• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EST 13:17
CET 19:17
KST 03:17
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
RSL Season 3 - RO16 Groups C & D Preview0RSL Season 3 - RO16 Groups A & B Preview2TL.net Map Contest #21: Winners12Intel X Team Liquid Seoul event: Showmatches and Meet the Pros10[ASL20] Finals Preview: Arrival13
Community News
[TLMC] Fall/Winter 2025 Ladder Map Rotation13Weekly Cups (Nov 3-9): Clem Conquers in Canada4SC: Evo Complete - Ranked Ladder OPEN ALPHA8StarCraft, SC2, HotS, WC3, Returning to Blizzcon!45$5,000+ WardiTV 2025 Championship7
StarCraft 2
General
[TLMC] Fall/Winter 2025 Ladder Map Rotation Mech is the composition that needs teleportation t RotterdaM "Serral is the GOAT, and it's not close" RSL Season 3 - RO16 Groups C & D Preview TL.net Map Contest #21: Winners
Tourneys
RSL Revival: Season 3 Sparkling Tuna Cup - Weekly Open Tournament Constellation Cup - Main Event - Stellar Fest Tenacious Turtle Tussle Master Swan Open (Global Bronze-Master 2)
Strategy
Custom Maps
Map Editor closed ?
External Content
Mutation # 499 Chilling Adaptation Mutation # 498 Wheel of Misfortune|Cradle of Death Mutation # 497 Battle Haredened Mutation # 496 Endless Infection
Brood War
General
FlaSh on: Biggest Problem With SnOw's Playstyle BGH Auto Balance -> http://bghmmr.eu/ What happened to TvZ on Retro? SnOw's ASL S20 Finals Review BW General Discussion
Tourneys
[Megathread] Daily Proleagues Small VOD Thread 2.0 [BSL21] RO32 Group D - Sunday 21:00 CET [BSL21] RO32 Group C - Saturday 21:00 CET
Strategy
PvZ map balance Current Meta Simple Questions, Simple Answers How to stay on top of macro?
Other Games
General Games
Path of Exile Clair Obscur - Expedition 33 Should offensive tower rushing be viable in RTS games? Stormgate/Frost Giant Megathread Nintendo Switch Thread
Dota 2
Official 'what is Dota anymore' discussion
League of Legends
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Deck construction bug Heroes of StarCraft mini-set
TL Mafia
TL Mafia Community Thread SPIRED by.ASL Mafia {211640}
Community
General
US Politics Mega-thread Things Aren’t Peaceful in Palestine Russo-Ukrainian War Thread Artificial Intelligence Thread Canadian Politics Mega-thread
Fan Clubs
White-Ra Fan Club The herO Fan Club!
Media & Entertainment
Movie Discussion! [Manga] One Piece Anime Discussion Thread Korean Music Discussion Series you have seen recently...
Sports
2024 - 2026 Football Thread Formula 1 Discussion NBA General Discussion MLB/Baseball 2023 TeamLiquid Health and Fitness Initiative For 2023
World Cup 2022
Tech Support
SC2 Client Relocalization [Change SC2 Language] Linksys AE2500 USB WIFI keeps disconnecting Computer Build, Upgrade & Buying Resource Thread
TL Community
The Automated Ban List
Blogs
Dyadica Gospel – a Pulp No…
Hildegard
Coffee x Performance in Espo…
TrAiDoS
Saturation point
Uldridge
DnB/metal remix FFO Mick Go…
ImbaTosS
Reality "theory" prov…
perfectspheres
Customize Sidebar...

Website Feedback

Closed Threads



Active: 1949 users

GOMTV.net compromised

Forum Index > SC2 General
Post a Reply
Normal
R1CH
Profile Blog Joined May 2007
Netherlands10341 Posts
Last Edited: 2011-08-13 22:47:11
August 12 2011 18:14 GMT
#1
There's a post on reddit that suggests that GOMTV has been compromised. I have independently verified that at least some usernames, passwords and email addresses have been compromised.

There appears to be zero security on the passwords as they were stored in plain text (really GOM?). This means if you use your GomTV password anywhere else, you should change it and consider it compromised. To clarify, your GomTV.net username, email address, PayPal real name and your GomTV.net password are likely compromised. Personal information such as your address may be compromised too if it was stored. You should also change your GomTV password to prevent unauthorized account access, although the exploit through which the information was compromised may still exist.

Since payments are processed through PayPal, there is no risk of your financial information being compromised, unless you used your PayPal password when signing up for GomTV (don't do this). Users who logged in via SNS should be safe as Twitter / Facebook authentication is token based, not password based.

