• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EST 13:32
CET 19:32
KST 03:32
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
RSL Season 3 - RO16 Groups C & D Preview0RSL Season 3 - RO16 Groups A & B Preview2TL.net Map Contest #21: Winners12Intel X Team Liquid Seoul event: Showmatches and Meet the Pros10[ASL20] Finals Preview: Arrival13
Community News
Weekly Cups (Nov 10-16): Reynor, Solar lead Zerg surge1[TLMC] Fall/Winter 2025 Ladder Map Rotation13Weekly Cups (Nov 3-9): Clem Conquers in Canada4SC: Evo Complete - Ranked Ladder OPEN ALPHA8StarCraft, SC2, HotS, WC3, Returning to Blizzcon!45
StarCraft 2
General
RotterdaM "Serral is the GOAT, and it's not close" Weekly Cups (Nov 10-16): Reynor, Solar lead Zerg surge [TLMC] Fall/Winter 2025 Ladder Map Rotation Mech is the composition that needs teleportation t RSL Season 3 - RO16 Groups C & D Preview
Tourneys
$5,000+ WardiTV 2025 Championship RSL Revival: Season 3 Sparkling Tuna Cup - Weekly Open Tournament Constellation Cup - Main Event - Stellar Fest Tenacious Turtle Tussle
Strategy
Custom Maps
Map Editor closed ?
External Content
Mutation # 500 Fright night Mutation # 499 Chilling Adaptation Mutation # 498 Wheel of Misfortune|Cradle of Death Mutation # 497 Battle Haredened
Brood War
General
FlaSh on: Biggest Problem With SnOw's Playstyle What happened to TvZ on Retro? BGH Auto Balance -> http://bghmmr.eu/ SnOw's ASL S20 Finals Review BW General Discussion
Tourneys
[BSL21] GosuLeague T1 Ro16 - Tue & Thu 22:00 CET [Megathread] Daily Proleagues Small VOD Thread 2.0 [BSL21] RO32 Group D - Sunday 21:00 CET
Strategy
How to stay on top of macro? Current Meta PvZ map balance Simple Questions, Simple Answers
Other Games
General Games
Stormgate/Frost Giant Megathread Clair Obscur - Expedition 33 Should offensive tower rushing be viable in RTS games? Path of Exile Nintendo Switch Thread
Dota 2
Official 'what is Dota anymore' discussion
League of Legends
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Deck construction bug Heroes of StarCraft mini-set
TL Mafia
TL Mafia Community Thread SPIRED by.ASL Mafia {211640}
Community
General
US Politics Mega-thread Russo-Ukrainian War Thread The Games Industry And ATVI Things Aren’t Peaceful in Palestine About SC2SEA.COM
Fan Clubs
White-Ra Fan Club The herO Fan Club!
Media & Entertainment
Movie Discussion! [Manga] One Piece Anime Discussion Thread Korean Music Discussion Series you have seen recently...
Sports
2024 - 2026 Football Thread Formula 1 Discussion NBA General Discussion MLB/Baseball 2023 TeamLiquid Health and Fitness Initiative For 2023
World Cup 2022
Tech Support
SC2 Client Relocalization [Change SC2 Language] Linksys AE2500 USB WIFI keeps disconnecting Computer Build, Upgrade & Buying Resource Thread
TL Community
The Automated Ban List
Blogs
Dyadica Gospel – a Pulp No…
Hildegard
Coffee x Performance in Espo…
TrAiDoS
Saturation point
Uldridge
DnB/metal remix FFO Mick Go…
ImbaTosS
Reality "theory" prov…
perfectspheres
Customize Sidebar...

Website Feedback

Closed Threads



Active: 1899 users

GOMTV.net compromised - Page 36

Forum Index > SC2 General
Post a Reply
Prev 1 34 35 36 37 38 44 Next All
obesechicken13
Profile Blog Joined July 2008
United States10467 Posts
August 13 2011 23:17 GMT
#701
On August 14 2011 07:54 deek wrote:
Show nested quote +
On August 14 2011 07:19 obesechicken13 wrote:
On August 14 2011 07:17 yoshi245 wrote:
On August 14 2011 06:00 Soleron wrote:
On August 14 2011 05:58 obesechicken13 wrote:

Also, Rich, I'm disappointed in you. Why would you recommend keypass instead of lastpass? Is it because keypass is open source? You can't use it from multiple computers. I think it's better to use lastpass.

lastpass
Use this instead of keypass.


