Author Topic: Forum security  (Read 3972 times)

0 Members and 1 Guest are viewing this topic.

I recently signed up to these forums to do work on the Boanerges. Literally days later, my Steam account is hijacked. It uses the same e-mail that I used on these forums, and the same password (not that saying this matters now). My security-concious friend tells me the SMF software these forms use is "terrible".

I have to ask this. Is this forum secure? Are the e-mails and passwords kept locked up?

No need to suggest other reasons for my Steam hijacking, I'm already looking into them all. I just want to cross this off my list of suspects.

 
I haven't had any problems with it :nervous:

 

Offline Herra Tohtori

  • The Academic
  • 211
  • Bad command or file name
Correlation doesn't imply causation, and I would think a weak password and foul luck would be far more likely culprit.

It is of course a possibility that if you use same password for many services, one of them has had a security leak of some kind. But it's still a stretch that someone would have connected your HLP account with the Steam account... unless your E-mail itself is compromised.

At any rate using same password for many purposes - especially non-important and important purposes alike - is very much not advisable...
There are three things that last forever: Abort, Retry, Fail - and the greatest of these is Fail.

 

Offline Polpolion

  • The sizzle, it thinks!
  • 211
I haven't had any issues in the four years that I've been here.

 

Offline Hellstryker

  • waffles
  • 210
    • Skype
No issues here.

 

Offline Aardwolf

  • 211
  • Posts: 16,384
* Aardwolf doesn't even have a Steam account

 

Offline Galemp

  • Actual father of Samus
  • 212
  • Ask me about GORT!
    • Steam
    • User page on the FreeSpace Wiki
Sorry to hear that, Athlon, but as far as I know we've never heard of any problems coming from outside the community.

Various unsavory types from within the community have been known to cause trouble, but nothing like what you've experienced.
"Anyone can do any amount of work, provided it isn't the work he's supposed to be doing at that moment." -- Robert Benchley

Members I've personally met: RedStreblo, Goober5000, Sandwich, Splinter, Su-tehp, Hippo, CP5670, Terran Emperor, Karajorma, Dekker, McCall, Admiral Wolf, mxlm, RedSniper, Stealth, Black Wolf...

 

Offline tinfoil

  • i'm 13 remember
  • 29
*cough* an0n *cough*
Alcibades' Gamble - We Love Our Ice Cream

Everything you need to know, and more can be found at The Freespace Wiki

 

 
Well, fair enough.

Nothing personal, but if a woman was killed by a serial killer, you'd question the husband as a suspect until that was proven. I'm just looking into all avenues.

 

Offline Mobius

  • Back where he started
  • 213
  • Porto l'azzurro Dolce Stil Novo nella fantascienza
    • Skype
    • Twitter
    • The Lightblue Ribbon | Cultural Project
I haven't had any issues in the four years that I've been here.

Make that three years for me. I've never had security problems. Even telling Dysko what my password was lead to nothing because it was difficult to spell. :p
The Lightblue Ribbon

Inferno: Nostos - Alliance
Series Resurrecta: {{FS Wiki Portal}} -  Gehenna's Gate - The Spirit of Ptah - Serendipity (WIP) - <REDACTED> (WIP)
FreeSpace Campaign Restoration Project
A tribute to FreeSpace in my book: Riflessioni dall'Infinito
My interviews: [ 1 ] - [ 2 ] - [ 3 ]

 

Offline Blue Lion

  • Star Shatterer
  • 210
Not to knock Athlonboy down a notch, but if there was an issue with security, "new guy's Steam account" wouldn't be my first pick.

I bet there is a ton of good stuff here to break into.

 

Offline Polpolion

  • The sizzle, it thinks!
  • 211
BTW, did you get your steam account back under control all right?

 

Offline Goober5000

  • HLP Loremaster
  • 214
    • Goober5000 Productions
*cough* an0n *cough*
Actually, when an0n found the new forums, he complimented us on our choice of SMF, due to SMF's security.

 

Offline tinfoil

  • i'm 13 remember
  • 29
Well he would know...
Not to be roasting an0n or anything, I find him to be quite entertaining. :nervous:

[/offtopic]

Carry on.
Alcibades' Gamble - We Love Our Ice Cream

Everything you need to know, and more can be found at The Freespace Wiki

 

 
It sure was an 'anon' who hijacked me. He changed my picture to the classic black-and-white tuxedo, which is a bit of a giveaway. As a veteran of internets, I know what anon is, and that you shouldn't take them seriously. Don't feed the troll, and all that.

A friend of mine had a chat with the hijacker. He claims he did indeed exploit some flaw in the MySQL of these forums. The way I've put that might sound incredibly silly, but I know nothing of SQL or of forums. Maybe an admin should check. 'Course, he may just be yanking our chains.

 

Offline Mongoose

  • Rikki-Tikki-Tavi
  • Global Moderator
  • 212
  • This brain for rent.
    • Steam
    • Something
It sure was an 'anon' who hijacked me. He changed my picture to the classic black-and-white tuxedo, which is a bit of a giveaway. As a veteran of internets, I know what anon is, and that you shouldn't take them seriously. Don't feed the troll, and all that.
Actually, the specific "an0n" they're referring to is a singular entity who predates the more recent "Anon" phenomenon by quite a bit.  And from what I understand, this isn't the sort of thing that would be up his alley.

 

Offline tinfoil

  • i'm 13 remember
  • 29
Aye, the singular an0n lives on a level far below the recant Anon phenomenon. *shudders as he remembers his lurking days and the permanent scarring*
Alcibades' Gamble - We Love Our Ice Cream

Everything you need to know, and more can be found at The Freespace Wiki

 

 

Offline Hippo

  • Darth water-horse
  • 211
  • Grazing.
    • All Hands to War
SMF encrypts passwords before putting them in the database, so I don't buy this for a second. More likely is you had some sort of keylogger on your computer already, and your combination of email/password you typed in when you registered was used on any common websites you've visited.
VBB Survivor -- 387 Posts -- July 3 2001 - April 12 2002
VWBB Survivor -- 100 Posts -- July 10 2002 - July 10 2004

AHTW

 

Offline Dilmah G

  • Failed juggling
  • 211
  • Do try it.
 :lol:

I've seen some of his posts, does he still go on here?

I can't offer much advice topic-wise, I don't have a steam account

 

Offline tinfoil

  • i'm 13 remember
  • 29
He does indeed still go on here but much less, and his posts are rather less disturbing. Except for the Lime in the Coconut one.
Alcibades' Gamble - We Love Our Ice Cream

Everything you need to know, and more can be found at The Freespace Wiki