Data Security Update 1/4/2019

Announcements made here about the game and the company.

Data Security Update 1/4/2019

Postby Achilles » Fri Jan 04, 2019 4:28 pm

We are in the process of finishing a contract with a professional security firm to audit our servers and guarantee we are safe. After that has been conducted we will be making some sweeping changes to force a password reset on all accounts as well as change our hashing algorithm to be something more secure. Were hoping to do all of this in one pass to make it as convenient as possible for our users. We have also added 2FA to admin accounts on PHPBB as a temporary measure and will be looking to migrate to a newer forum technology as a long term solution.

We are also in the process of forcing everything on the website to go through https.

Addition by TurdPile: Forums have been toggled to prefer HTTPS. Users may experience weirdness trying to log into the forums if they are not using HTTPS. (https:// in the URL). This will persist until everything is done being forced to HTTPS. If you are having this issue, just add the s to "http" to the URL.
User avatar
Achilles
Developer
Developer
 
Posts: 1038
Joined: Sat Feb 08, 2014 5:02 pm

Re: Data Security Update 1/4/2019

Postby Chemist1422 » Fri Jan 04, 2019 4:30 pm

Will people who changed their passwords after the announcement have to change it again?
mist ~ she/her

i guess this is goodbye?
(still here for danganronpa i guess)


stop sending reports to me i'm not a tos game moderator
User avatar
Chemist1422
FM Game Moderator
FM Game Moderator
 
Posts: 1026
Joined: Tue Mar 20, 2018 5:39 pm
Location: on the beach at dusk (CST/CDT)

Re: Data Security Update 1/4/2019

Postby Achilles » Fri Jan 04, 2019 4:39 pm

Chemist1422 wrote:Will people who changed their passwords after the announcement have to change it again?


Most likely yes. The only way to be sure an account wasn't compromised will be to force a password reset through the registered email to the account. I realize some users may have used a fake email or lost their registered email to their accounts but we don't believe there is any other way to insure the integrity of accounts after the breach. Our community manager will respond to emails and help anyone he can that has proof of their account (valid receipts or Steam link proof for example). If an account has never made any kind of purchase and doesn't have a valid email registered to the account it will end up lost unfortunately but there isn't much else we can do about the scenario. Users should start making sure their account has a valid registered email. They should be able to update their email through the forums.
User avatar
Achilles
Developer
Developer
 
Posts: 1038
Joined: Sat Feb 08, 2014 5:02 pm

Re: Data Security Update 1/4/2019

Postby Technetium » Fri Jan 04, 2019 4:43 pm

So, the setup is, in order to perform a password reset when this happens, it will be via an email sent to the address associated with the account? Do I have that right?
Image

In memory of those who have been deleted.
The last poster to survive Blindside Island will win a cookie. Or perhaps 1500...
Technetium#8515 on Discord
User avatar
Technetium
Godfather
Godfather
 
Posts: 1941
Joined: Fri Dec 18, 2015 8:25 am
Location: The city, she's been dead, for years now...

Re: Data Security Update 1/4/2019

Postby Phone0Ix » Fri Jan 04, 2019 4:43 pm

Achilles wrote:
Chemist1422 wrote:Will people who changed their passwords after the announcement have to change it again?


Most likely yes. The only way to be sure an account wasn't compromised will be to force a password reset through the registered email to the account. I realize some users may have used a fake email or lost their registered email to their accounts but we don't believe there is any other way to insure the integrity of accounts after the breach. Our community manager will respond to emails and help anyone he can that has proof of their account (valid receipts or Steam link proof for example). If an account has never made any kind of purchase and doesn't have a valid email registered to the account it will end up lost unfortunately but there isn't much else we can do about the scenario. Users should start making sure their account has a valid registered email. They should be able to update their email through the forums.

A friend of mine wasn't able to log in to the forums because account was inactive while he got Coven and stuff. Is it possible the email ended up being non valid after being valid for a while?
Call me Phone Ig

Or Silver because of my old discord name. Or Mikan because of my new discord name. Or Julian as that's my actual name
User avatar
Phone0Ix
[Forum Mafia XVII] Winner
[Forum Mafia XVII] Winner
 
Posts: 429
Joined: Sun Jul 24, 2016 11:00 am
Location: The Netherlands

Re: Data Security Update 1/4/2019

Postby Achilles » Fri Jan 04, 2019 4:44 pm

Technetium wrote:So, the setup is, in order to perform a password reset when this happens, it will be via an email sent to the address associated with the account? Do I have that right?