If you aren't already, you should really use unique passwords for each website since this happens more often than you think (ever hear someone say they were "hacked"? this is likely how it happens) and not all websites will disclose if they get compromised. Use http://keepass.info/ for password management.

UPDATE: Email from GOM:
Dear Valued GOMTV.net users:

We regretfully inform you that approximately at 2 AM KST, Aug.12th, there has been an attack against our web site, GOMTV.net.

We have found that some of the user information from GOMTV.net has been compromised from the attack. We suspect that the following information might have been exposed: name, location (country), e-mail address, GOMTV.net nickname and password.

We deeply apologize for the inconvenience and concern caused by the intrusion.

Since we use PayPal’s service to handle payments, we do not store nor have any payment related information on our site including your credit card numbers and bank account details.

We strongly encourage you to change your GOMTV.net password and if you have been using the same password for other web sites, we suggest changing the passwords for those sites as well.

Users who have signed up with Facebook or Twitter do not have to worry about changing their passwords as they did not have to enter separate passwords at the time of sign up.

As soon as we discovered the sign of intrusion we have conducted a complete investigation into the incident and have also taken steps to enhance security and strengthen our network system in order to provide you with better protection of your personal information.

We greatly appreciate your patience and understanding and we pledge to work harder to bring you a better and greater service experience.

If you have any concerns or questions please feel free to contact us at support@gomtv.net.

Thank you.
GOMTV.net
AdministratorTwitter: @R1CH_TL
TL+ Member
atmuh
Profile Blog Joined November 2010
United States246 Posts
August 12 2011 18:16 GMT
#2
oh god
Cyrak
Profile Joined July 2011
Canada536 Posts
August 12 2011 18:16 GMT
#3
I use Facebook to login but this is pretty unfortunate. Thanks for the alert.
Fortune favors the prepared mind.
SniXSniPe
Profile Blog Joined March 2010
United States1938 Posts
Last Edited: 2011-08-12 18:17:22
August 12 2011 18:16 GMT
#4
Thankfully I always logged in via Twitter =).


Helpful comment for those of you unsure of what this means, via Reddit.
+ Show Spoiler +

Bank details are NOT at risk. While this is bad for GOM, don't start sensationalising it. Saying its "a leak on the scale of the PSN shitstorm" is bullshit, plain and simple.

All payments made to GOM are handled through PayPal. GOM has no access to your financial details in the first place, so bank details have not and never will be compromised. This is why so many internet vendors use PayPal; its amazingly secure, and all payments are processed externally.

I can see you getting more and more worked up about this with every comment. Calm the fuck down. It's bad and GOM certainly needs to fix it, but at the end of the day a bunch of names and e-mails isn't really the most private of data.

thoradycus
Profile Joined August 2010
Malaysia3262 Posts
August 12 2011 18:16 GMT
#5
I used visa/mastercard to buy my ticket. Am I in trouble?
Benjef
Profile Blog Joined December 2010
United Kingdom6921 Posts
Last Edited: 2011-08-12 18:17:32
August 12 2011 18:16 GMT
#6
Failed to read the very last line ><.

Well this sucks thankfully I use Twitter :D
<3 | Dota 2 | DayZ | <3
Zeburial
Profile Blog Joined May 2009
Sweden1126 Posts
Last Edited: 2011-08-12 18:18:12
August 12 2011 18:16 GMT
#7
"There appears to be zero security on the passwords as they were stored in plain text (really GOM?)."

wtf? Changing my password this second!

EDIT: hmpf.. how do I change my GOMpassword? XD
Empires are not brought down by outside forces - they are destroyed by weaknesses from within
Zuxo
Profile Joined April 2010
Sweden395 Posts
August 12 2011 18:16 GMT
#8
WTF?!
I'm a mother******* lyrical wordsmith, mother******* genius
JonB
Profile Joined February 2011
Sweden325 Posts
Last Edited: 2011-08-12 19:00:16
August 12 2011 18:16 GMT
#9
seriously? wow, didnt expect this from gom

edit: chobo spelling
hacker and programmer - the2me4u on skype
Ashes
Profile Joined January 2011
United States362 Posts
August 12 2011 18:17 GMT
#10
Thanks for info R1CH. right on it!
xSixGeneralHan
Profile Joined April 2011
United States528 Posts
August 12 2011 18:17 GMT
#11
Oh god. Thanks for verifying, youre awesome. But really gom? Holy crap, how lax
Team Operations Director for CheckSix Gaming
MinoMino
Profile Blog Joined April 2010
Norway1103 Posts
August 12 2011 18:17 GMT
#12
Man, there are way too many sites out there that store passwords in plain text. I guess it's time to change passwords again. D:
Blah.
Moobutt
Profile Joined May 2011
United States1996 Posts
August 12 2011 18:17 GMT
#13
Any word on when the compromise took place? I recently changed my GOMTV password and was wondering if I maybe inadvertently saved my self some time.
3/22/16 The Day EG Died
Khenra
Profile Blog Joined January 2009
Netherlands885 Posts
Last Edited: 2011-08-12 18:23:59
August 12 2011 18:17 GMT
#14
What the fuck.....