Lastpass could be sending your passwords to the developer. In fact the same mechanism as your comic: cool free application that gets a lot of downloads and then they have your information.

Open source is required for anything like this.



I still use lastpass despite it being sort of compromised some weeks ago, but even then the passwords that may or may not have been taken were still encrypted and people with lengthy passes would take forever to decrypt nonetheless. And since then I changed my own lastpass master pass to be something convoluted and over 20 alphanumeric.

As to the issue of it being sent to the dev, don't know anything about that, though it's a possibility with just about any of these password services that can remain as a risk.

Makes me glad I log in to GOM via facebook.

The people who hacked into lastpass (potentially, not certain if they even did) were only in long enough to get like 20 passwords from their database. Lastpass is pretty secure.


Your post shows the exact reason why Lastpass cant work, even if they only got 20 passwords.. Its 20 passwords to paypal/banks/battlenetaccounts etc, Last pass will store the info in their database with an ecryption key, but the problem is anyone else can get the encryption key as its in their program. Its like having a shop with everyones information for free if u can break into the shop, history has shown us even those in Internet Security have lax security

To attempt it with KeePass would require the hacker to break into your computer first, and thats very unlikely to happen unless you were personally targeted, because developing a worm that searched for users who ran KeePass and had an exploit available for them to access is too much time, when they could break into Lastpass and steal thousands of important user names and passwords

20 secure passwords that potentially could've been stolen. There was no evidence that anything was stolen, only that there was an unusual amount of bandwith at a weird hour.

I don't know much about the encryption algorithm they use at lastpass, but let's put it this way. This is not a college student project. They do not reuse the same exact encryption key on every user. I suspect the use something like rainbow encryption tables http://en.wikipedia.org/wiki/Rainbow_table. The hackers were not able to get the encryption key... and they can not get the encryption keys.

Lastpass can not access your passwords so hackers can't either.

Your Security Is Our Priority

LastPass is an evolved Host Proof hosted solution, which avoids the stated weakness of vulnerability to XSS as long as you're using the add-on. LastPass strongly believes in using local encryption, and locally created one way salted hashes to provide you with the best of both worlds for your sensitive information: Complete security, while still providing online accessibility and syncing capabilities. We've accomplished this by using 256-bit AES implemented in C++ and JavaScript (for the website) and exclusively encrypting and decrypting on your local PC. No one at LastPass can ever access your sensitive data. We've taken every step we can think of to ensure your security and privacy.
Availability

You need to always have access to your data, we've accomplished this in multiple ways, first we have 2 data-centers in production service, second we store your encrypted data on your local PC when you login, so that if LastPass.com can't be reached, you can still login to the add-on and get to your accounts. The website is usable without the add-on installed (the Encryption and Decryption happens in JavaScript which you can see happen on some forms), but we take advantage of faster encryption available in the add-ons if they're available. We also have a mobile site m.lastpass.com if you're on your phone.
Security

On Windows, LastPass helps find insecure passwords stored on your computer so you can store them securely in LastPass and remove the easy access by malicious software. LastPass uses SSL exclusively for data transfer even though the vast majority of data you're sending is already encrypted with 256-bit AES and unusable to both LastPass and any party listening in to the network traffic -- the amount of data is trivial so the extra encryption doesn't hurt. Our policy of never receiving private data that you haven't already locked down with your LastPass master password (which we never receive and will never ask for) radically reduces attack vectors. We use firewalls and best practices to protect the servers and service, but our best line of defense is simply not having access to data even if someone got in. If LastPass can't access it, hackers can't either.

https://lastpass.com/whylastpass_technology.php?fromwebsite=1
I think what the bolded part means is that lastpass uses private decryption keys on the client side. Like when the developer at lastpass looks at the passwords in their tables, they are all encrypted passwords. The developer doesn't know how to decrypt the passwords, only you have the decryption key.

