SIGforum.com    Main Page  Hop To Forum Categories  The Lounge    If you're going into Classifieds today, you'd better be careful. SCAMMER ALERT
Page 1 2 
Go
New
Find
Notify
Tools
Reply
  
If you're going into Classifieds today, you'd better be careful. SCAMMER ALERT Login/Join 
Peace through
superior firepower
Picture of parabellum
posted
At least two members have had their accounts hacked. Proceed with caution. Verify identity, and if a deal is too good to be true, it is.
 
Posts: 114179 | Registered: January 20, 2000Reply With QuoteReport This Post
Oriental Redneck
Picture of 12131
posted Hide Post
Fuckers! Mad


Q






 
Posts: 30999 | Location: TEXAS | Registered: September 04, 2008Reply With QuoteReport This Post
Peace through
superior firepower
Picture of parabellum
posted Hide Post
If you have a gmail account you use for your forum account, CHANGE YOUR PASSWORD, to a strong, complex password.

If you're buying anything in Classifieds right now, insist on a phone call with the seller.
 
Posts: 114179 | Registered: January 20, 2000Reply With QuoteReport This Post
Prepared for the Worst, Providing the Best
Picture of 92fstech
posted Hide Post
Done. I'm really sorry guys. I hate that my account was used for this Mad.


-----------------------------------------------------------

Any comments made by this poster are my own and do not reflect the views or opinions of my employer.
 
Posts: 11817 | Location: In the Cornfields | Registered: May 25, 2006Reply With QuoteReport This Post
Nullus Anxietas
Picture of ensigmatic
posted Hide Post
The systems/database hackers are getting better, the software people that make the stuff that gets hacked apparently are not (and neither are the end-users), so, much like the forced transition to HTTPS-only, I see the day fast approaching where the only safe way to maintain any on-line account is with two-factor authentication (2FA) using TOTP/HOTP, with an app such as Google Authenticator or 2FAs.

(I'm currently using 2FAs for 2FA for every on-line account I have that supports it.)



"America is at that awkward stage. It's too late to work within the system,,,, but too early to shoot the bastards." -- Claire Wolfe
"If we let things terrify us, life will not be worth living." -- Seneca the Younger, Roman Stoic philosopher
 
Posts: 26151 | Location: S.E. Michigan | Registered: January 06, 2008Reply With QuoteReport This Post
Shall Not Be Infringed
Picture of nhracecraft
posted Hide Post
Well, I am now back. Like '92fstech', I too am sorry for the hassle this incident may have caused anyone here. I appears it was my SIGforum account that was hacked, but I'm now changing passwords EVERYWHERE as a precaution!

Para - Thank you for all your help, and EVERYTHING you do! Smile


____________________________________________________________

If Some is Good, and More is Better.....then Too Much, is Just Enough !!
Trump 47....Making America Great Again!
"May Almighty God bless the United States of America" - parabellum 7/26/20
Live Free or Die!
 
Posts: 10873 | Location: New Hampshire | Registered: October 29, 2011Reply With QuoteReport This Post
Prepared for the Worst, Providing the Best
Picture of 92fstech
posted Hide Post
If I have to guess in this case they probably brute forced my overly simplistic forum password. I haven't accessed the forum or my email from any untrusted devices or networks, and my Gmail account is set up for 2FA and has more of a "passparagraph" than a password. I changed it this morning anyway just to be safe, along with my forum pwd.

My forum account pwd was pretty basic and likely hadn't changed since I set my account up almost 20 years ago. I wasn't super worried about it because it's not tied to any personal info or financials ...heck, I rarely even use the classifieds here. The only reason I caught it this morning was because I used the link in my profile to check recent posts in case there has been any new conversation overnight, and then saw the posts in the classifieds that I knew I hadn't made. I guess I didn't thoroughly consider the scenario that somebody might hack my account with the intent of using it to defraud other people Frown.

Don't be like me, guys...update your passwords.


-----------------------------------------------------------

Any comments made by this poster are my own and do not reflect the views or opinions of my employer.
 