That was the last thing I would expect from GOM. Very unfortunate.
This signature is ruining eSports.
radim
Profile Joined October 2009
Czech Republic122 Posts
August 12 2011 18:18 GMT
#15
On August 13 2011 03:14 R1CH wrote:
...the passwords as they were stored in plain text...

are you serious? oh my god :x
끝까지.
itsjustatank
Profile Blog Joined November 2010
Hong Kong9159 Posts
Last Edited: 2011-08-12 18:24:38
August 12 2011 18:18 GMT
#16
On August 13 2011 03:14 R1CH wrote:
There appears to be zero security on the passwords as they were stored in plain text (really GOM?). This means if you use your GomTV password anywhere else, you should change it and consider it compromised. To clarify, your GomTV.net username, email address, PayPal real name and your GomTV.net password are likely compromised. Personal information such as your address may be compromised too if it was stored. You should also change your GomTV password to prevent unauthorized account access.


What if you've been using third-party authentication, ie having my twitter login be my GomTV login? Is my Twitter compromised?

edit: oh gg im dumb, sorry. good thing I did use twitter for authentication, then. this thread should probably be highlighted on the front page for people so it gets more attention
Photographer"nosotros estamos backamos" - setsuko
forgottendreams
Profile Joined August 2010
United States1771 Posts
August 12 2011 18:18 GMT
#17
Man this is a horrible day of hard knock SC2 news.... it's almost depressing.
Keap
Profile Joined July 2010
United States214 Posts
August 12 2011 18:18 GMT
#18
GOM is so unprofessional. The level of play of their players is amazing, but the business side of the Korean SC2 scene is really lacking to say the least.
yukimochi
Profile Joined December 2010
Japan27 Posts
August 12 2011 18:18 GMT
#19
does changing my gomtv password right now makes me safe or.. do i have to change everything?
GSL Forever the win!
lbmaian
Profile Joined December 2010
United States689 Posts
August 12 2011 18:19 GMT
#20
Wow, I didn't expect to be thanking Facebook for my password safekeeping.
Navichi
Profile Joined July 2011
49 Posts
August 12 2011 18:19 GMT
#21
wow im so lucky i used a password i used NOWHERE else, phew
٩(͡๏̯͡๏)۶
R1CH
Profile Blog Joined May 2007
Netherlands10341 Posts
August 12 2011 18:19 GMT
#22
On August 13 2011 03:16 thoradycus wrote:
I used visa/mastercard to buy my ticket. Am I in trouble?

No, your financial information is safe since payments are done via PayPal.

On August 13 2011 03:18 itsjustatank wrote:
What if you've been using third-party authentication, ie having my twitter login be my GomTV login? Is my Twitter compromised?

No, read the OP.
AdministratorTwitter: @R1CH_TL
TL+ Member
Munk-E
Profile Blog Joined July 2010
United States672 Posts
Last Edited: 2011-08-12 18:22:18
August 12 2011 18:19 GMT
#23
EDIT: Never mind, answered above.
You recognise me because of my signature!
bITt.mAN
Profile Blog Joined March 2009
Switzerland3693 Posts
August 12 2011 18:19 GMT
#24
Does that mean you could *recover* them R1CH, if you choose to accept this mission?
BW4LYF . . . . . . PM me, I LOVE PMs. . . . . . Long live "NaDa's Body" . . . . . . Fantasy | Bisu/Best | Jaedong . . . . .
Pengu
Profile Joined April 2011
England226 Posts
August 12 2011 18:19 GMT
#25
That's just pathetic does Korea not have any laws on storage of personal information ?
zeru
Profile Blog Joined September 2010
8156 Posts
August 12 2011 18:20 GMT
#26
--- Nuked ---
speedphlux
Profile Blog Joined April 2010
Bulgaria962 Posts
August 12 2011 18:20 GMT
#27
Well, the only other place that I used the same ID/PWD combo as the ones I use on GomTV are actually for RIGHT HERE, so thanks for the heads up Password is now changed and I can safely go back to playing ... HoN :D
... Humanity Is Not What I Suffer From ...
MinoMino
Profile Blog Joined April 2010
Norway1103 Posts
August 12 2011 18:20 GMT
#28
On August 13 2011 03:18 yukimochi wrote:
does changing my gomtv password right now makes me safe or.. do i have to change everything?

