Imgur Account Info Hacked

Discussion in 'General Discussion' started by Satan Himself, Nov 27, 2017.

Thread Status:
Not open for further replies.
  1. Satan Himself

    Satan Himself Avatar

    Messages:
    2,702
    Likes Received:
    12,806
    Trophy Points:
    165
    Paladin Michael, Cordelayne and Leelu like this.
  2. Turk Key

    Turk Key Avatar

    Messages:
    2,561
    Likes Received:
    4,012
    Trophy Points:
    153
    Gender:
    Male
    Hosting site vulnerability is the reason I never post images to this forum. Nothing is free my friends.
     
    Leelu likes this.
  3. DavidDC

    DavidDC Programmer Moderator SOTA Developer

    Messages:
    1,532
    Likes Received:
    3,236
    Trophy Points:
    113
    Gender:
    Male
    maybe in 2025 we will have forums that we can paste from clipboard and then crop the image directly ;p saving times and this kind of thing for everyone
     
  4. Spoon

    Spoon Avatar

    Messages:
    8,403
    Likes Received:
    23,554
    Trophy Points:
    165
    Gender:
    Male
    Location:
    Sweden
    Well....
    It has been part of Xenforo since at least 2010

    but due to potential cost and legality issues that has been disabled in these forums...
     
    Jimmy Cliff likes this.
  5. hammadowna

    hammadowna Avatar

    Messages:
    634
    Likes Received:
    678
    Trophy Points:
    93
    Gender:
    Male
    Much appreciated for the warning! Hard to believe they only now discovered this breach!
     
    jammaplaya likes this.
  6. jammaplaya

    jammaplaya Avatar

    Messages:
    1,139
    Likes Received:
    1,995
    Trophy Points:
    113
    You do realize that you could just set up an account with a fake name since imgur doesn't ask for any personal information, right?
     
    Sempiternal Dragon and Aldo like this.
  7. Turk Key

    Turk Key Avatar

    Messages:
    2,561
    Likes Received:
    4,012
    Trophy Points:
    153
    Gender:
    Male
    A fake name and a fake computer? The problem is not the name, it is the junk loaded on your computer not to mention all the questionable adds people have to suffer when they link to your content.
     
  8. Vallin Tregres

    Vallin Tregres Avatar

    Messages:
    943
    Likes Received:
    1,357
    Trophy Points:
    93
    I use Postimage when I wanna share my shenanigans and just keep pictures stored on my computer rather than online.
     
  9. Lained

    Lained Avatar

    Messages:
    2,804
    Likes Received:
    4,794
    Trophy Points:
    165
    Location:
    Yeovil, England
    Given the lack of personal information that imgur hold I'm not worried. You should never use the same email & password combination across multiple sites for this very reason.
     
  10. Korim Rackham

    Korim Rackham Avatar

    Messages:
    733
    Likes Received:
    1,569
    Trophy Points:
    93
    Gender:
    Male
    Location:
    PIsmo Beach, CA
    thanks for the heads up! Also lets see if this reply gets deleted seems like ive had alot of my posts deleted today....
     
  11. Sara Dreygon

    Sara Dreygon Avatar

    Messages:
    1,678
    Likes Received:
    5,830
    Trophy Points:
    113
    Gender:
    Male
    1. Copy/Paste pic into a Discord channel
    2. Open pic in Discord and view original
    3. Copy URL of pic
    4. Paste URL into forum
    Takes seconds and no website needed.
     
  12. Morgoth redbeard

    Morgoth redbeard Avatar

    Messages:
    250
    Likes Received:
    399
    Trophy Points:
    28
    yes is what i do use discord for my pic uploads
     
    Mykll likes this.
  13. Mykll

    Mykll Avatar

    Messages:
    671
    Likes Received:
    1,223
    Trophy Points:
    105
    Gender:
    Male
    Location:
    Davidian Bunker
    For the lazy:
    1. Copy/Paste (or drag and drop!) pic into a Discord channel
    2. Right-click, Copy Link of pic
    3. Paste URL into forum
     
  14. LoneWerewolf

    LoneWerewolf Guest

  15. Preachyr

    Preachyr Avatar

    Messages:
    457
    Likes Received:
    1,362
    Trophy Points:
    43
    For the Really lazy:

    1. Take picture/Screenshot
    2. Never upload it

    Foolproof!

