Open Side Menu Go to the Top
Register
Forum Database Compromise Forum Database Compromise

01-08-2017 , 07:04 PM
As it says in the forum notice we learned that the database had been compromised this morning. We cannot find any evidence that accounts created after approximately November 20 have been compromised (we fixed a problem that day) but as users you should assume that if you've been a member of the forums since before that date that the information necessary to determine your (unchanged) password is out there.

(Although the people "selling" the database claim a December 7 date we believe this to be wrong.)

We have asked all users to reset their password if it hasn't changed in the last 45 days. You will be prompted to do so the next time you login to the forums.

The actions that Max Silver suggests in another post are incredibly important. To recap them:

1) Change your Password on 2+2
2) Change ALL other passwords that are the same or similair
3) Start using unique passwords for every site, these breaches are so common. I'd reccomend a password manager like lastpass
4) enable 2 factor authentication on any vital accounts/emails
5) Take extra precautions to verify identity when trading via 2+2 via separate means

Feel free to update this thread or PM me with any questions.

Chuck
Forum Database Compromise Quote
01-08-2017 , 07:41 PM
How did this happen? Have any precautions been taken to reduce the likelihood of it happening again?
Forum Database Compromise Quote
01-08-2017 , 07:52 PM
The Russians?
Forum Database Compromise Quote
01-08-2017 , 08:31 PM
do we know what was in the compromised database? usernames and cleartext passwords, usernames and hashed passwords, other account data?
Forum Database Compromise Quote
01-08-2017 , 08:45 PM
According to what I saw from an external source: user name, hashed password, DOB, registration date, email.
Forum Database Compromise Quote
01-08-2017 , 08:49 PM
LastPass is now free to use across multiple device types, cell phone, tablet, laptop, etc. There's no excuse not to be using it in this day and age. Tell someone you care about that LastPass or a similar password manager is the only way to roll, and help keep those accounts secure!
Forum Database Compromise Quote
01-08-2017 , 09:07 PM
What if the password manager gets hacked?
Forum Database Compromise Quote
01-08-2017 , 09:15 PM
Lastpass HAS been hacked in the past
Forum Database Compromise Quote
01-08-2017 , 09:35 PM
Quote:
Originally Posted by Jbrochu
What if the password manager gets hacked?
Then you change your password, ldo

LastPass can be set up for 2FA using the google authenticator fwiw
Forum Database Compromise Quote
01-08-2017 , 09:47 PM
Quote:
Originally Posted by Noodle Wazlib
LastPass is now free to use across multiple device types, cell phone, tablet, laptop, etc. There's no excuse not to be using it in this day and age. Tell someone you care about that LastPass or a similar password manager is the only way to roll, and help keep those accounts secure!
Are you sure? I thought you had to pay monthly to use it one more than one device.
Forum Database Compromise Quote
01-08-2017 , 10:26 PM
Chuck and colleagues - please think about the way you're dealing with this.

The way you have set things up (requiring the password reset) means that users cannot see the banner at the top of the forums, and cannot read any of these threads in ATF and elsewhere, before they change their password.

Like me, plenty of people might be wondering whether the "password expired" message is genuine. Unlike me, they may not load up a different browser (or simply log out) in order to read further.

Can you please edit the "change your password" page - the one that people now hit automatically when they visit with an old password logged in - to explain what's going on to people?


Second, it's obviously a serious concern that you're saying the information is out there to determine our (old) passwords. But you're a bit vague on the important detail. Were passwords stored in plain text? If they were hashed, as suggested by someone above, were they salted?
Forum Database Compromise Quote
01-08-2017 , 10:29 PM
Quote:
Originally Posted by gregorio
Are you sure? I thought you had to pay monthly to use it one more than one device.
Hence the key word "now".
Forum Database Compromise Quote
01-08-2017 , 10:30 PM
They can just log out and then read ATF. That's what I did before changing it as I wasn't sure if it were legit or not.
Forum Database Compromise Quote
01-08-2017 , 10:34 PM
They can, yes. But some may not. And surely it would be easy enough to make sure that the first thing they see is a proper explanation rather than the misleading password expiry due to x days message.
Forum Database Compromise Quote
01-08-2017 , 10:42 PM
Quote:
Originally Posted by Noodle Wazlib
Hence the key word "now".
Thanks. Right, when I checked the PlayStore right now they tell me it's $12 a year to use on multiple devices so I stopped installing it. But on their web site they say it's now free. Makes it seem like Lastpass as a company is largely incompetent.

Last edited by gregorio; 01-08-2017 at 10:51 PM.
Forum Database Compromise Quote
01-08-2017 , 10:51 PM
The passwords were not stored as plain text. They were salted.
Forum Database Compromise Quote
01-08-2017 , 10:58 PM
Thanks Chuck. That's some good news, I suppose.

I see it's reported that the database also contained the salts (but my understanding is that that's not necessarily an additional cause for concern).

Can we assume that 2+2 was running an old (and thus vulnerable) version of vBulletin and what you did on 7 December was to update it?
Forum Database Compromise Quote
01-08-2017 , 11:46 PM
Quote:
Originally Posted by Lattimer
They can just log out and then read ATF. That's what I did before changing it as I wasn't sure if it were legit or not.
I wasn't smart enough to think of that.
Forum Database Compromise Quote
01-09-2017 , 12:39 AM
I find it surprising that an email wasn't sent out.
Forum Database Compromise Quote
01-09-2017 , 01:28 AM
I cannot log into my genuine account, and I don't have access to the email associated with my genuine account. I've contacted Mat but I haven't received a reply.

Edit: I will add that when I clicked the forgot password link I was directed to a 'win an iPhone 7' click bait scam page which I obviously thought was really weird.

Last edited by BLACK DEATH; 01-09-2017 at 01:34 AM.
Forum Database Compromise Quote
01-09-2017 , 09:31 AM
Quote:
Originally Posted by batair
The Russians?
No point here as they are mainly lefties.
Forum Database Compromise Quote
01-09-2017 , 09:43 AM
Quote:
Originally Posted by pvn
do we know what was in the compromised database? usernames and cleartext passwords, usernames and hashed passwords, other account data?
Please respond.

Did the database include email addresses? User IP addresses?
Forum Database Compromise Quote
01-09-2017 , 09:46 AM
Quote:
Originally Posted by Gin 'n Tonic
I find it surprising that an email wasn't sent out.
Also this. Telling a user that their password has "expired" once they try to log in is absolutely the wrong way to inform them. A proactive approach, including sending a simple, informative email to all affected accounts is step one here.
Forum Database Compromise Quote
01-09-2017 , 10:24 AM
Quote:
Originally Posted by Mayo
Please respond.

Did the database include email addresses? User IP addresses?
http://forumserver.twoplustwo.com/sh...php?p=51500005
Forum Database Compromise Quote
01-09-2017 , 11:03 AM
call Larry Legend ffs.
Forum Database Compromise Quote

      
m