Correct. There will be a random unique string generated in the email that will be used to verify legitimate email access upon the link redirect. Very similar to how email verification works.
User avatar
Achilles
Developer
Developer
 
Posts: 1038
Joined: Sat Feb 08, 2014 5:02 pm

Re: Data Security Update 1/4/2019

Postby Achilles » Fri Jan 04, 2019 4:47 pm

Phone0Ix wrote:
Achilles wrote:
Chemist1422 wrote:Will people who changed their passwords after the announcement have to change it again?


Most likely yes. The only way to be sure an account wasn't compromised will be to force a password reset through the registered email to the account. I realize some users may have used a fake email or lost their registered email to their accounts but we don't believe there is any other way to insure the integrity of accounts after the breach. Our community manager will respond to emails and help anyone he can that has proof of their account (valid receipts or Steam link proof for example). If an account has never made any kind of purchase and doesn't have a valid email registered to the account it will end up lost unfortunately but there isn't much else we can do about the scenario. Users should start making sure their account has a valid registered email. They should be able to update their email through the forums.

A friend of mine wasn't able to log in to the forums because account was inactive while he got Coven and stuff. Is it possible the email ended up being non valid after being valid for a while?


Due to a bug a long time ago in the past there are some accounts that have no registered email. We are hoping to work on specialty code to handle these accounts and help them get a valid email setup. They can email us ahead of time to get help setting one up as well, but response time may take a while. As you could imagine we are getting a lot of emails requesting account deletion and other information about what happened so emails are backed up.
User avatar
Achilles
Developer
Developer
 
Posts: 1038
Joined: Sat Feb 08, 2014 5:02 pm

Re: Data Security Update 1/4/2019

Postby Phone0Ix » Fri Jan 04, 2019 4:49 pm

Achilles wrote:
Phone0Ix wrote:
Achilles wrote:
Chemist1422 wrote:Will people who changed their passwords after the announcement have to change it again?


Most likely yes. The only way to be sure an account wasn't compromised will be to force a password reset through the registered email to the account. I realize some users may have used a fake email or lost their registered email to their accounts but we don't believe there is any other way to insure the integrity of accounts after the breach. Our community manager will respond to emails and help anyone he can that has proof of their account (valid receipts or Steam link proof for example). If an account has never made any kind of purchase and doesn't have a valid email registered to the account it will end up lost unfortunately but there isn't much else we can do about the scenario. Users should start making sure their account has a valid registered email. They should be able to update their email through the forums.

A friend of mine wasn't able to log in to the forums because account was inactive while he got Coven and stuff. Is it possible the email ended up being non valid after being valid for a while?


Due to a bug a long time ago in the past there are some accounts that have no registered email. We are hoping to work on specialty code to handle these accounts and help them get a valid email setup. They can email us ahead of time to get help setting one up as well, but response time may take a while. As you could imagine we are getting a lot of emails requesting account deletion and other information about what happened so emails are backed up.

Ok, but while it be handled before the password clearings?
Call me Phone Ig

Or Silver because of my old discord name. Or Mikan because of my new discord name. Or Julian as that's my actual name
User avatar
Phone0Ix
[Forum Mafia XVII] Winner
[Forum Mafia XVII] Winner
 
Posts: 429
Joined: Sun Jul 24, 2016 11:00 am
Location: The Netherlands

Re: Data Security Update 1/4/2019

Postby YFYDB » Fri Jan 04, 2019 4:51 pm

I am so glad that we will be safe ^^
Okey so. I have normal not fake e-mail so i will survive it.
EDIT: Btw, Achilles check ur forum dms.
My avatar is a random picture found in the internet.
User avatar
YFYDB
Witch
Witch
 
Posts: 41
Joined: Thu Aug 03, 2017 9:08 am

Re: Data Security Update 1/4/2019

Postby williewest » Fri Jan 04, 2019 4:53 pm

Any possibility in the future of setting up a secure security questions system so people will be able to prove ownership of an account they might have lost access to or has outdated email, lost password, etc.?
Everything in my signature is a clickable link
Image
Spoiler: Discord: William#2527


Image
User avatar
williewest
Transporter
Transporter
 
Posts: 121
Joined: Fri Nov 13, 2015 7:32 pm
Location: Pensacola, Florida

Re: Data Security Update 1/4/2019

Postby Achilles » Fri Jan 04, 2019 4:55 pm

williewest wrote:Any possibility in the future of setting up a secure security questions system so people will be able to prove ownership of an account they might have lost access to or has outdated email, lost password, etc.?


Yeah this would be a great add in the future.
User avatar
Achilles
Developer
Developer
 
Posts: 1038
Joined: Sat Feb 08, 2014 5:02 pm

Re: Data Security Update 1/4/2019

Postby TurdPile » Fri Jan 04, 2019 5:01 pm

Achilles wrote:
williewest wrote:Any possibility in the future of setting up a secure security questions system so people will be able to prove ownership of an account they might have lost access to or has outdated email, lost password, etc.?