In other words, if the passwords were secure enough (not a dictionary word), the encryption would've saved the users even if they were stolen. If they weren't, well then it'd be easier to just hack paypal or your bank account and these idiots should stop using "password" as their primary password for everything.

The passwords are all stored in huge gigabyte large files filled with garbage, and when 20 of them are transferred, the server automatically detects the hack and shuts down.

In addition, lastpass doesn't normally store information on banking accounts or paypal accounts because the paypal and banks sites tell lastpass not to.




I'll end my long post like this:
Lastpass probably isn't infinitely secure. The worst thing that could happen is that the primary developer is really evil. But it is more secure than just about anything else out there including your banks sites and paypal.

Keepass is open source. There are many concerns about open source being unsecure. http://www.internetnews.com/skerner/2010/03/is-open-source-software-more-s.html
You made the claim that someone could potentially create a worm to take passwords from keepass. Well someone could (and you say they wouldn't), but it'd be significantly easier to create keylogger malware or something similar. If someone gets access to your computer through a virus, your computer is no longer yours, so I seriously doubt keepass is any safer than lastpass in that respect.
I think in our modern age technology has evolved to become more addictive. The things that don't give us pleasure aren't used as much. Work was never meant to be fun, but doing it makes us happier in the long run.
Zinnwaldite
Profile Joined August 2010
Norway1567 Posts
Last Edited: 2011-08-13 23:27:16
August 13 2011 23:17 GMT
#702
how do i find out my nick? i can't sign in with my password and need to know the nick to reset.. *_*

though i think the nick is right,, it's just not working,,
We promise with a view to hope, but the reason to "accomplish" what we promised would be fear.
Caseyclysm
Profile Joined May 2010
United States104 Posts
August 13 2011 23:19 GMT
#703
That's too bad for Gomtv. I hope noone has anything stolen because of this and that Gomtv continues to provide us with great service!
“You cannot teach a man anything; you can only help him discover it in himself.” -Galileo Galilei
Antoine
Profile Blog Joined May 2010
United States7481 Posts
August 13 2011 23:33 GMT
#704
looks like they killed all the cookies and are forcing a password change on login, good step to take imo ^^
ModeratorFlash Sea Action Snow Midas | TheStC Ret Tyler MC | RIP 우정호
vlf
Profile Joined April 2010
Portugal170 Posts
August 13 2011 23:40 GMT
#705
And this is why I use dummy passwords for non-financial related sites.
çpç
Seraphic
Profile Joined September 2010
United States3849 Posts
August 13 2011 23:42 GMT
#706
just have to change. probably for the better regardless.
Natus Vincere Fan | Team Secret Fan | SK Telecom T1 Fan | Lanaya the Templar Assassin <3
thecoupe
Profile Joined June 2011
United States77 Posts
August 13 2011 23:46 GMT
#707
Plaintext? Really? Come on GOM, can't you at least use md5?
Pandemona *
Profile Blog Joined March 2011
Charlie Sheens House51493 Posts
August 13 2011 23:46 GMT
#708
On August 14 2011 08:17 Zinnwaldite wrote:
how do i find out my nick? i can't sign in with my password and need to know the nick to reset.. *_*

though i think the nick is right,, it's just not working,,



Same with me dude! I think we got hacked and they changed our nicknames because you can do that i think.

I sent them an email with a few details for them to give me my accounts back, i suggest you do the same.

support@gomtv.net
ModeratorTeam Liquid Football Thread Guru! - Chelsea FC ♥
D_K_night
Profile Joined April 2010
Canada615 Posts
August 13 2011 23:51 GMT
#709
The ironic thing in all this, is this:

I couldn't even create a GOMTV.net username/password in the early days when I wanted to watch SC2 games. Because I couldn't, I was forced to sign-up on twitter - just so I could watch GOMTV.

So I suppose things are totally safe on my end here? And yes I use different passwords for everything.
Canada
LetoAtreides82
Profile Joined January 2011
United States1188 Posts
August 13 2011 23:55 GMT
#710
On August 14 2011 08:00 Glowbox wrote:
Show nested quote +
On August 14 2011 07:47 R1CH wrote:
Email from GOM:


You received an actual e-mail? I did not get one yet. Anyone else?