If you use the same password for other stuff, then you're not safe. Especially if your e-mail account tied to GOMTV has the same password.
Blah.
ZidaneTribal
Profile Joined September 2007
United States2800 Posts
August 12 2011 18:20 GMT
#29
when u say compromised do u mean stolen? and who would hack gomtv.net, some bw activists?
fuck lag
Blasterion
Profile Blog Joined October 2010
China10272 Posts
August 12 2011 18:20 GMT
#30
I didn't expect a day that I would tank Facebook
[TLNY]Mahjong Club Thread
Domination
Profile Joined December 2010
United States1177 Posts
August 12 2011 18:21 GMT
#31
On August 13 2011 03:20 MinoMino wrote:
Show nested quote +
On August 13 2011 03:18 yukimochi wrote:
does changing my gomtv password right now makes me safe or.. do i have to change everything?

If you use the same password for other stuff, then you're not safe. Especially if your e-mail account tied to GOMTV has the same password.

Which is why I have one email/password for stupid bullshit like this and another one for important stuff.
Engore
Profile Blog Joined February 2011
United States1916 Posts
August 12 2011 18:21 GMT
#32
Well hopefully they will learn from this and take some more precautions. R1CH time to contract your wizardry out, ever wanted to go to Korea xD?

I used facebook yay.

Good luck to anyone who has to fix their account or got hacked i'm sorries for you.
EG | Liquid | Dignitas | FXO | SlayerS | TSL | iS | Fan of pretty much all players ^_^ | SeleCT <3 forever! Axslav <3
Redmark
Profile Joined March 2010
Canada2129 Posts
Last Edited: 2011-08-12 18:22:38
August 12 2011 18:22 GMT
#33
On August 13 2011 03:21 Domination wrote:
Show nested quote +
On August 13 2011 03:20 MinoMino wrote:
On August 13 2011 03:18 yukimochi wrote:
does changing my gomtv password right now makes me safe or.. do i have to change everything?

If you use the same password for other stuff, then you're not safe. Especially if your e-mail account tied to GOMTV has the same password.

Which is why I have one email/password for stupid bullshit like this and another one for important stuff.

I do the same, one system for entertainment stuff and one for things tied to real life.

Though I guess I should start just having different passwords for everything period. Quite a hassle.
Blasterion
Profile Blog Joined October 2010
China10272 Posts
August 12 2011 18:22 GMT
#34
On August 13 2011 03:20 ZidaneTribal wrote:
when u say compromised do u mean stolen? and who would hack gomtv.net, some bw activists?

Probably KeSPA lol....They didn't like SC2 being around
[TLNY]Mahjong Club Thread
fusefuse
Profile Blog Joined February 2011
Estonia4644 Posts
August 12 2011 18:22 GMT
#35
go go SNS
shame though
just another hard knock to get over though, nothing unsurmountable
GOMTV hwaiting
Liquipedia@jkursk
HTODethklok
Profile Joined November 2010
United States221 Posts
August 12 2011 18:22 GMT
#36
Are you serious? When your dealing with as many customers as Gom has how can you not do your pat to protect your customers information? Gom not only needs to step up their security but also give something back to its customers for their errors.(free season tickets?) I will no longer be buying GSL season tickets until GOM fixes its security issues. Now if youll excuse me I have to go change all of my passwords.
Guns for show... Knives for a pro HTODethklok.201 NA
Calasmere
Profile Joined September 2010
United Kingdom161 Posts
Last Edited: 2011-08-12 18:23:01
August 12 2011 18:22 GMT
#37
On August 13 2011 03:20 ZidaneTribal wrote:
when u say compromised do u mean stolen? and who would hack gomtv.net, some bw activists?

OP of the Reddit post here, I was in the original /v/ thread, which is where it came from. In it, there was no hostility, it was more showing off the numbers in the picture, which show how many people buy GOMtv tickets. He was saying 'esports is not dead', I doubt he was trying to cause any harm, because the picture with the compromised passwords/usernames is in the background, and isn't the focus.