Posts: 11817 | Location: In the Cornfields | Registered: May 25, 2006Reply With QuoteReport This Post
Optimistic Cynic
Picture of architect
posted Hide Post
It may be helpful to describe how 92fstech's password was compromised, and where (Para's post implies Google/GMail).

Was it a protocol-based attack against the relevant password store (as ensigmatic's post implies) or an interception/guess/brute force/re-use? If the former, password complexity is no defense, and we should all assume that our password are known.

2FA is not without its shortcomings, and can certainly be inconvenient. I would favor public/private key exchange over 2FA although usable implementations have eluded most software developers, and there is the issue of general implementation to get past (everybody has to start using it about the same time). There exist various One-Time Password mechanisms like those listed above and the venerable S/KEY, that can be integrated into the ubiquitous mobile phone deployment that could make a quick revolution to the security environment.

As agentic AI's get more involved in penetrating systems, and communications, maintaining a secure presence on the Internet will get many levels of magnitude more difficult and chancy. Pretty soon we may all be working in an environment where nothing is known for certain, and however hard we try to stay inviolate, we have little chance of success.
 
Posts: 7927 | Location: NoVA | Registered: July 22, 2009Reply With QuoteReport This Post
Thank you
Very little
Picture of HRK
posted Hide Post
Done, appreciate the update.
 
Posts: 27668 | Location: Gunshine State | Registered: November 07, 2008Reply With QuoteReport This Post
Firearms Enthusiast
Picture of Mustang-PaPa
posted Hide Post
Damn I wondered why a seasoned member like 92 was spamming the classifieds.
Glad it was shut down and hope no one lost money.
 
Posts: 18683 | Location: DFW | Registered: December 26, 2008Reply With QuoteReport This Post
Member
Picture of P250UA5
posted Hide Post
Updated my password just as a precaution. Don't actually know what my old pwd was, now it's more in line with the complexity of my others.




The Enemy's gate is down.
 
Posts: 18527 | Location: Spring, TX | Registered: July 11, 2011Reply With QuoteReport This Post
Needs a check up
from the neck up
Picture of Timdogg6
posted Hide Post
Not to sound like a dip shit but where do you update your password. I don't see that option in the profile section, or preferences?


__________________________
 
Posts: 5413 | Location: Boca Raton, FL | Registered: July 30, 2002Reply With QuoteReport This Post
Thank you
Very little
Picture of HRK
posted Hide Post
quote:
Originally posted by Timdogg6:
Not to sound like a dip shit but where do you update your password. I don't see that option in the profile section, or preferences?


Open Profile
Select View/Edit Complete Profile in top right
Click Box to Change Password
Change Password
Write it down so you don't forget it!
Save it.
 
Posts: 27668 | Location: Gunshine State | Registered: November 07, 2008Reply With QuoteReport This Post
A Grateful American
Picture of sigmonkey
posted Hide Post
GMAIL users, set two-factor authentication (2FA) active on your GMAIL/Google accounts in addition to changing and using strong passwords.




"the meaning of life, is to give life meaning" Ani Yehudi אני יהודי Le'olam lo shuv לעולם לא עוד
 
Posts: 46423 | Location: Box 1663 Santa Fe, New Mexico | Registered: December 20, 2008Reply With QuoteReport This Post
Member
Picture of rolin808
posted Hide Post
Thank you Para


To whom much is given
Much will be required
 
Posts: 732 | Location: Honolulu | Registered: February 25, 2011Reply With QuoteReport This Post
Nullus Anxietas
Picture of ensigmatic
posted Hide Post
quote:
Originally posted by sigmonkey:
GMAIL users, set two-factor authentication (2FA) active on your GMAIL/Google accounts in addition to changing and using strong passwords.
For those who have (relatively modern) smartphones I strongly recommend using TOTP/HOTP 2FA such as supported by Google Authenticator or 2FAs (which is what I use). It's far superior to SMS/MMS 2FA in every way.

The iThings 2FAs app will sync your tokens between your iThings mobile devices and has an Apple Watch applet, which makes it even more convenient.

And, as I've said many, many, many times here in the past: Everybody should be:
  • Using a separate password/pass-phrase for every site
  • Using "tagged" (aka: "plussed") email addresses when possible (see below)
  • Using a password safe (aka: "electronic keyring") to store everything, incl. site URLs.
For a discussion on why you should be using tagged email addresses, please see: Tagged Email Addresses

Poor, sloppy Internet hygiene/behavior is likely to come back to bite you.