I got the email.
The spice must flow
Goldfish
Profile Blog Joined August 2010
2230 Posts
August 13 2011 23:56 GMT
#711
So GOMTV is safe now right (or at least they're trying to fix the security holes atm?). Also only thing compromised are user info, the site itself (like admin password, etc) isn't compromised right?
https://connect.microsoft.com/WindowsServerFeedback/feedback/details/741495/biggest-explorer-annoyance-automatic-sorting-windows-7-server-2008-r2-and-vista#details Allow Disable Auto Arrange in Windows 7+
Pandemona *
Profile Blog Joined March 2011
Charlie Sheens House51493 Posts
August 14 2011 00:03 GMT
#712
On August 14 2011 08:46 Pandemona wrote:
Show nested quote +
On August 14 2011 08:17 Zinnwaldite wrote:
how do i find out my nick? i can't sign in with my password and need to know the nick to reset.. *_*

though i think the nick is right,, it's just not working,,



Same with me dude! I think we got hacked and they changed our nicknames because you can do that i think.

I sent them an email with a few details for them to give me my accounts back, i suggest you do the same.

support@gomtv.net



Just had a response and they said this;

Dear User:

Your nickname has not been modified by anyone.
At the moment we have similar problem with users e-mail containing under scroll. ( _ )
This will be fixed momentarily

We greatly appreciate your patience and understanding and we pledge to work harder to bring you a better and greater service experience.


GOMTV.net



Hope this helps
ModeratorTeam Liquid Football Thread Guru! - Chelsea FC ♥
Carbonthief
Profile Joined October 2010
United States289 Posts
August 14 2011 00:20 GMT
#713
OH shit, good thing I used a different password...
GOM.Sam
Profile Joined February 2011
Korea (South)210 Posts
August 14 2011 01:00 GMT
#714
Apart from GOM's apology I would personally like to apologize for the inconvenience and concern we have caused you.

Please, if you have not yet, visit GOMTV.net to change your GOM password. Clicking sign in and entering your ID (e-mail address) and old password will direct you to change your password.

If you have been using the same password for other web sites, please change the passwords for those sites as well.

Thank you for your patience and understanding.
Roll Tide.
TDN3
Profile Joined August 2011
United States81 Posts
August 14 2011 01:03 GMT
#715
glad I changed my passwords yesterday.

So, who's the dump hacker?
Goragoth
Profile Blog Joined April 2009
New Zealand1065 Posts
August 14 2011 01:06 GMT
#716
Hang on, what the hackers got are hashed and salted passwords, right?? I mean no fucking moron would be stupid enough to save passwords in plaintext. Seriously if they did then they should be sued into the fucking ground because that would be such utter stupidity on a level I just don't understand.
Creator of LoLTool.
tjg92
Profile Joined March 2011
United States100 Posts
August 14 2011 01:07 GMT
#717
Glad I logged in with Twitter.
The Maze Blog: http://mazeblog-tjg92.blogspot.com
XRaDiiX
Profile Blog Joined November 2010
Canada1730 Posts
Last Edited: 2011-08-14 01:17:23
August 14 2011 01:15 GMT
#718
On August 14 2011 07:49 R1CH wrote:
I have to say I'm happy how this was handled by GOM. 1-2 days notice is better than none at all - many companies will actively try to cover up or downplay such attacks or claim that sensitive data was never stolen.


That's true.

We need to uncover who was really behind these attacks. Was it Kespa? (Sc1 Elitists?)

Was it just some hacker trying to make a buck getting E-mails for spam and/or passwords that might correlate with peoples Paypal account.

We may never know. But lets hope they find out who committed this attack against their website. It was bad enough the security of their site was severely lacking; i hope they can find out who did this and bring them to justice for an attack on E-Sports.


Long Live GomTv and the GSL for their Great contribution to E-Sports for SC2 Thank you.
Never GG MKP | IdrA
Kamikiri
Profile Joined October 2010
United States1319 Posts
August 14 2011 01:19 GMT
#719
Sucks having to change all of my passwords and everything but i cant really say im upset because i enjoy watching koreans play while tastosis talks about random stuff, livin the good life.
Ghad
Profile Blog Joined April 2010
Norway2551 Posts
August 14 2011 01:19 GMT
#720
On August 14 2011 08:51 D_K_night wrote:
The ironic thing in all this, is this:

I couldn't even create a GOMTV.net username/password in the early days when I wanted to watch SC2 games. Because I couldn't, I was forced to sign-up on twitter - just so I could watch GOMTV.

