4228Bf19434aDDB1B79E740822540
TheQuin
Hero Member
*****
Offline Offline

Activity: 2576
Merit: 882


Freebitco.in Support https://bit.ly/2I9BVS2


View Profile WWW
May 17, 2018, 07:51:03 AM
 #7

Good day Quin Wink

For A. I don't think brute force will work well here, In our login form we have a captcha and that will prevent brute force + we have a limit on incorrect passwords.

They can buy the database that has an MD5 hash of the password and brute force it offline.

For B. The phishing site has a captcha error so I think it wouldn't work anymore(hopefully).

That's good news but there will be many more phishing sites to replace it.

Plus an experienced member here has a "hairstrand" of a chance get phished by that site because a lot of members here is aware of that phishing site but we should still spread the word.

It's the far greater number of inexperienced members that are getting hacked.

freebitcoin.TO WIN A  LAMBORGHINI!..

.
                                ▄▄▄▄▄▄▄▄▄▄███████████▄▄▄▄▄
                    ▄▄▄▄▄██████████████████████████████████▄▄▄▄
                    ▀██████████████████████████████████████████████▄▄▄
                    ▄▄████▄█████▄████████████████████████████▄█████▄████▄▄
                    ▀████████▀▀▀████████████████████████████████▀▀▀██████████▄
                      ▀▀▀████▄▄▄███████████████████████████████▄▄▄██████████
                           ▀█████▀  ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀  ▀█████▀▀▀▀▀▀▀▀▀▀
                   ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
lebrone08
Jr. Member
*
Offline Offline

Activity: 142
Merit: 2


View Profile
May 17, 2018, 08:38:59 AM
 #8

The forum login doesn't appear to be particularly vulnerable to me, and the use of a decent anti-virus package should provide some additional protection. My instinct is to believe that most of the hacked accounts are sold accounts, but I'm not sure that reporting them would be of much benefit.

The other alternative is a lack of sensible precautions. Leaving a computer logged into Bitcoin Talk whilst you go to the 'loo, or some other place, would seem to be pretty stupid if you are posting from a location with other computer users nearby. Allowing your browser to supply passwords is fine if you are sure nobody else will use your machine, but if you are in a dormitory, and leave your machine unattended, then it may not be the most sensible thing to do.

So do we have a profile of the people who are losing their accounts? Are most of them posting from educational establishments or libraries?

phising is number reason why theirs a  lot of account have been scam. most of the scammer send a personal message were in, if you open the links it will automatically copied all your important information so better stay away from all the message that is not related from you or anonymous sender.
Jet Cash (OP)
Legendary
*
Offline Offline

Activity: 2716
Merit: 2457


https://JetCash.com


View Profile WWW
May 17, 2018, 09:05:18 AM
 #9

Thanks for all the replies guys, and I hope that a few members will read the thread, and avoid losing their accounts.

I forgot about phishing, probably because I use direct navigation instead of clicking links in email. In fact the google omnibox has become a real nuisance for me, and I may put some direct navigation boxes on some of my pages to bypass Google.

Offgrid campers allow you to enjoy life and preserve your health and wealth.
Save old Cars - my project to save old cars from scrapage schemes, and to reduce the sale of new cars.
My new Bitcoin transfer address is - bc1q9gtz8e40en6glgxwk4eujuau2fk5wxrprs6fys
hugeblack
Legendary
*
Offline Offline

Activity: 2520
Merit: 3688


View Profile WWW
May 17, 2018, 01:01:09 PM
 #10

Two big reasons I know of:
a) The forum was hacked back in 2015, and the encrypted database is available on the darknet. Accounts with weak passwords are vulnerable to being brute forced.
b) The .to and other phishing sites masquerading as mirror sites. They often show up on a Google search ahead of the real site.

c) BitcoinTalk mobile Apps: Many unofficial applications appear on Google Play.
d) Fake ICOs: Many require to create a new account"any jobs related to username and password" and add bitcointalk information "People usually use the same password for all accounts."

Plus traditional methods of hacking accounts" hacking emails, secret Question,...."
LTU_btc
Legendary
*
Offline Offline

Activity: 3066
Merit: 1337


Slava Ukraini!


View Profile WWW
May 17, 2018, 05:06:04 PM
 #11

I can tell you from my own experience, why my account was hacked. I just didn't cared much about security. I used weak password and no 2FA on my email. No surprise - it was hacked. Then hacker changed my bitcointalk password with "Forgot your password?" function, later he changed email address of bitcointalk. Luckily, I was able to recover my account by signing a message from staked Bitcoin address. It was very good lesson for me that I need to secure my mail, exchange and other accounts with strong unique passwords and 2FA.

BTCeminjas
Member
**
Offline Offline

Activity: 322
Merit: 23


View Profile
May 17, 2018, 06:27:35 PM
 #12

That's the reason why we are the one who has a responsibility to keep safe our password in bitcointalk account and email account, don't make do the same password in your email account in bitcointalk account or even other accounts. Recently issues that having a phishing link in bitcointalk that fooled people and that was probably the cause when you log in a wrong website.

***-SNIP-
d) Fake ICOs: Many require to create a new account"any jobs related to username and password" and add bitcointalk information "People usually use the same password for all accounts."

Plus traditional methods of hacking accounts" hacking emails, secret Question,...."
Exactly, maybe one of the reasons those ICO intended a scam to their participants.
Or those signing in airdrops also be careful on that.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!