1. Here you will find official announcements and updates. These announcements are also linked in the Official SotA Discord server.
    We encourage comments from the community! To keep the announcements official, we ask that comment threads be created in the General forums for player input.

                                                 Thanks!

Password Change Request Due to Other Sites Being Compromised

Discussion in 'Announcements' started by Berek, Aug 11, 2016.

Thread Status:
Not open for further replies.
  1. Berek

    Berek Portalarian Emeritus Dev Emeritus

    Messages:
    3,957
    Likes Received:
    12,761
    Trophy Points:
    165
    Gender:
    Male
    Location:
    Austin, TX
    Earlier this year a few well-known games and sites were compromised, and lists of usernames and passwords became widely available. Yesterday, it was revealed that DOTA2 was the latest victim.

    We continue to be fortunate enough to not be one of the victims of these attacks. However we are under a hacking attack that is using these leaked username/password combinations to try and login to Shroud and has succeeded several times so far. If you have played one of these games that has been compromised you may be one of the victims we identified today.

    You must make sure your username, or at least your password is unique on our site. We insist that you change your password if you have any doubt. FYI, this is good security behavior in general.

    For now we have temporarily disabled login to the official website until 6:00 PM CDT (11:00 PM UTC). When we bring it back up, please login to the website, click on "Account" to go to your Account Page, click "Edit Profile" link beneath your profile image, and enter a new password on your Profile Settings page.
     
    Last edited: Aug 11, 2016
  2. Drocis the Devious

    Drocis the Devious Avatar

    Messages:
    18,188
    Likes Received:
    35,440
    Trophy Points:
    153
    Gender:
    Male
    Two Factor Authentication would be nice.
     
  3. smack

    smack Avatar

    Messages:
    7,077
    Likes Received:
    15,288
    Trophy Points:
    153
    2FA could have prevented this...just sayin'. :)

    But yes, using the same password on multiple sites is not a good thing.
     
  4. Chris

    Chris Tech Lord Moderator Ambassador SOTA Developer

    Messages:
    2,470
    Likes Received:
    27,551
    Trophy Points:
    190
    Gender:
    Male
    Agree, if we FORCED 2fa on everyone, like Steam does, it would have avoided this. Just having 2fa as an option would not have helped. The people who were compromised were using the same username/pw on multiple sites so not really the security conscious group. Definitely will start more serious discussions about mandatory 2fa though!
     
  5. Drocis the Devious

    Drocis the Devious Avatar

    Messages:
    18,188
    Likes Received:
    35,440
    Trophy Points:
    153
    Gender:
    Male
    Yubikey support would be appreciated.
     
    gadget, Time Lord, Tahru and 3 others like this.
  6. Chris

    Chris Tech Lord Moderator Ambassador SOTA Developer

    Messages:
    2,470
    Likes Received:
    27,551
    Trophy Points:
    190
    Gender:
    Male
    Also, I can provide a bit more info without compromising our investigation. This was a distributed bot dictionary attack. They are trying thousands of username/pw combos alphabetically from a list. 99% of them are failing because the user name isn't a valid user which is a sign that they are using someone elses list. We throttle and block IPs that fail logins and have blocked more than 500 so far and are turning up the amount of throttling and reducing the blocking threshold BUT as with all distributed attacks, they have what seems to be infinite IPs.

    We get these attacks almost daily but this one actually had some matches which is why we're advising PW security.
     
  7. Rufus D`Asperdi

    Rufus D`Asperdi Avatar

    Messages:
    6,347
    Likes Received:
    15,785
    Trophy Points:
    165
    Gender:
    Male
    Location:
    Austin, TX
    Without knowing the list of "a few well-known games" or what DOTA2 is, it's impossible for anyone to make an accurate risk assessment. My password is only used here, and is very strong because it's good practice ESPECIALLY IN THE ABSENCE OF 2-FACTOR AUTHENTICATION and I like keeping my substantial investment with Me.
     
    Last edited: Aug 11, 2016
  8. DancingShade

    DancingShade Avatar

    Messages:
    320
    Likes Received:
    678
    Trophy Points:
    43
    Location:
    Australia
    Thanks for the heads up!

    Fortunately I always do the right thing and never reuse a password or passphrase anywhere. Still, it's always a good habit to change passwords frequently for reasons just like this, so I have.
     