Regardless, it still poses a threat.
MangoTango
Profile Blog Joined June 2010
United States3670 Posts
August 12 2011 18:22 GMT
#38
oh, FML. What the hell, Gom.
"One fish, two fish, red fish, BLUE TANK!" - Artosis
Bleak
Profile Blog Joined September 2010
Turkey3059 Posts
August 12 2011 18:23 GMT
#39
Changed my password but not getting verification e-mail yet...hope it doesn't get fucked up.
"I am a beacon of knowledge blazing out across a black sea of ignorance. "
Maelstrom.cobhc
Profile Joined April 2010
United States126 Posts
August 12 2011 18:23 GMT
#40
Thank you so much Rich!!! I've now changed my gomtv password and my paypal password, taking no chances!!!
I don't care what you need. I only do it to please me.
zhurai
Profile Blog Joined September 2010
United States5660 Posts
Last Edited: 2011-08-12 18:23:55
August 12 2011 18:23 GMT
#41
wow....

people on the internet are serious ****tards fucking srsly...

for once I find myself using SNS/Facebook as good o_o;;, cause before (Open 2? Open 3? forgot) it was bugged a bit v.v ish... forgot, oh well~..

hope those affected by it get everything resolved ~_~
Twitter: @zhurai | Site: http://zhurai.com
LovE-
Profile Blog Joined September 2010
United States1963 Posts
August 12 2011 18:23 GMT
#42
Wow WTF!!

I changed my password, but still. This is ridiculous
LovE.311 (NA) || @LovE_Sc2
Telcontar
Profile Joined May 2010
United Kingdom16710 Posts
August 12 2011 18:24 GMT
#43
GOM..... wtf man. Please do your jobs.
Et Eärello Endorenna utúlien. Sinome maruvan ar Hildinyar tenn' Ambar-metta.
EtohEtoh
Profile Joined May 2011
Canada669 Posts
August 12 2011 18:24 GMT
#44
I'm getting really pissed at companies storing passwords in text.

come the fuck on
R1CH
Profile Blog Joined May 2007
Netherlands10341 Posts
August 12 2011 18:24 GMT
#45
Someone just pointed out that the exploit through which this information was gained may still exist, so you may want to hold off changing passwords until GomTV confirm it is safe.
AdministratorTwitter: @R1CH_TL
TL+ Member
jester-
Profile Blog Joined February 2011
Canada547 Posts
August 12 2011 18:24 GMT
#46
Great.................................................................................
Arise, chicken sandwich.
Brotatolol
Profile Blog Joined November 2010
United States1742 Posts
Last Edited: 2011-08-12 18:25:45
August 12 2011 18:25 GMT
#47
Thanks for the warning, r1ch. Just finished changing my password.

Edit: Lol maybe I shouldn't have yet
Calasmere
Profile Joined September 2010
United Kingdom161 Posts
August 12 2011 18:25 GMT
#48
On August 13 2011 03:24 R1CH wrote:
Someone just pointed out that the exploit through which this information was gained may still exist, so you may want to hold off changing passwords until GomTV confirm it is safe.

I really doubt it will have been fixed. But regardless, changing passwords will not harm anyone, and it will only make it safer, although not a much at all.
chesshaha
Profile Joined March 2010
United States1117 Posts
August 12 2011 18:25 GMT
#49
OMG! I'm telling my friend to take actions asap.

Hopefully no one suffers a huge lost...
"Hopefully you're not the real TLO so it's not casted" - SpecialK
ArnaudF
Profile Blog Joined September 2010
France993 Posts
August 12 2011 18:26 GMT
#50
On August 13 2011 03:24 R1CH wrote:
Someone just pointed out that the exploit through which this information was gained may still exist, so you may want to hold off changing passwords until GomTV confirm it is safe.


And I read this just after I changed my password xd
My heart aches with pain, When I see you I vomit, Die away from me
Snuggles
Profile Blog Joined May 2010
United States1865 Posts
Last Edited: 2011-08-12 18:29:27
August 12 2011 18:27 GMT
#51
Fuck I'm so stupid... changing passwords immediately.

EDIT: Or maybe I should finish reading the thread first.... well I just need to keep my paypal account safe.
Telcontar
Profile Joined May 2010
United Kingdom16710 Posts
August 12 2011 18:27 GMT
#52
On August 13 2011 03:26 ArnaudF wrote:
Show nested quote +
On August 13 2011 03:24 R1CH wrote:
Someone just pointed out that the exploit through which this information was gained may still exist, so you may want to hold off changing passwords until GomTV confirm it is safe.


And I read this just after I changed my password xd

Same..... :D
Et Eärello Endorenna utúlien. Sinome maruvan ar Hildinyar tenn' Ambar-metta.
EtohEtoh
Profile Joined May 2011
Canada669 Posts
August 12 2011 18:28 GMT
#53
On August 13 2011 03:26 ArnaudF wrote:
Show nested quote +
On August 13 2011 03:24 R1CH wrote:
Someone just pointed out that the exploit through which this information was gained may still exist, so you may want to hold off changing passwords until GomTV confirm it is safe.


