I think my account has been hacked

Discussion in 'New Player Welcome' started by instgtr, Nov 1, 2016.

Thread Status:
Not open for further replies.
  1. instgtr

    instgtr Avatar

    Messages:
    15
    Likes Received:
    5
    Trophy Points:
    3
    I tried to log in this morning, but got a message saying my password was not recognized - I tried a couple more times, then went to change my password, but was unable to do so.

    Can a hacker change the account name, preventing you from doing anything?

    How do I contact Portalarium to take care of the problem?

    Thanx,

    Dennis
     
    Acred likes this.
  2. Duke Gréagóir

    Duke Gréagóir Legend of the Hearth

    Messages:
    5,686
    Likes Received:
    11,827
    Trophy Points:
    165
    Location:
    Dara Brae
  3. By Tor

    By Tor Avatar

    Messages:
    2,362
    Likes Received:
    4,717
    Trophy Points:
    165
    Gender:
    Male
    It may have been due to the server being down this morning (at least it was for me). But... contact Port to be on the safe side.
     
  4. Selene

    Selene Avatar

    Messages:
    3,106
    Likes Received:
    11,697
    Trophy Points:
    165
    Gender:
    Female
    Location:
    Serpents Watch Brewery!!
    If you were able to log into the forum or your account page on the website, then a down server may have been the culprit, as all three use the same credentials.
     
    Last edited: Nov 1, 2016
    Lained, Net, Acred and 2 others like this.
  5. Sorthious

    Sorthious Avatar

    Messages:
    1,135
    Likes Received:
    1,354
    Trophy Points:
    113
    How did you log in to post this message? If you were hacked they would just change the password or delete the account. I don't think an account name can be changed. Regardless, you can log in now. If it makes you more comfortable, you should be able to change your password now that you can log in.
     
    Acred and Alexander like this.
  6. Wintermute of CoF

    Wintermute of CoF Avatar

    Messages:
    1,372
    Likes Received:
    2,432
    Trophy Points:
    113
    Gender:
    Male
    Location:
    London, United Kingdom
    After logging in once you stay logged in to the forum for several days. Although the game, website and forum share credentials they have different session management.
     
    4EverLost likes this.
  7. LoneStranger

    LoneStranger Avatar

    Messages:
    3,023
    Likes Received:
    4,761
    Trophy Points:
    165
    Gender:
    Male
    Location:
    Petaluma, CA
    For security reasons, even if you are 'logged in' for several days, it should still be double-checking your security token validity against a backend server for every interaction. Password changes should kill/expire the token.
     
  8. Berek

    Berek Portalarian Emeritus Dev Emeritus

    Messages:
    3,957
    Likes Received:
    12,761
    Trophy Points:
    165
    Gender:
    Male
    Location:
    Austin, TX
    Please do contact us right away and we will help you here! Thanks everyone for responding and sharing the support link.
     
    Alexander, Tahru, By Tor and 2 others like this.
  9. Sorthious

    Sorthious Avatar

    Messages:
    1,135
    Likes Received:
    1,354
    Trophy Points:
    113
    That's only if you tell your browser to auto-log you I believe. I don't stay logged into anything. I don't have passwords saved or do the whole auto-log thing. However, this wasn't the case for the OP:

    Yeah, I had to cut off the Steam Guard thing. Because of how I have my security set up on my PC it thinks I'm using a different computer/browser configuration every time and is constantly sending me to email to get a code to log back in.(endless loop) Just easier to cut it off! LOL
     
    Moiseyev Trueden likes this.
  10. ThurisazSheol

    ThurisazSheol Avatar

    Messages:
    2,309
    Likes Received:
    3,988
    Trophy Points:
    165
    Location:
    The Drowned Mountains
    odd, just now i couldn't authenticate via steam - even though i did confirm i was in with steam by bouncing out and back into the service a few times. - i then saw that the steam client was asking me to re-validate my email address. once i did that and waited ten minutes, i was fine. so...not a sota issue for me. :)
     
    Leelu and By Tor like this.
  11. majoria70

    majoria70 Avatar

    Messages:
    10,352
    Likes Received:
    24,876
    Trophy Points:
    153
    Gender:
    Female
    Location:
    United States
    Also make sure caps lock wasn't on, yeah yeah yeah, I know you probably checked, but it happened to me earlier ;)
     
    Leelu and Sea Bear like this.
  12. By Tor

    By Tor Avatar

    Messages:
    2,362
    Likes Received:
    4,717
    Trophy Points:
    165
    Gender:
    Male
    Actually,I've had the same thing happen to me on steam numerous times ..once i retry once or twice,it eventually logs me in. this only started happening since the latest release and only after launching sota.
     
