SIGforum
If you're going into Classifieds today, you'd better be careful. SCAMMER ALERT

This topic can be found at:
https://sigforum.com/eve/forums/a/tpc/f/320601935/m/4420075615

August 06, 2025, 08:31 AM
parabellum
If you're going into Classifieds today, you'd better be careful. SCAMMER ALERT
At least two members have had their accounts hacked. Proceed with caution. Verify identity, and if a deal is too good to be true, it is.
August 06, 2025, 08:37 AM
12131
Fuckers! Mad


Q






August 06, 2025, 08:41 AM
parabellum
If you have a gmail account you use for your forum account, CHANGE YOUR PASSWORD, to a strong, complex password.

If you're buying anything in Classifieds right now, insist on a phone call with the seller.
August 06, 2025, 08:45 AM
92fstech
Done. I'm really sorry guys. I hate that my account was used for this Mad.


-----------------------------------------------------------

Any comments made by this poster are my own and do not reflect the views or opinions of my employer.
August 06, 2025, 09:03 AM
ensigmatic
The systems/database hackers are getting better, the software people that make the stuff that gets hacked apparently are not (and neither are the end-users), so, much like the forced transition to HTTPS-only, I see the day fast approaching where the only safe way to maintain any on-line account is with two-factor authentication (2FA) using TOTP/HOTP, with an app such as Google Authenticator or 2FAs.

(I'm currently using 2FAs for 2FA for every on-line account I have that supports it.)



"America is at that awkward stage. It's too late to work within the system,,,, but too early to shoot the bastards." -- Claire Wolfe
"If we let things terrify us, life will not be worth living." -- Seneca the Younger, Roman Stoic philosopher
August 06, 2025, 09:41 AM
nhracecraft
Well, I am now back. Like '92fstech', I too am sorry for the hassle this incident may have caused anyone here. I appears it was my SIGforum account that was hacked, but I'm now changing passwords EVERYWHERE as a precaution!

Para - Thank you for all your help, and EVERYTHING you do! Smile


____________________________________________________________

If Some is Good, and More is Better.....then Too Much, is Just Enough !!
Trump 47....Making America Great Again!
"May Almighty God bless the United States of America" - parabellum 7/26/20
Live Free or Die!
August 06, 2025, 09:43 AM
92fstech
If I have to guess in this case they probably brute forced my overly simplistic forum password. I haven't accessed the forum or my email from any untrusted devices or networks, and my Gmail account is set up for 2FA and has more of a "passparagraph" than a password. I changed it this morning anyway just to be safe, along with my forum pwd.

My forum account pwd was pretty basic and likely hadn't changed since I set my account up almost 20 years ago. I wasn't super worried about it because it's not tied to any personal info or financials ...heck, I rarely even use the classifieds here. The only reason I caught it this morning was because I used the link in my profile to check recent posts in case there has been any new conversation overnight, and then saw the posts in the classifieds that I knew I hadn't made. I guess I didn't thoroughly consider the scenario that somebody might hack my account with the intent of using it to defraud other people Frown.

Don't be like me, guys...update your passwords.


-----------------------------------------------------------

Any comments made by this poster are my own and do not reflect the views or opinions of my employer.
August 06, 2025, 09:47 AM
architect
It may be helpful to describe how 92fstech's password was compromised, and where (Para's post implies Google/GMail).

Was it a protocol-based attack against the relevant password store (as ensigmatic's post implies) or an interception/guess/brute force/re-use? If the former, password complexity is no defense, and we should all assume that our password are known.

2FA is not without its shortcomings, and can certainly be inconvenient. I would favor public/private key exchange over 2FA although usable implementations have eluded most software developers, and there is the issue of general implementation to get past (everybody has to start using it about the same time). There exist various One-Time Password mechanisms like those listed above and the venerable S/KEY, that can be integrated into the ubiquitous mobile phone deployment that could make a quick revolution to the security environment.

As agentic AI's get more involved in penetrating systems, and communications, maintaining a secure presence on the Internet will get many levels of magnitude more difficult and chancy. Pretty soon we may all be working in an environment where nothing is known for certain, and however hard we try to stay inviolate, we have little chance of success.
August 06, 2025, 10:02 AM
HRK
Done, appreciate the update.
August 06, 2025, 10:14 AM
Mustang-PaPa
Damn I wondered why a seasoned member like 92 was spamming the classifieds.
Glad it was shut down and hope no one lost money.
August 06, 2025, 10:24 AM
P250UA5
Updated my password just as a precaution. Don't actually know what my old pwd was, now it's more in line with the complexity of my others.