Yeah this would be a great add in the future.


I'm willing to bet Vanilla has this built-in already
I have mostly rescinded my role as Admin.

All previous contact should instead be redirected to Flavorable.

If your inquiry doesn't directly have to do with Trial 2.0 or TrialBot, then please refrain from messaging.

Thank you.
User avatar
TurdPile
Vampire
Vampire
 
Posts: 8900
Joined: Tue Feb 11, 2014 10:25 am
Location: Massachusetts

Re: Data Security Update 1/4/2019

Postby Flavorable » Fri Jan 04, 2019 5:03 pm

Achilles wrote:
williewest wrote:Any possibility in the future of setting up a secure security questions system so people will be able to prove ownership of an account they might have lost access to or has outdated email, lost password, etc.?


Yeah this would be a great add in the future.


Tiny thing, Josh. If I log in and click on "Return to index page" it logs me back out.
Not sure if it was just bad timing on my part, or if there's some kind of relay issue.
No reply to your support ticket after 15 business days? PM me with your ticket number.

You may PM me for clarifications on appeal verdicts, but keep in mind the verdict will not change.

Do you have 151+ games played and want to help rid the community of toxic players and gamethrowers? Join the Trial System today: https://www.blankmediagames.com/Trial/#start

Also, check out the Trial System Discord Server: https://discord.gg/K5SnyJS
User avatar
Flavorable
Global Moderator
Global Moderator
 
Posts: 9337
Joined: Thu Apr 28, 2016 3:24 am
Location: Netherlands

Re: Data Security Update 1/4/2019

Postby TurdPile » Fri Jan 04, 2019 5:04 pm

Flavorable wrote:
Achilles wrote:
williewest wrote:Any possibility in the future of setting up a secure security questions system so people will be able to prove ownership of an account they might have lost access to or has outdated email, lost password, etc.?


Yeah this would be a great add in the future.


Tiny thing, Josh. If I log in and click on "Return to index page" it logs me back out.
Not sure if it was just bad timing on my part, or if there's some kind of relay issue.


Read the first post, I made a mention of this
I have mostly rescinded my role as Admin.

All previous contact should instead be redirected to Flavorable.

If your inquiry doesn't directly have to do with Trial 2.0 or TrialBot, then please refrain from messaging.

Thank you.
User avatar
TurdPile
Vampire
Vampire
 
Posts: 8900
Joined: Tue Feb 11, 2014 10:25 am
Location: Massachusetts

Re: Data Security Update 1/4/2019

Postby Flavorable » Fri Jan 04, 2019 5:05 pm

TurdPile wrote:
Flavorable wrote:
Achilles wrote:
williewest wrote:Any possibility in the future of setting up a secure security questions system so people will be able to prove ownership of an account they might have lost access to or has outdated email, lost password, etc.?


Yeah this would be a great add in the future.


Tiny thing, Josh. If I log in and click on "Return to index page" it logs me back out.
Not sure if it was just bad timing on my part, or if there's some kind of relay issue.


Read the first post, I made a mention of this


Awesome. That wasn't there yet when I posted. :D Thanks.
No reply to your support ticket after 15 business days? PM me with your ticket number.

You may PM me for clarifications on appeal verdicts, but keep in mind the verdict will not change.

Do you have 151+ games played and want to help rid the community of toxic players and gamethrowers? Join the Trial System today: https://www.blankmediagames.com/Trial/#start

Also, check out the Trial System Discord Server: https://discord.gg/K5SnyJS
User avatar
Flavorable
Global Moderator
Global Moderator
 
Posts: 9337
Joined: Thu Apr 28, 2016 3:24 am
Location: Netherlands

Re: Data Security Update 1/4/2019

Postby FrankLeeAwful » Fri Jan 04, 2019 5:23 pm

Force-logged on another tab, I would assume this is the reason.

Good to see that steps are being taken.
User avatar
FrankLeeAwful
Doctor
Doctor
 
Posts: 198
Joined: Sun Jul 06, 2014 1:38 pm
Location: The depths of Tartarus

Re: Data Security Update 1/4/2019

Postby FrankLeeAwful » Fri Jan 04, 2019 7:41 pm

TrialBot still defaults to http; is this something that is planned to change?
User avatar
FrankLeeAwful
Doctor
Doctor
 
Posts: 198
Joined: Sun Jul 06, 2014 1:38 pm
Location: The depths of Tartarus

Re: Data Security Update 1/4/2019

Postby ICECLIMBERS » Fri Jan 04, 2019 7:50 pm

Achilles wrote:will be looking to migrate to a newer forum technology as a long term solution.

