G oog le BadWeB | Login/out | Topics | Search | Custodians | Register | Edit Profile


Buell Forum » Quick Board » Archive through July 26, 2016 » Motorcycle.com passwords were breached... « Previous Next »

Author Message
Top of pagePrevious messageNext messageBottom of page Link to this message

Reepicheep
Posted on Thursday, June 23, 2016 - 11:56 am:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only) Ban Poster IP (Custodian/Admin only)

Verticalscope, the company that bought a number of sites, including Motorcycle.com, was running a very old version of vBulletin. Looks like the contact information and hashed password for 45 million users got stolen.

http://www.theregister.co.uk/2016/06/16/verticalsc ope_breach/

The passwords were hashed, but weakly, so over time probably half of these passwords will be brute force cracked.

Anyway, if you had a password you used there, and used it elsewhere, you probably want to change it everywhere.

In general, passwords have never been a very good control, and have always been used way beyond their practical strength. So turn on second factors for authentication everywhere you can for everything sensitive (like banking, email, ecommerce, etc).

Passwords alone a fairly weak but low friction control. They are fine for stuff that would just be basically a minor nuisance if the were compromised (for example this site).
Top of pagePrevious messageNext messageBottom of page Link to this message

Teeps
Posted on Thursday, June 23, 2016 - 12:54 pm:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only) Ban Poster IP (Custodian/Admin only)

Yeah, I've had email alerts from 2 forums about this.
One forum sent an alert and advised changing the password asap. Then a few hours later they changed my already changed password, then emailed info on what is going on.
Top of pagePrevious messageNext messageBottom of page Link to this message

Figorvonbuellingham
Posted on Thursday, June 23, 2016 - 06:37 pm:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only) Ban Poster IP (Custodian/Admin only)

I've had several forums change my passwords today. Must be a pretty big breach.
Top of pagePrevious messageNext messageBottom of page Link to this message

Teeps
Posted on Thursday, June 23, 2016 - 06:42 pm:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only) Ban Poster IP (Custodian/Admin only)

I'm up to 3 auto password changes as of an hour ago.
Top of pagePrevious messageNext messageBottom of page Link to this message

Ourdee
Posted on Thursday, June 23, 2016 - 10:00 pm:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only) Ban Poster IP (Custodian/Admin only)

Vtwin changed mine today.
Top of pagePrevious messageNext messageBottom of page Link to this message

Sifo
Posted on Friday, June 24, 2016 - 08:12 pm:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only) Ban Poster IP (Custodian/Admin only)

I had the s10forum change my password yesterday too. Must have been quite a breach.
Top of pagePrevious messageNext messageBottom of page Link to this message

Teeps
Posted on Saturday, June 25, 2016 - 10:27 am:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only) Ban Poster IP (Custodian/Admin only)

Got this notice today from AVS forum: http://www.verticalscope.com/about-us/notice-of-da ta-breach.html
Top of pagePrevious messageNext messageBottom of page Link to this message

Hybridmomentspass
Posted on Saturday, June 25, 2016 - 10:30 am:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only) Ban Poster IP (Custodian/Admin only)

yep, VS owns a TON of sites, so its spreadinglike wildfire
Top of pagePrevious messageNext messageBottom of page Link to this message

Pwnzor
Posted on Saturday, June 25, 2016 - 04:50 pm:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only) Ban Poster IP (Custodian/Admin only)

Sorry, but if you use your forum login for your banking then you are electronically retarded.
« Previous Next »

Add Your Message Here
Post:
Bold text Italics Underline Create a hyperlink Insert a clipart image

Username: Posting Information:
This is a public posting area. Enter your username and password if you have an account. Otherwise, enter your full name as your username and leave the password blank. Your e-mail address is optional.
Password:
E-mail:
Options: Post as "Anonymous" (Valid reason required. Abusers will be exposed. If unsure, ask.)
Enable HTML code in message
Automatically activate URLs in message
Action:

Topics | Last Day | Tree View | Search | User List | Help/Instructions | Rules | Program Credits Administration