Data Security Update 1/4/2019

Announcements made here about the game and the company.

Re: Data Security Update 1/4/2019

Postby shapesifter13 » Wed Jan 09, 2019 2:26 pm

Malfoydragon wrote:
Malfoydragon wrote:Has the malware, the hackers, and all traces of the hackers been removed?


I'd like a clear answer from staff on this please, because I changed my password to a temporary password, if everything is removed I can create a permanent password for this account.


We believe we have fixed all the holes, but we are having a security firm audit everything currently. Once they gives us the all clear we will be making every user change their password with a new force password reset feature we are working on.
shapesifter13
Developer
Developer
 
Posts: 4511
Joined: Fri Jan 02, 2015 4:55 pm

Re: Data Security Update 1/4/2019

Postby mdb1023 » Wed Jan 09, 2019 5:24 pm

Dammit I already changed my password. Can I change it and then change it back to what I have now?
Assassin House
Better watch your back; there's always a target on it!
March 22nd

Join the Forum Survivor Discord Server!

Forum Survivor "Wall of Winners:" Spoiler: Image
User avatar
mdb1023
Serial Killer
Serial Killer
 
Posts: 2137
Joined: Mon Mar 30, 2015 2:45 pm
Location: At work, rehearsal, or finishing whatever I pushed off to the last minute this time.

Re: Data Security Update 1/4/2019

Postby danzho55 » Wed Jan 09, 2019 9:46 pm

If my account was linked to my steam account, does that mean my steam info is compromised aswell? Also, since I forgot my old password a year ago, I've been resetting my password and just logging in with the password that was sent to my email. If I never bothered to update my password, does that mean they don't have my original password?
danzho55
Newbie
Newbie
 
Posts: 1
Joined: Sun Dec 20, 2015 9:05 pm

Re: Data Security Update 1/4/2019

Postby Jerme » Wed Jan 09, 2019 10:59 pm

danzho55 wrote:If my account was linked to my steam account, does that mean my steam info is compromised aswell? Also, since I forgot my old password a year ago, I've been resetting my password and just logging in with the password that was sent to my email. If I never bothered to update my password, does that mean they don't have my original password?

No Steaminfo was taken as far as I've seen, as only the forum DB was breached instead of the one of the game (in which only your Steam ID is saved in). Thus the hackers do not have gotten any Steaminfo on that (or onyl the email if you use the same for Steam and ToS). Only the hash of the passwor was taken, so with work they could decode it, but this cna take a while to be done.
Visit my role suggestions and give me feedback: http://www.blankmediagames.com/phpbb/viewtopic.php?f=27&t=28949

I tend to write small stories into my will and dislike Forgers and Janitors for removing them.

If you see a Grim Reaper called 'Zoroark', know that you might have encountered me.

Image
Occupation: A developers pain and joy (QA-fox), currently "hired" by Ralozey
User avatar
Jerme
Global Moderator
Global Moderator
 
Posts: 17813
Joined: Thu Apr 30, 2015 2:09 pm

Re: Data Security Update 1/4/2019

Postby Jerme » Thu Jan 10, 2019 11:33 am

Gutten wrote:Considering you are sending out plain text passwords through emails, I’d say you deserve what’s coming to you.

That password is supposed to be one use only in order to have it changed.
Visit my role suggestions and give me feedback: http://www.blankmediagames.com/phpbb/viewtopic.php?f=27&t=28949

I tend to write small stories into my will and dislike Forgers and Janitors for removing them.

If you see a Grim Reaper called 'Zoroark', know that you might have encountered me.

Image
Occupation: A developers pain and joy (QA-fox), currently "hired" by Ralozey
User avatar
Jerme
Global Moderator
Global Moderator
 
Posts: 17813
Joined: Thu Apr 30, 2015 2:09 pm

Re: Data Security Update 1/4/2019

Postby Phone0Ix » Thu Jan 10, 2019 11:54 am

shapesifter13 wrote:
Malfoydragon wrote:
Malfoydragon wrote:Has the malware, the hackers, and all traces of the hackers been removed?


I'd like a clear answer from staff on this please, because I changed my password to a temporary password, if everything is removed I can create a permanent password for this account.


We believe we have fixed all the holes, but we are having a security firm audit everything currently. Once they gives us the all clear we will be making every user change their password with a new force password reset feature we are working on.

Can you give a warning a week before the reset? Because I'm still afraid my friend will use their account with the password reset. In that way my friend can contact the admins when emails to your team are stopped being about the breach and he can contact you to get to change their email
Hey I'm Julian, a fan from ToS! If you want to have my Discord username or play a game of ToS, just PM me!

FM stats:
9 * Citizen
5 * TP
2 * TI
2 * TS
4 * Maf
Note: In role madness I chose alignment that was most like role. Further the Double>Fruit Vendor>BG was counted as TP
7-11-2
Also look this link: https://docs.google.com/spreadsheets/d/ ... sp=sharing
User avatar
Phone0Ix
[Forum Mafia XVII] Winner
[Forum Mafia XVII] Winner
 
Posts: 273
Joined: Sun Jul 24, 2016 11:00 am
Location: The Netherlands

Re: Data Security Update 1/4/2019

Postby TurdPile » Thu Jan 10, 2019 12:05 pm

Phone0Ix wrote:
shapesifter13 wrote:
Malfoydragon wrote:
Malfoydragon wrote:Has the malware, the hackers, and all traces of the hackers been removed?