So I suppose things are totally safe on my end here? And yes I use different passwords for everything.



Lol. When GSL started last summer i found that most days that foreigners were playing it was inpossible to log in with gomtv user/pass, so i switched to twitter auth which was more likely to work.
forgottendreams: One underage girl, two drunk guys, one gogo dancer and starcraft 2. Apparently just another day in Europe.
Prev 1 34 35 36 37 38 44 Next All
Please log in or register to reply.
Live Events Refresh
Monday Night Weeklies
17:00
#30
RotterdaM952
TKL 367
IndyStarCraft 177
SteadfastSC122
BRAT_OK 92
ZombieGrub39
LiquipediaDiscussion
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
RotterdaM 952
TKL 367
Reynor 317
IndyStarCraft 177
ProTech124
SteadfastSC 122
BRAT_OK 92
UpATreeSC 60
JuggernautJason44
ZombieGrub39
MindelVK 25
Vindicta 16
StarCraft: Brood War
Britney 27424
Calm 3018
Horang2 1318
firebathero 205
Dewaltoss 80
Killer 44
scan(afreeca) 38
Rock 37
yabsab 12
Dota 2
qojqva3277
resolut1ontv 196
BananaSlamJamma158
Other Games
Beastyqt770
ceh9437
Lowko311
Hui .149
Liquid`VortiX145
QueenE49
Trikslyr48
Organizations
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 20 non-featured ]
StarCraft 2
• kabyraGe 95
• Adnapsc2 8
• Reevou 3
• Kozan
• sooper7s
• AfreecaTV YouTube
• Migwel
• intothetv
• LaughNgamezSOOP
• IndyKCrew
StarCraft: Brood War
• HerbMon 28
• STPLYoutube
• ZZZeroYoutube
• BSLYoutube
Dota 2
• WagamamaTV552
• lizZardDota244
• Noizen35
League of Legends
• Nemesis4606
Other Games
• imaqtpie763
• Shiphtur235
Upcoming Events
Replay Cast
4h 28m
ChoboTeamLeague
6h 28m
WardiTV Korean Royale
17h 28m
BSL: GosuLeague
1d 2h
PiGosaur Cup
1d 6h
The PondCast
1d 15h
Replay Cast
2 days
RSL Revival
2 days
herO vs Zoun
Classic vs Reynor
Maru vs SHIN
MaxPax vs TriGGeR
BSL: GosuLeague
3 days
RSL Revival
3 days
[ Show More ]
WardiTV Korean Royale
3 days
RSL Revival
4 days
WardiTV Korean Royale
4 days
IPSL
4 days
Julia vs Artosis
JDConan vs DragOn
RSL Revival
5 days
Wardi Open
5 days
IPSL
6 days
StRyKeR vs OldBoy
Sziky vs Tarson
Replay Cast
6 days
Liquipedia Results

Completed

Proleague 2025-11-14
Stellar Fest: Constellation Cup
Eternal Conflict S1

Ongoing

C-Race Season 1
IPSL Winter 2025-26
KCM Race Survival 2025 Season 4
SOOP Univ League 2025
YSL S2
BSL Season 21
CSCL: Masked Kings S3
SLON Tour Season 2
RSL Revival: Season 3
META Madness #9
BLAST Rivals Fall 2025
IEM Chengdu 2025
PGL Masters Bucharest 2025
Thunderpick World Champ.
CS Asia Championships 2025
ESL Pro League S22
StarSeries Fall 2025
FISSURE Playground #2
BLAST Open Fall 2025

Upcoming

BSL 21 Non-Korean Championship
Acropolis #4
IPSL Spring 2026
HSC XXVIII
RSL Offline Finals
WardiTV 2025
IEM Kraków 2026
BLAST Bounty Winter 2026
BLAST Bounty Winter 2026: Closed Qualifier
eXTREMESLAND 2025
ESL Impact League Season 8
SL Budapest Major 2025
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2025 TLnet. All Rights Reserved.