The Enemy's gate is down.
August 06, 2025, 10:38 AM
Timdogg6
Not to sound like a dip shit but where do you update your password. I don't see that option in the profile section, or preferences?


__________________________
August 06, 2025, 10:39 AM
HRK
quote:
Originally posted by Timdogg6:
Not to sound like a dip shit but where do you update your password. I don't see that option in the profile section, or preferences?


Open Profile
Select View/Edit Complete Profile in top right
Click Box to Change Password
Change Password
Write it down so you don't forget it!
Save it.
August 06, 2025, 10:56 AM
sigmonkey
GMAIL users, set two-factor authentication (2FA) active on your GMAIL/Google accounts in addition to changing and using strong passwords.




"the meaning of life, is to give life meaning" Ani Yehudi אני יהודי Le'olam lo shuv לעולם לא עוד
August 06, 2025, 12:23 PM
rolin808
Thank you Para


To whom much is given
Much will be required
August 06, 2025, 12:28 PM
ensigmatic
quote:
Originally posted by sigmonkey:
GMAIL users, set two-factor authentication (2FA) active on your GMAIL/Google accounts in addition to changing and using strong passwords.
For those who have (relatively modern) smartphones I strongly recommend using TOTP/HOTP 2FA such as supported by Google Authenticator or 2FAs (which is what I use). It's far superior to SMS/MMS 2FA in every way.

The iThings 2FAs app will sync your tokens between your iThings mobile devices and has an Apple Watch applet, which makes it even more convenient.

And, as I've said many, many, many times here in the past: Everybody should be:
For a discussion on why you should be using tagged email addresses, please see: Tagged Email Addresses

Poor, sloppy Internet hygiene/behavior is likely to come back to bite you.



"America is at that awkward stage. It's too late to work within the system,,,, but too early to shoot the bastards." -- Claire Wolfe
"If we let things terrify us, life will not be worth living." -- Seneca the Younger, Roman Stoic philosopher
August 06, 2025, 12:49 PM
gjgalligan
quote:
For those who have (relatively modern) smartphones I strongly recommend using TOTP/HOTP 2FA such as supported by Google Authenticator or 2FAs (which is what I use). It's far superior to SMS/MMS 2FA in every way.



I can only guess that many are like me that don't have a clue what all that means.


Integrity is doing the right thing, even when nobody is looking.
August 06, 2025, 12:56 PM
redstone
My windows PC and my android phone are both now using 2FA. I went ahead and changed my gmail password since it has been a minute.



This business will get out of control. It will get out of control and we'll be lucky to live through it. -Rear Admiral (Lower Half) Joshua Painter Played by Senator Fred Thompson
August 06, 2025, 02:13 PM
ensigmatic
quote:
Originally posted by gjgalligan:
quote:
For those who have (relatively modern) smartphones I strongly recommend using TOTP/HOTP 2FA such as supported by Google Authenticator or 2FAs (which is what I use). It's far superior to SMS/MMS 2FA in every way.
I can only guess that many are like me that don't have a clue what all that means.
Sorry about that

TOTP: Time-based One Time Password
HOTP: HMAC-based One Time Password (HMAC: Hash-based Message Authentication Code)
2FA: Two-Factor Authentication
SMS: Short Message Service (text-only text messaging)
MMS: Multimedia Messaging Service (text, image, video, and audio clip "text" messaging)

You really don't need to know what TOTP and HOTP are, much less understand them, to use them. (I probably should've just left those acronyms out entirely.)

So what happens with TOTP/HOTP authenticators like Google Authenticator and 2FAs {*} is:It's superior to text-message 2FA because:Both of these arguments apply to email, though email is, or can be, a more reliable transport than SMS/MMS.

{*} Microsoft also has an authenticator. I do not recommend it unless you have to use it because I am informed that, in typical Microsoft fashion, it's almost, but not quite, standard.

This message has been edited. Last edited by: ensigmatic,



"America is at that awkward stage. It's too late to work within the system,,,, but too early to shoot the bastards." -- Claire Wolfe
"If we let things terrify us, life will not be worth living." -- Seneca the Younger, Roman Stoic philosopher
August 06, 2025, 03:13 PM
Pipe Smoker
Welcome back ensigmatic - it’s been a few months. Smile



Serious about crackers.