    Leelu and ThurisazSheol like this.
  13. Tahru

    Tahru Avatar

    Messages:
    4,800
    Likes Received:
    12,170
    Trophy Points:
    165
    Gender:
    Male
    Location:
    Spite
    Simple suggestion for everyone, not as bad as going to the dentist.... I know many people are like, "Oh <insert word choice>! Is my account safe?"

    1) Don't be stupid and use the same password in more than one place.
    2) Use 16 characters of complete and utter garbage random characters/numbers/symbols as passwords.
    3) Use Lastpass or 1Password, seriously these services are the bomb and they completely remove the problem with making and especially using "great" passwords that have no meaning. They also make it much harder for spyware to grab your passwords. If you aren't using these, you are making a grave mistake in judgement that will someday cost you dearly.
    4) Use the steam login for SOTA (with secondary authentication), especially since SOTA does not offer it.

    Anyone that thinks the password they invented in their head is good enough is a fool. Hackers keep databases and can reverse crack nearly 100% of passwords less than 9 characters in seconds.

    If you think I am blowing steam, try this search and be very afraid.
     
  14. ThurisazSheol

    ThurisazSheol Avatar

    Messages:
    2,309
    Likes Received:
    3,988
    Trophy Points:
    165
    Location:
    The Drowned Mountains
    if this happens multiple times for me i'll file a bug report.. until then i just can't justify one myself, because it could be chalked up to it 'just being that time' for steam to do it sthing...but if it happens again anytime soon, i'm sure it has to do with some faulty wiring between steam and sota.

    thanks for the heads-up


    keepass is also very nice, and for those that need to be even more secure, the database is local and portable, so nothing is 'on the cloud', and the app itself is open source. :) it also has an option to save macros of sorts. i constantly have to write some fairly long BASH or powershell commands (just short enough to not be called scripts lol), and this will save them for ease of use for ya, too. that alone is VERY useful for any administrative duties.



    i also have experience with lastpass. very user friendly, and easy as pie to use in linux (firefox addon), android, windows, and mac. as long as you have 'net access you will be fine.
     
  15. Wintermute of CoF

    Wintermute of CoF Avatar

    Messages:
    1,372
    Likes Received:
    2,432
    Trophy Points:
    113
    Gender:
    Male
    Location:
    London, United Kingdom
    No, it isn't. You login through the Wordpress based main site, this also logs you into the forum. The forum log on survives a browser restart, the Wordpress logon doesn't.

    It's very rare for any federated identity or SSO system to work that way, the authentication is usually done once and then the app or site maintains the session after that. It's possible to still have an active session on the forum but not the main site, which is why posting on the forum isn't evidence that your logon to the main site or the game is currently working.
     
  16. LoneStranger

    LoneStranger Avatar

    Messages:
    3,023
    Likes Received:
    4,761
    Trophy Points:
    165
    Gender:
    Male
    Location:
    Petaluma, CA
    Yes, that's what I was saying. I was just trying to keep it general. Regardless of who approved the initial authentication, the individual applications create their own token and should be checking the veracity of that token when it is given back to them by the client. They would check against server-side data to make sure that their session is valid and hasn't been expired for any reason.
     
  17. Sorthious

    Sorthious Avatar

    Messages:
    1,135
    Likes Received:
    1,354
    Trophy Points:
    113
    That's odd. If I'm auto-logged for days at a time, why do I have to input my account name and password every time I open the forum webpage? If they are tracking my logins already, I could save time if I didn't have to type in name/pw every time.
     
  18. ThurisazSheol

    ThurisazSheol Avatar

    Messages:
    2,309
    Likes Received:
    3,988
    Trophy Points:
    165
    Location:
    The Drowned Mountains
    Do you open directly to the forums, or do you go through the website?
     
    Wintermute of CoF likes this.
  19. Sorthious

    Sorthious Avatar

    Messages:
    1,135
    Likes Received:
    1,354
    Trophy Points:
    113
    I log directly into forums...not from main page. I was just making the point that not everyone lets their browsers auto-log them into sites. Auto logging is dependent upon cookies/cache saving log-in info, unless something has entirely changed with regards to my understanding of how things work. I'm not up on my tech like I used to be, so maybe I am missing something.
     
    Moiseyev Trueden likes this.
Thread Status:
Not open for further replies.