And I read this just after I changed my password xd

same lol
Sermokala
Profile Blog Joined November 2010
United States14047 Posts
August 12 2011 18:28 GMT
#54
How is my teamliquid information stored?
A wise man will say that he knows nothing. We're gona party like its 2752 Hail Dark Brandon
nicknt
Profile Joined October 2010
185 Posts
August 12 2011 18:28 GMT
#55
yup this happened to me when i bought the pass for the GSL super tournament. A couple of days later my email was compromised as I stupidly used the same password so had to change it.
RenardDesMers
Profile Joined April 2011
France76 Posts
August 12 2011 18:28 GMT
#56
By the way, as a website developer, I can tell you storing passwords in plain text is much more common than most people think, even for large websites.

Basically, if you do the "forgot my password" procedure and get sent the original password, most of the time it means it's in plain text in the database.

There should be laws against that. I don't understand it's still possible to do such things (on large sites).
Anyway, with that in mind, always pick different passwords for important stuff or better, never use the same password twice.
zeru
Profile Blog Joined September 2010
8156 Posts
August 12 2011 18:29 GMT
#57
--- Nuked ---
XaCez
Profile Joined May 2010
Sweden6991 Posts
August 12 2011 18:29 GMT
#58
Thank God I signed in with Twitter, this sucks big time.
People get too easily offended by people getting too easily offended by the word rape.
Seranetho
Profile Joined July 2010
France91 Posts
August 12 2011 18:29 GMT
#59
O RLY GOM
What a shame not to crypt the password, every programmer knows that you have to crypt them ...
Now I have to change a good third of my passwords, yay
Ever tried. Ever failed. No matter. Try again. Fail again. Fail better.
FlyingDJ
Profile Joined April 2008
Germany153 Posts
August 12 2011 18:30 GMT
#60
Amazing that after all the Lulzsec and Anonymous breaches recently, websites still store private information without at least hashing it.
Tennet
Profile Joined January 2010
United States1458 Posts
August 12 2011 18:30 GMT
#61
good thing i used a completely different pass for gom..though originally it was my usual pass.. which i know is stupid..
"The harder it gets, the more you need to focus on the basics." - Seo Gyung Jong
T0fuuu
Profile Blog Joined May 2009
Australia2275 Posts
August 12 2011 18:30 GMT
#62
Well I guess i should be happy i have a facebook account lol.
Odoakar
Profile Joined May 2010
Croatia1837 Posts
August 12 2011 18:30 GMT
#63
Goddamit, I'm running out of passwords:|

First Kotaku. Then NWN/KOTOR forums. Then PSN. Then GOMtv.
HTODethklok
Profile Joined November 2010
United States221 Posts
August 12 2011 18:30 GMT
#64
I just changed all my other passwords but left my Gom password the same. I wont be editing that one until the issue is resolved
Guns for show... Knives for a pro HTODethklok.201 NA
chipmonklord17
Profile Joined February 2011
United States11944 Posts
August 12 2011 18:31 GMT
#65
Well I'm just worried as my email was my first/last name at gmail.... Although it ended up being an email I only have tied to my gom account so I'm not all that concerned about being hacked, although I'll change all my passwords anyway
ArnaudF
Profile Blog Joined September 2010
France993 Posts
August 12 2011 18:31 GMT
#66
Well, I got 200 € stolen from my paypal account a few days ago, it was the same email adress as gomtv, I think I now know what was going on.
My heart aches with pain, When I see you I vomit, Die away from me
carloselcoco
Profile Blog Joined December 2010
United States2302 Posts
August 12 2011 18:32 GMT
#67
I was about to ask if I was at risk, but then I saw that those of us who logged in through FB are not. TY for the warning and I am really disappointed at GOM for keeping the passwords so unprotected...
http://www.twitch.tv/carloselcoco/b/296431601 <------Suscribe! Casts in Spanish :) |||| http://www.twitch.tv/carloselcoco/b/300285215<----- CSL: Before Sunday! Episode 3!
ZidaneTribal
Profile Joined September 2007
United States2800 Posts
August 12 2011 18:32 GMT
#68
On August 13 2011 03:30 HTODethklok wrote:
I just changed all my other passwords but left my Gom password the same. I wont be editing that one until the issue is resolved


lol that must have took a lot of work. how do u change all ur passwords so quickly
fuck lag
Zzoram
Profile Joined February 2008
Canada7115 Posts
August 12 2011 18:33 GMT
#69
Sony also stored passwords in unencrypted text, apparently it's common among all companies to do that.