does this mean a NEW forum or will this be transferred over

either way you're going to make people unhappy ¯\_(ツ)_/¯
Spoiler: Image

in the distance the shelves
rode three shadows of blue
User avatar
ICECLIMBERS
[Forum Mafia VII] Winner
[Forum Mafia VII] Winner
 
Posts: 3080
Joined: Wed Nov 19, 2014 11:50 pm
Location: Eastern Time

Re: Data Security Update 1/4/2019

Postby Chemist1422 » Fri Jan 04, 2019 8:05 pm

Oh yeah

If the forums move to a new software will the threads from the old one be kept?
mist ~ she/her

i guess this is goodbye?
(still here for danganronpa i guess)


stop sending reports to me i'm not a tos game moderator
User avatar
Chemist1422
FM Game Moderator
FM Game Moderator
 
Posts: 1026
Joined: Tue Mar 20, 2018 5:39 pm
Location: on the beach at dusk (CST/CDT)

Re: Data Security Update 1/4/2019

Postby NekroG » Fri Jan 04, 2019 8:57 pm

so i cant login via steam anymore how do I reconnect the account to steam?
User avatar
NekroG
Benefactor
Benefactor
 
Posts: 15
Joined: Tue Jan 12, 2016 12:21 am
Location: Riverside, CA, USA

Re: Data Security Update 1/4/2019

Postby Technetium » Fri Jan 04, 2019 9:08 pm

Was the password reset forcing just done?
Image

In memory of those who have been deleted.
The last poster to survive Blindside Island will win a cookie. Or perhaps 1500...
Technetium#8515 on Discord
User avatar
Technetium
Godfather
Godfather
 
Posts: 1941
Joined: Fri Dec 18, 2015 8:25 am
Location: The city, she's been dead, for years now...

Re: Data Security Update 1/4/2019

Postby TurdPile » Fri Jan 04, 2019 9:34 pm

NekroG wrote:so i cant login via steam anymore how do I reconnect the account to steam?


If you are getting the disconnected message, you need to hit the clear password button below the steam login button.
I have mostly rescinded my role as Admin.

All previous contact should instead be redirected to Flavorable.

If your inquiry doesn't directly have to do with Trial 2.0 or TrialBot, then please refrain from messaging.

Thank you.
User avatar
TurdPile
Vampire
Vampire
 
Posts: 8900
Joined: Tue Feb 11, 2014 10:25 am
Location: Massachusetts

Re: Data Security Update 1/4/2019

Postby Technetium » Fri Jan 04, 2019 9:37 pm

I had tried to view the forums on phone, and after logging in and it saying "logged in successfully" it took me right back to the login screen as if I wasn't. So I changed the password through the link in an email I had received...which must have been the original mass email.
Image

In memory of those who have been deleted.
The last poster to survive Blindside Island will win a cookie. Or perhaps 1500...
Technetium#8515 on Discord
User avatar
Technetium
Godfather
Godfather
 
Posts: 1941
Joined: Fri Dec 18, 2015 8:25 am
Location: The city, she's been dead, for years now...

Re: Data Security Update 1/4/2019

Postby Malfoydragon » Fri Jan 04, 2019 11:45 pm

Has the malware, the hackers, and all traces of the hackers been removed?
Malfoydragon
Witch
Witch
 
Posts: 51
Joined: Sun Sep 02, 2018 3:11 am

Re: Data Security Update 1/4/2019

Postby ChubbyMooshroom9 » Sat Jan 05, 2019 8:56 am

Achilles wrote:
Chemist1422 wrote:Will people who changed their passwords after the announcement have to change it again?


Most likely yes. The only way to be sure an account wasn't compromised will be to force a password reset through the registered email to the account. I realize some users may have used a fake email or lost their registered email to their accounts but we don't believe there is any other way to insure the integrity of accounts after the breach. Our community manager will respond to emails and help anyone he can that has proof of their account (valid receipts or Steam link proof for example). If an account has never made any kind of purchase and doesn't have a valid email registered to the account it will end up lost unfortunately but there isn't much else we can do about the scenario. Users should start making sure their account has a valid registered email. They should be able to update their email through the forums.

Given game went to P2P and some people don’t pay for anything this is probably a bad idea.
Image

Hall of Fame
Spoiler:
Shino Thomson
Image
Federico Decandia
Image
Clayton (Briah)
Image
Gebura Briah
User avatar
ChubbyMooshroom9
FM Awards: Town
FM Awards: Town
 
Posts: 1376
Joined: Wed Jun 10, 2015 2:31 pm
Location: Ethiopia

Next

Return to Announcements

Who is online

Users browsing this forum: Bing [Bot] and 11 guests