Accounts Hacked Change Your Passwords

Discussion in 'Discussions Archive' started by FreddoFrog, Apr 9, 2014.

  1. FreddoFrog
    Offline

    FreddoFrog Well-Known Member

    Joined:
    Sep 22, 2013
    Messages:
    1,065
    Well this week some minecraft users were hacked again and some members of the skyblock community were also hacked so i strongly advise you all to change your minecraft passwords for the saftey of yourselves and others...

    EDIT: Minecraft wasnt hacked but if you were using the internet you could well have been hacked...
     
  2. Doctor_seuss
    Offline

    Doctor_seuss Active Member

    Joined:
    Jul 8, 2013
    Messages:
    193
    I probably was.
     
  3. Beaver2206
    Offline

    Beaver2206 Active Member

    Joined:
    Feb 14, 2013
    Messages:
    213
    I saw people boasting the other day that they were and have hacked people, shall I pass these on to anybody? I took screenshots.

    Has this become a problem lately?
     
  4. FreddoFrog
    Offline

    FreddoFrog Well-Known Member

    Joined:
    Sep 22, 2013
    Messages:
    1,065
    yes post it in reports if you have enough evidence please
     
  5. Beaver2206
    Offline

    Beaver2206 Active Member

    Joined:
    Feb 14, 2013
    Messages:
    213
    Well the only evidence present would be him say it. And in a very provocative way, purely to get a reaction. probably trollin'
     
  6. Beaver2206
    Offline

    Beaver2206 Active Member

    Joined:
    Feb 14, 2013
    Messages:
    213
    K, posted a report in the 'reports' section. I also noticed that Zara had had account issues. I believe this player is named in my screenshots. Hope this helps.
     
  7. luckynumber56
    Offline

    luckynumber56 Well-Known Member

    Joined:
    Sep 15, 2012
    Messages:
    509
    I don't think it is necessary for people to change their passwords, unless they have poor ones like 123456. It isn't like the SkyBlock database (If there were one :p) got hacked, and all user passwords were leaked -- it is most likely simple account cracking with a bruteforcer like the one on WeepCraft.
     
  8. blaq
    Offline

    blaq Experienced Member

    Joined:
    Jun 17, 2013
    Messages:
    4,625
    Again if you follow the golden rules regarding accounts, you're fine:

    1) Use a good password that you can't find in a dictionary, Eg. make it up by combining a phrase "The quick brown fox jumps over the lazy dog" = tqbfjotld, add numbers and special characters = tqbfjot!ld@1736
    2) Don't reuse passwords between websites. Good websites that know what they're doing will store the passwords properly, but those that don't will expose your password by storing it poorly.
    3) Use a service like LastPass if you want to best manage your passwords.
    4) There is NO NEED to "change your password regularly" if you follow the rules above - changing your password regularly increases the chance you'll have to do something silly like writing it down or using a simple password.
     
  9. Gideon25
    Offline

    Gideon25 Member

    Joined:
    Feb 20, 2014
    Messages:
    61
    My friends password for something (not minecraft) im not telling you the website is dbz (dragon ball z) and i wont tell you the rest of his password cause there is some numbers
     
  10. blaq
    Offline

    blaq Experienced Member

    Joined:
    Jun 17, 2013
    Messages:
    4,625
  11. SLGMichael
    Offline

    SLGMichael Experienced Member

    Joined:
    Sep 13, 2012
    Messages:
    528
    This is not an issue with users hacking, this an issue SSL security which effected tens of thousands of websites and databases across the web. All users should change their passwords, it's not "simple account cracking with a bruteforcer like the one on WeepCraft" and its nothing something that can be circumvented by having a secure password.
     
  12. blaq
    Offline

    blaq Experienced Member

    Joined:
    Jun 17, 2013
    Messages:
    4,625
    No point changing the passwords if the site hasn't patched the vulnerability or changed their SSL keys, you need to look for a site that has SSL certificates of date after 8th April 2014
     
  13. SLGMichael
    Offline

    SLGMichael Experienced Member

    Joined:
    Sep 13, 2012
    Messages:
    528
    Let me rephrase, change you Minecraft passwords. No one cares about a Skyblock forum db.
     
  14. blaq
    Offline

    blaq Experienced Member

    Joined:
    Jun 17, 2013
    Messages:
    4,625
    But but...all my posts, and my friendly ratings...

    Seriously though, most people reuse usernames and passwords across different things, meaning that if someone got the Skyblock forum db there'd be a good chance they'd not only get your minecraft username/password, but also access to other accounts like twitter, facebook etc.
     
  15. SLGMichael
    Offline

    SLGMichael Experienced Member

    Joined:
    Sep 13, 2012
    Messages:
    528
    Which is why I'm saying to change your non-skyblock passwords.
     
  16. blaq
    Offline

    blaq Experienced Member

    Joined:
    Jun 17, 2013
    Messages:
    4,625
    Was mainly referring to your comment that no one cares about a Skyblock forum db :)
     
  17. luckynumber56
    Offline

    luckynumber56 Well-Known Member

    Joined:
    Sep 15, 2012
    Messages:
    509
    I saw that post on minecraft.net, they claim to have shut their services down as soon as they realized the breach in security, but I suppose there is still that chance. Other sites, however, would likely be more common to have user account info leaked (Because they did not shut down their service, I would assume). I won't go through the lengthy process of changing all of my passwords, rather the few that are serious, others I can just reset with email if necessary.
     
  18. Sean
    Offline

    Sean Senior Member

    Joined:
    Sep 23, 2012
    Messages:
    4,597
    You forgot to mention that this exploit.. If you can even call it that has been around since 2012, since then it was patched. Need I even bother to add it didn't effect MineCraft at all? Mojang is just trying to look like a good guy about it. Also the developers of SSL have already confirmed no data was actually unencrypted or taken, it was only just made public, any site that hasn't patched the SSL related stuff in 2 years has some serious questioning to answer.
     
  19. Gideon25
    Offline

    Gideon25 Member

    Joined:
    Feb 20, 2014
    Messages:
    61
    people didn't know that before now that you told us then if someone DOES find your password then they CAN use it for all your stuff
     
  20. SLGMichael
    Offline

    SLGMichael Experienced Member

    Joined:
    Sep 13, 2012
    Messages:
    528
    The exploit itself has been around for a while, but never to this level. Think of it as a small leak in a barrel. They patched it well enough to hold normal pressure, but as the pressure built up, those patches burst more and more. Mojang was affected just as much as any other website that uses OpenSSL authentication.

    Regardless, this is not something to argue about, it will only confuse people. I've said what I have to say, and will not continue to discuss it. If you feel the need to give your users a false sense of security, then so be it. That's why I left in the first place.
     

Share This Page