Really scary.
flyersa
Profile Joined September 2010
Germany141 Posts
August 12 2011 18:34 GMT
#70
what the hell...
CEO of reGame.tv and co-founder of Berlin eSports e.V.
xBillehx
Profile Blog Joined June 2009
United States1289 Posts
Last Edited: 2011-08-12 18:37:55
August 12 2011 18:34 GMT
#71
Meh, don't use the same password for anything anyway so I'm cool. I'm sure GOM will fix it ASAP, TY for the warning R1CH. (Honestly you'd think with all this kind of shit going on by 2011 people wouldn't use the same pw. )

Edit: With that said the numbers look pretty sweet. Props to the e-Sports community for managing over $2.5m this past year.
Taengoo ♥
Hellspawnl
Profile Joined June 2010
Sweden103 Posts
August 12 2011 18:34 GMT
#72
Thanks for the Warning, will pass it on. I was so stupid that I reset so don't know the PW I had but I use unique for everything important ^^
@Hellspawnlord - hellspawn@rakaka.se - Editor of Rakaka.se - Head Admin of Dreamhack Starcraft 2
Chocolate
Profile Blog Joined December 2010
United States2350 Posts
Last Edited: 2011-08-12 18:36:41
August 12 2011 18:35 GMT
#73
Look on the bright side, GOM might feel obliged to give us free vods or hq.
Crying
Profile Joined February 2011
Bulgaria778 Posts
August 12 2011 18:35 GMT
#74
ROFL another clueless tech support ..to keep passwords in plain text is like having your door key behind the flowers .. TT
Determination~ Hard Work Surpass NATURAL GENIUS!
NemesysTV
Profile Blog Joined October 2010
United States1088 Posts
August 12 2011 18:36 GMT
#75
Wow... at least i used twitter so im a little bit safer
giuocob
Profile Joined July 2010
United States149 Posts
August 12 2011 18:37 GMT
#76
Yeah, this is totally unacceptable if it is true. Storing passwords in plain text? I learned about hash tables in fucking high school. Gom definitely owes us an explanation.
Jank
Profile Blog Joined March 2008
United States308 Posts
Last Edited: 2011-08-12 18:39:50
August 12 2011 18:37 GMT
#77
Not surprising. Korean websites seem to be notoriously poorly coded (sc2bw anyone?). I remember not too long ago gomtv didn't even filter anything in comments and were like here, use XSS lol. Out of curiosity do you know the nature of the exploit? Was it something trivial like SQL injection?

EDIT: Thanks as always for the info r1ch.
"You don't know you're wearing a leash if you sit by the peg all day." - Michael Parenti
Schmieds
Profile Blog Joined August 2010
United States312 Posts
August 12 2011 18:38 GMT
#78
Well fuck.
8
wishbones
Profile Blog Joined April 2009
Canada2600 Posts
August 12 2011 18:39 GMT
#79
i think someone with skills got pissed that koreans withdrew, too bad that prick didnt know the full story, or he might not have done this. EFFING a-hole hackers!
joined TL.net in 2006 (aka GMer) - http://www.teamliquid.net/forum/viewmessage.php?topic_id=41944#2
Xinder
Profile Blog Joined January 2011
United States2269 Posts
August 12 2011 18:39 GMT
#80
I'm glad i read TL on a daily basis. Password has been reset. Thanks.
"Daaayyyy9, King Pussyfoot of NinnyVille"- Day9 while playing Amnesia
Bleak
Profile Blog Joined September 2010
Turkey3059 Posts
August 12 2011 18:39 GMT
#81
Verification e-mail still hasn't arrived..why??
"I am a beacon of knowledge blazing out across a black sea of ignorance. "
Chaosvuistje
Profile Joined April 2010
Netherlands2581 Posts
August 12 2011 18:41 GMT
#82
God damnit, plain text?