    :D
     
    Black Tortoise and Mykll like this.
  16. Quenton

    Quenton Avatar

    Messages:
    605
    Likes Received:
    979
    Trophy Points:
    105
    Gender:
    Male
    Location:
    Old Britannia
    The thing about all of these suggestions is that it's possible any of these other places could get hacked just like imgur did.

    I guess Preachyr's suggestion would work
     
  17. Black Tortoise

    Black Tortoise Avatar

    Messages:
    1,961
    Likes Received:
    3,655
    Trophy Points:
    125
    Gender:
    Male
    Location:
    Storm's Reach
    1. Do not use passwords. Use a passphrase.
    2. Come up with a way to combine your passphrase with different concepts that only make sense to you, such that you have a unique passphase for every single site you use.
    3. If 2 sounds hard, then use a master password service, and make use of forgot password services on sites. Do not register with any entity that does not offer HTTPS.
    4. If you still think this sounds hard, have "faith" in proven scientific studies that show that humans are actually very good at remembering many different secret access phrases, it only appears to be a daunting task on the surface.
    5. Enjoy not caring a whole lot if one service gets breached - that password is useless anywhere else!

    Srsly just use a unique password on every thing you use, its not hard, Ive been doing it for a very long time, and I get better at remembering my unique passphrases every year. I even actually have my own sort of "algorithm" for how I jumble special characters into it (#$%^&*!_-+=><etc...).

    Maybe your phassphrase is something like "mommakesthebestturkey". 8-12 chars is simply not long enough these days.

    Then you think about the best year for your mom's turkey, 2017, and you splice it into the phrase, like "mom2makes0the1best7turkey"

    Then you can just spice it up a bit, a la "!moM2maKes0tHe1bEst?tu|2k3y$"

    ...and come up with a clever way of mixing that up for the different sites you would never, ever want someone compromising. Rotate them too, perhaps every 6-10 months or so.

    That might seem like a lot. Trust me, type it a few thousand times, and you wont have a problem doing it, even all the variations for all your diff sites.

    Or just use master password and hope no one gets access to your physical machine/device. As a technologist, Id never do that, I just get really freaking good at typing my passphrases.

    These are the times you live in. The amount of data breaches that occur are far higher than what are reported in mainstream news.The cost to hack your weak security is minuscule compared to what is gained. It gets easier every year. And please, at the very least, please do not reuse the same password on two different sites that are your "top level" security - email you use for identity and that contains sensitive personal data (for identity theft to financial theft), financial sites, or any site you have a credit card stored on.
     
    Paladin Michael likes this.
  18. Lained

    Lained Avatar

    Messages:
    2,804
    Likes Received:
    4,794
    Trophy Points:
    165
    Location:
    Yeovil, England
    Alternatively buy yourself a domain name and use a unique email address for each site.
     
  19. LoneStranger

    LoneStranger Avatar

    Messages:
    3,023
    Likes Received:
    4,761
    Trophy Points:
    165
    Gender:
    Male
    Location:
    Petaluma, CA
    I have a rule: Do not save your password in your browser. Not because of any risk associated with that, but rather, if you have to type your password in each time you are more likely to remember it.
     
  20. LoneStranger

    LoneStranger Avatar

    Messages:
    3,023
    Likes Received:
    4,761
    Trophy Points:
    165
    Gender:
    Male
    Location:
    Petaluma, CA
    This can be used to discover who is selling your information, as well. If each email address you use is unique to the place you signed up, and you start to get email to that address from other places you know immediately who sold it. Just like using a fake name a couple decades ago when signing up for snail-mail newsletters and catalogs.
     
Thread Status:
Not open for further replies.