"America is at that awkward stage. It's too late to work within the system,,,, but too early to shoot the bastards." -- Claire Wolfe
"If we let things terrify us, life will not be worth living." -- Seneca the Younger, Roman Stoic philosopher
 
Posts: 26151 | Location: S.E. Michigan | Registered: January 06, 2008Reply With QuoteReport This Post
Just because something is legal to do doesn't mean it is the smart thing to do.
posted Hide Post
quote:
For those who have (relatively modern) smartphones I strongly recommend using TOTP/HOTP 2FA such as supported by Google Authenticator or 2FAs (which is what I use). It's far superior to SMS/MMS 2FA in every way.



I can only guess that many are like me that don't have a clue what all that means.


Integrity is doing the right thing, even when nobody is looking.
 
Posts: 4640 | Location: Metamora MI | Registered: October 31, 2003Reply With QuoteReport This Post
Why don’t you fix your little
problem and light this candle
Picture of redstone
posted Hide Post
My windows PC and my android phone are both now using 2FA. I went ahead and changed my gmail password since it has been a minute.



This business will get out of control. It will get out of control and we'll be lucky to live through it. -Rear Admiral (Lower Half) Joshua Painter Played by Senator Fred Thompson
 
Posts: 3898 | Location: Central Virginia | Registered: November 06, 2006Reply With QuoteReport This Post
Nullus Anxietas
Picture of ensigmatic
posted Hide Post
quote:
Originally posted by gjgalligan:
quote:
For those who have (relatively modern) smartphones I strongly recommend using TOTP/HOTP 2FA such as supported by Google Authenticator or 2FAs (which is what I use). It's far superior to SMS/MMS 2FA in every way.
I can only guess that many are like me that don't have a clue what all that means.
Sorry about that

TOTP: Time-based One Time Password
HOTP: HMAC-based One Time Password (HMAC: Hash-based Message Authentication Code)
2FA: Two-Factor Authentication
SMS: Short Message Service (text-only text messaging)
MMS: Multimedia Messaging Service (text, image, video, and audio clip "text" messaging)

You really don't need to know what TOTP and HOTP are, much less understand them, to use them. (I probably should've just left those acronyms out entirely.)

So what happens with TOTP/HOTP authenticators like Google Authenticator and 2FAs {*} is:
  • You get a unique code from the site that's stashed in your authenticator app's little database.
  • A rolling code specific to your account is generated every X amount of time (usually every 30 seconds).
  • That rolling code is synchronized between the app and the server.
  • When you're challenged for that code: You enter whatever the app's showing for that time period and the server checks to make sure it's what it should be.
It's superior to text-message 2FA because:
  • While text messaging is more secure than it used to be much of the time, it is still not regarded a secure messaging platform.
  • Text messaging is transported/delivered on a "best effort" basis. That means it's not guaranteed.
Both of these arguments apply to email, though email is, or can be, a more reliable transport than SMS/MMS.

{*} Microsoft also has an authenticator. I do not recommend it unless you have to use it because I am informed that, in typical Microsoft fashion, it's almost, but not quite, standard.

This message has been edited. Last edited by: ensigmatic,



"America is at that awkward stage. It's too late to work within the system,,,, but too early to shoot the bastards." -- Claire Wolfe
"If we let things terrify us, life will not be worth living." -- Seneca the Younger, Roman Stoic philosopher
 
Posts: 26151 | Location: S.E. Michigan | Registered: January 06, 2008Reply With QuoteReport This Post
Baroque Bloke
Picture of Pipe Smoker
posted Hide Post
Welcome back ensigmatic - it’s been a few months. Smile



Serious about crackers.
 
Posts: 11309 | Location: San Diego | Registered: July 26, 2014Reply With QuoteReport This Post
  Powered by Social Strata Page 1 2  
 

SIGforum.com    Main Page  Hop To Forum Categories  The Lounge    If you're going into Classifieds today, you'd better be careful. SCAMMER ALERT

© SIGforum 2026