0 Members and 1 Guest are viewing this topic.503 views

*

Offline Cool like Redtunnel

Your account is not secure
« on: January 22, 2019, 19:59:26 »
An interesting watch...I'm sure as hell changing all my passwords :P


*

Offline Alaklondewen

Re: Your account is not secure
« Reply #1 on: January 22, 2019, 20:45:19 »
Very helpful though!  I've always been wary of those surveys people fill out on social media, because they often include security questions. :/

Also...someone guested in the right place at the right time...

(click to show/hide)

*

Offline Rune

Re: Your account is not secure
« Reply #2 on: January 22, 2019, 21:04:30 »
As a previous forum admin it was scarily easy to obtain a full copy of the database through the admin part of the forums. I'm glad Red disabled that functionality so it's only accessible by knowing the actual code to the database.

I strongly suggest to turn on both Authenticator on your rs account and on your registered emails.

MFA on microsoft accounts:
https://support.microsoft.com/en-gb/help/12408/microsoft-account-how-to-use-two-step-verification

Google mail:
https://www.google.com/landing/2step/

You can check if your email is compromised by using this site:
https://haveibeenpwned.com/

I recently changed passwords on 150+ websites with some autogenerated ones, so all of them are different.

*

Offline Tommykillme

Re: Your account is not secure
« Reply #3 on: January 22, 2019, 21:33:29 »
How scary! Some great words of wisdom @Rune

*

Offline Joe

Re: Your account is not secure
« Reply #4 on: January 23, 2019, 02:07:25 »
I thought of a lot of these things.  I take very special care to hide my passwords.  Most are randomly generated gibberish that mean nothing and I keep track of them by writing them down on paper so they're not saved anywhere online.  Not even on a flash drive.  Just a piece of paper that I keep under a hidden flap on my desk.

*

Offline Redtunnel

  • *
  • Join Date: Sep 2011
  • 2655
  • Gender: Male
  • Awards For Capping 52 Times Won three CTS games tournaments This player has 99 in the skill: Construction! This player has 99 in the skill: Fletching! This player has 120 in the skill: Fishing!
  • Rsn: Redtunnel
Re: Your account is not secure
« Reply #5 on: January 23, 2019, 08:44:27 »
I was targetted after Consentus' database breach around 2011 (they got access because one of the Consentus admins used the same password on some other RS fansite that got compromised). I know they targetted me because someone uploaded the chat logs to pastebin where the hacker, who was trying to sell the information, named me as a wealthy player in his selling argument. They never did manage to get into my account, though.

Never use the same password twice on anything that matters to you and you will probably be fine. 2FA on your email accounts. But how do you memorize all your usernames and passwords? Use a password manager! Stronger passwords help in case the database gets breached. If you have a strong password, chances are it will take too long to find its match (if the hashing algorithm is even remotely modern, it's all done through brute force, i.e. trying millions of passwords every second until it's found; often dictionary list based).

Jagex's account recovery system is the most concerning part in all of this, especially if they rely on such basic information such as IP and ISP (they are by no means secret on the internet and you cannot hide it unless you're using a VPN or proxy, which is a security problem of itself), name and country.
"The purity of a person's heart can be measured by how they regard cats"



*

Offline Cool like Redtunnel

Re: Your account is not secure
« Reply #6 on: January 23, 2019, 16:02:34 »
Never use the same password twice on anything that matters to you and you will probably be fine. 2FA on your email accounts. But how do you memorize all your usernames and passwords? Use a password manager! Stronger passwords help in case the database gets breached. If you have a strong password, chances are it will take too long to find its match (if the hashing algorithm is even remotely modern, it's all done through brute force, i.e. trying millions of passwords every second until it's found; often dictionary list based).

What password managers do you use or recommend? Mine are currently saved on a USB so nobody has access to them unless it gets stolen which I know isn't the safest method of storing password, lol.

But how secure are these password managing sites and can they handle multiple emails?

Edit:
The video is no longer listed...Wonder what happened :equips tinfoil hat:

*

Offline Joe

Re: Your account is not secure
« Reply #7 on: January 23, 2019, 20:33:15 »
In my opinion, being an paranoid as I am and understanding the significant risk like Red does, I save nothing like that digitally like I mentioned early.  But a flash drive would be your safest bet.  I'd personally use a Word document with the website's name and your password, game name, etc - and organize it alpabetically for ease of finding what you're looking for. 

Absolutely use the authenticator for your login.  But I don't recommend using it for your bank PIN like the hijacker in the video stated.  As soon as it's disabled, your bank and your coin pouch are defenseless.  The 4 digit PIN is still your safest bet as you have 3 days for it disable.  You can also switch it 7 days which would be even better.

*

Offline Qevin

  • *
  • Join Date: Jan 2016
  • 134
  • Gender: Male
  • Awards This player has won 1 weekly skill competition!
  • Rsn: Sudo rm rf
Re: Your account is not secure
« Reply #8 on: January 23, 2019, 20:36:54 »
I work as IT security officer, always use multifactor authentication where possible, trust me it works

 

SimplePortal 2.3.6 © 2008-2014, SimplePortal