I'd like a clear answer from staff on this please, because I changed my password to a temporary password, if everything is removed I can create a permanent password for this account.


We believe we have fixed all the holes, but we are having a security firm audit everything currently. Once they gives us the all clear we will be making every user change their password with a new force password reset feature we are working on.

Can you give a warning a week before the reset? Because I'm still afraid my friend will use their account with the password reset. In that way my friend can contact the admins when emails to your team are stopped being about the breach and he can contact you to get to change their email


He can change his account's email directly from the forums at any time.
Do not PM me about your open appeal. It will be ignored.

DISCLAIMER: I am a Moderator of the forums and the game.
I manage the clutter so the developers can do their work.
My voice and my opinions are of my own and shouldn't be taken as the
word of the developers (although I may be slightly more informed of
certain matters). Therefore, rude remarks I may occasionally make
should not impact the reputation of the developers.
Cheers.
User avatar
TurdPile
Developer
Developer
 
Posts: 7498
Joined: Tue Feb 11, 2014 10:25 am
Location: Massachusetts

Re: Data Security Update 1/4/2019

Postby Phone0Ix » Thu Jan 10, 2019 1:37 pm

TurdPile wrote:
Phone0Ix wrote:
shapesifter13 wrote:
Malfoydragon wrote:
Malfoydragon wrote:Has the malware, the hackers, and all traces of the hackers been removed?


I'd like a clear answer from staff on this please, because I changed my password to a temporary password, if everything is removed I can create a permanent password for this account.


We believe we have fixed all the holes, but we are having a security firm audit everything currently. Once they gives us the all clear we will be making every user change their password with a new force password reset feature we are working on.

Can you give a warning a week before the reset? Because I'm still afraid my friend will use their account with the password reset. In that way my friend can contact the admins when emails to your team are stopped being about the breach and he can contact you to get to change their email


He can change his account's email directly from the forums at any time.

But he got the inactive account bug
Hey I'm Julian, a fan from ToS! If you want to have my Discord username or play a game of ToS, just PM me!

FM stats:
9 * Citizen
5 * TP
2 * TI
2 * TS
4 * Maf
Note: In role madness I chose alignment that was most like role. Further the Double>Fruit Vendor>BG was counted as TP
7-11-2
Also look this link: https://docs.google.com/spreadsheets/d/ ... sp=sharing
User avatar
Phone0Ix
[Forum Mafia XVII] Winner
[Forum Mafia XVII] Winner
 
Posts: 273
Joined: Sun Jul 24, 2016 11:00 am
Location: The Netherlands

Re: Data Security Update 1/4/2019

Postby Jerme » Thu Jan 10, 2019 3:25 pm

In which regard? The account for the forum or the game?
Does the usage of this link work? http://www.blankmediagames.com/phpbb/uc ... resend_act
Visit my role suggestions and give me feedback: http://www.blankmediagames.com/phpbb/viewtopic.php?f=27&t=28949

I tend to write small stories into my will and dislike Forgers and Janitors for removing them.

If you see a Grim Reaper called 'Zoroark', know that you might have encountered me.

Image
Occupation: A developers pain and joy (QA-fox), currently "hired" by Ralozey
User avatar
Jerme
Global Moderator
Global Moderator
 
Posts: 17813
Joined: Thu Apr 30, 2015 2:09 pm

Re: Data Security Update 1/4/2019

Postby Flavorable » Thu Jan 10, 2019 5:15 pm

Jerme wrote:In which regard? The account for the forum or the game?
Does the usage of this link work? http://www.blankmediagames.com/phpbb/uc ... resend_act


Use this link: ucp.php?mode=resend_act
Steam ToS Moderator and Bug Report buttinsky.
Image
User avatar
Flavorable
Global Moderator
Global Moderator
 
Posts: 2105
Joined: Thu Apr 28, 2016 3:24 am
Location: Netherlands

Re: Data Security Update 1/4/2019

Postby PyromonkeyGG » Fri Jan 11, 2019 9:17 pm

We are working with a security firm and increasing our security. We are also creating easier to use pages to change your password (we know only changing it through phpbb isn't ideal) among other things.
User avatar
PyromonkeyGG
Developer
Developer
 
Posts: 2222
Joined: Mon Feb 10, 2014 5:32 pm

Re: Data Security Update 1/4/2019

Postby James2 » Fri Jan 11, 2019 10:00 pm

Hopefully the security firm can help you not use the same password for everything.
James2
Consigliere
Consigliere
 
Posts: 1250
Joined: Tue Jun 16, 2015 9:53 am

Re: Data Security Update 1/4/2019

Postby Aerle » Sun Jan 13, 2019 8:17 am

My password was changed to an automated one and I would like to change it to a password that I will remember. How do I do this?

Thank you.
Aerle
Newbie
Newbie
 
Posts: 1
Joined: Wed Mar 09, 2016 3:53 pm

Re: Data Security Update 1/4/2019

Postby Flavorable » Sun Jan 13, 2019 11:03 am

Aerle wrote:My password was changed to an automated one and I would like to change it to a password that I will remember. How do I do this?

Thank you.

ucp.php?i=profile&mode=reg_details
Steam ToS Moderator and Bug Report buttinsky.
Image
User avatar
Flavorable
Global Moderator
Global Moderator
 
Posts: 2105
Joined: Thu Apr 28, 2016 3:24 am
Location: Netherlands

Previous

Return to Announcements

Who is online

Users browsing this forum: No registered users and 3 guests