Site Problems 12.01.2015

Discussion in 'Empire News' started by Krysyy, Dec 1, 2015.

  1. Just saying, traditional two factor authentication does nothing if someone has your e-mail.

    I've seen individuals try to access my e-mails and steam about 10 times in the past 3 months alone
    1. Asking for a password reset on these sites sends a reset code to your e-mail.
    2. You then insert the code into the site 'reset area' (or steam reset area) and are able to type any password you want...
    If you have two-factor authentication, I would 'at minimum' recommend having a separate password for the e-mail from the websites you use the e-mail on ... This way it reduces the chance someone can use the reset option, even if your e-mail is compromised (From knowing the password - If someone has access to the databases, not so much).

    If you do get your e-mail compromised:
    • Reset your e-mail password
    • Change the associated e-mail on the sites you have initially were using it on.
    TomvanWijnen likes this.
  2. The authentication we are likely going to be using is a little more special, but great advice for in general practice.
    crystaldragon13 likes this.
  3. I recommend people use Gmail, in which you can use App Based 2FA.

    But i'm going to look at non standard means (not email) for the 2FA and make the game/forums not even tell you how to verify the connection, so staff will just know from their training but nothing else will tell you, so unauthorized access wont even know where to try to verify it.
    607 and crystaldragon13 like this.
  4. oh no sorry to hear that bad happened but hopefully all is fixed
    crystaldragon13 likes this.
  5. Yeah I feel an external app would be better as it reduces the chances of KeyLogging on the main device you are currently using.

    Plus I feel having a reset code being sent to the e-mail defeats the whole purpose of preventing unauthorized access.

    No problem | I also forgot to mention:

    If you are scared that you might have a KeyLogger (A silent program, virus, extension, etc. that tracks what keys you type) I recommend doing one of three things...
    • Type what you want as your password along with random jargon
      • Then use your mouse to copy/paste what you need - so if someone is keylogging you, it may look jumbled.
    • Reset the password on a different device (Your phone/ipod/tablet etc)
    • Disconnect your device from the internet, clear internet data, run some anti-malware programs, re-enable internet, and reset password using a different browser.
    It's not always a KeyLogger issue, though - A lot of individuals outside of the United States access databases directly and just sniff out your information...

    I noticed with me, my gmails were fine, but every affected e-mail kept always being Yahoo (so maybe their security isn't the greatest)
    607 likes this.
  6. I swear if your password was skittles...

    "Yes the password is skittles!" said the little troller/hacker.
  7. no....
    *changes password*
  8. *Chin rushes to change password* :rolleyes:
    _Devuu__, Tuqueque, 607 and 1 other person like this.
  9. -krysyy quote is from may,2015
    _Devuu__, 607, PetuniaFigtree and 4 others like this.
  10. I think I know your new password. Brb, trying it now.
    tuqueque likes this.
  11. http://empireminecraft.com/conversations/add?to=Krysyy

    Here is your help from me
  12. there were some recent security issues on OTHER minecraft sites, and I'm assuming that's how they got ahold of chins password. The guy's been posting about password leaks.

    Lesson Learned: Only play on EMC.
  13. Glad everything is back. I never expected a SS to get their password compromised though...
  14. We have a life lesson here Boys/Gals, a life lesson here!
    Kephras likes this.
  15. Just because someone's SS on EMC doesn't guarantee technology discipline.

    In life in general, most people tend to slack off until they get bit, and then they get better. It's the sad way most people learn, but it's usually what happens.

    Case in point: Same thing with me @ my backups....

    They were not a member of EMC. They just found Chins password, then found things related to him to try his PW on multiple sites.
    607 and crystaldragon13 like this.
  16. Technology discipline? Does that mean responsibility with technology?
  17. I use LastPass and use a unique password on every site. It makes it very easy to do so while using LastPass. I haven't made the jump to using the ubikey for 2-factor as well but this is still pretty secure.