    Time Lord and Duchess Fionwyn like this.
  9. Astor Cerberus

    Astor Cerberus Avatar

    Messages:
    385
    Likes Received:
    997
    Trophy Points:
    55
    Gender:
    Male
    Location:
    Texas, USA
    @Berek - is there a way to change our account username? password strength is half the solution. When I look at my profile I can change my password and my display name but not my username.
     
    Retlaw, strabo, Time Lord and 2 others like this.
  10. Beaumaris

    Beaumaris Avatar

    Messages:
    4,301
    Likes Received:
    7,423
    Trophy Points:
    165
    Gender:
    Male
    Location:
    Caladruin
    How about the ability to type longer passwords? The string length seems shorter in the available space than I use on some other sites. Or is it just difficult to see more characters being added?
     
  11. EVL Treasurer

    EVL Treasurer Avatar

    Messages:
    108
    Likes Received:
    106
    Trophy Points:
    30
    Gender:
    Female
    @Chris Discussion on 2fa is nice. Doesn't do a bit of good to just talk about it, however. Force it on us today.
     
    gadget, Ravalox, strabo and 3 others like this.
  12. Yeorl

    Yeorl Avatar

    Messages:
    2
    Likes Received:
    24
    Trophy Points:
    3
    Gender:
    Male
    Location:
    Los Angeles, CA
    If you log into your account exclusively via Steam, it might be cool to have a feature where you could disable regular SotA logins for your account via the profile settings page. Not as good as 2fa for everybody, but could be a reasonable interim solution for that subset of users.
     
    Rebelweasel and Time Lord like this.
  13. Drocis the Devious

    Drocis the Devious Avatar

    Messages:
    18,188
    Likes Received:
    35,440
    Trophy Points:
    153
    Gender:
    Male
    I'd like the ability to change user name too.
     
    strabo and Time Lord like this.
  14. Tahru

    Tahru Avatar

    Messages:
    4,800
    Likes Received:
    12,170
    Trophy Points:
    165
    Gender:
    Male
    Location:
    Spite
    Glad to see this addressed proactively.
     
  15. Alley Oop

    Alley Oop Bug Hunter Bug Moderator

    Messages:
    15,754
    Likes Received:
    19,478
    Trophy Points:
    153
    what would the second factor be, since the nist is now actively warning against using phones?
     
    Saosis and Time Lord like this.
  16. John Markus

    John Markus Avatar

    Messages:
    305
    Likes Received:
    324
    Trophy Points:
    43
    Gender:
    Male
    Location:
    Tokyo, Japan
    I use unique passwords on all sites.
    That being said, Google Authenticator compatible 2fa would help my smart phone being clutter free.
     
    Time Lord likes this.
  17. Drocis the Devious

    Drocis the Devious Avatar

    Messages:
    18,188
    Likes Received:
    35,440
    Trophy Points:
    153
    Gender:
    Male
    The cheapest option would be $18. Which of course is not feasible to "force" people to buy, nor is it reasonable for Portalarium to put pledge dollars towards that. However, it would make a great premium option that I would very much support.


    Not to mention you could totally brand this as the Oracle Authenticator, and sell it in the shape of a watcher. :)
    [​IMG]
     
    Last edited: Aug 11, 2016
  18. Drocis the Devious

    Drocis the Devious Avatar

    Messages:
    18,188
    Likes Received:
    35,440
    Trophy Points:
    153
    Gender:
    Male
    Also...

    http://www.slate.com/blogs/future_t...from_sms_based_two_factor_authentication.html
     
    Astor Cerberus and Time Lord like this.
  19. Justen Thyme

    Justen Thyme Avatar

    Messages:
    14
    Likes Received:
    19
    Trophy Points:
    3
    Reluctantly, I agree that we should have 2 factor authentication. It is just not worth the risk not to. Besides, Portalarium should not want to have to return stuff to many many users if they have a big failure.
     
    Time Lord likes this.
  20. Frederick Glasgow

    Frederick Glasgow Avatar

    Messages:
    729
    Likes Received:
    2,052
    Trophy Points:
    93
    2Fa would be nice,or at least give us a option to have a code sent to our cell phone number we provide with a verification code to enable a password change or a log in from a unknown computer.
     
Thread Status:
Not open for further replies.