Come on... why does EVERY website out there seem to be made by a complete security noob! This is first grade database protection people =.= . Sigh...
Crying
Profile Joined February 2011
Bulgaria778 Posts
August 12 2011 18:41 GMT
#83
I don't know even if we reset password will we be fine
I already resetted password and got new but there is one but

If GOMTV got SQL'd and database was exported than its pretty fucked up..alot of accounts will be compromised if GOM doesnt fill the gap right now..
Determination~ Hard Work Surpass NATURAL GENIUS!
nicknt
Profile Joined October 2010
185 Posts
August 12 2011 18:42 GMT
#84
the ppl in charge of security are the ones who couldnt cut it as hackers .
Karakaxe
Profile Joined August 2010
Sweden585 Posts
August 12 2011 18:42 GMT
#85
WTF? This is not cool at all.
Sword of Omens, give me sight beyond sight.
Grettin
Profile Joined April 2010
42381 Posts
August 12 2011 18:42 GMT
#86
Glad i had different email for my logging info. Thanks for the info R1CH.
"If I had force-fields in Brood War, I'd never lose." -Bisu
zeru
Profile Blog Joined September 2010
8156 Posts
August 12 2011 18:43 GMT
#87
--- Nuked ---
StimiLant
Profile Blog Joined July 2006
United States534 Posts
August 12 2011 18:43 GMT
#88
thanks R1ch <3 always u are the best
Jank
Profile Blog Joined March 2008
United States308 Posts
August 12 2011 18:43 GMT
#89
On August 13 2011 03:41 Chaosvuistje wrote:
God damnit, plain text?

Come on... why does EVERY website out there seem to be made by a complete security noob! This is first grade database protection people =.= . Sigh...

It's really not surprising. I'm working on my computer science bachelors right now and security is barely ever touched upon. A class that covers databases never even bothered telling students to use prepared statements. I know several of my classmates turned in projects that were completely vulnerable to SQL injection. I doubt half of my classmates know what salting a hash means rofl.
"You don't know you're wearing a leash if you sit by the peg all day." - Michael Parenti
Crying
Profile Joined February 2011
Bulgaria778 Posts
August 12 2011 18:45 GMT
#90
On August 13 2011 03:43 Jank wrote:
Show nested quote +
On August 13 2011 03:41 Chaosvuistje wrote:
God damnit, plain text?

Come on... why does EVERY website out there seem to be made by a complete security noob! This is first grade database protection people =.= . Sigh...

It's really not surprising. I'm working on my computer science bachelors right now and security is barely ever touched upon. A class that covers databases never even bothered telling students to use prepared statements. I know several of my classmates turned in projects that were completely vulnerable to SQL injection. I doubt half of my classmates know what salting a hash means rofl.


O god ,that seems like bad teachers??Salting isnt the only security proof method used.

SHA-1 256/512 even an MD5 can take months to crack.
And MD5 salted the salt can be isolated ,and thus negated.
Determination~ Hard Work Surpass NATURAL GENIUS!
Phenny
Profile Joined October 2010
Australia1435 Posts
August 12 2011 18:45 GMT
#91
God damnit I like to use the same few pwords for everything because there's too many different sites to keep track of any more, then shit like this happens and I run out
ClysmiC
Profile Blog Joined December 2010
United States2192 Posts
August 12 2011 18:46 GMT
#92
Thanks for the post R1CH. Nice to here reliable info from someone who knows what they're talking about.
Shield
Profile Blog Joined August 2009
Bulgaria4824 Posts
August 12 2011 18:46 GMT
#93
This is so bad, especially not crypting passwords.
Chaosvuistje
Profile Joined April 2010
Netherlands2581 Posts
August 12 2011 18:46 GMT
#94
On August 13 2011 03:43 Jank wrote:
Show nested quote +
On August 13 2011 03:41 Chaosvuistje wrote:
God damnit, plain text?

Come on... why does EVERY website out there seem to be made by a complete security noob! This is first grade database protection people =.= . Sigh...

It's really not surprising. I'm working on my computer science bachelors right now and security is barely ever touched upon. A class that covers databases never even bothered telling students to use prepared statements. I know several of my classmates turned in projects that were completely vulnerable to SQL injection. I doubt half of my classmates know what salting a hash means rofl.


Which is why I have a big hatred towards IT people. Too many times have I encountered someone with a degree that has absolutely no knowledge of SQL injections or hashes. Too many a times have I been lied to that everything is optimized for speed and all that jazz when all they are doing is tying strings together until the thing starts falling apart.

It' s depressing to be someone in the designing industry to have more knowledge of security than some of the people that are actually supposed to know that sort of thing...
JohnnyYen
Profile Joined September 2010
United States313 Posts
August 12 2011 18:46 GMT
#95
I have more than one password, but I do share passes for multiple websites like a dumbo. TY Rich, really glad I check TL at work ~_~

Saved me from worrying about PSN info getting lost, and not my standard password is going to be changed. Thank you thank you thank you.
FairForever
Profile Joined February 2011
Canada2392 Posts
August 12 2011 18:47 GMT
#96
On August 13 2011 03:43 zeru wrote:
Show nested quote +
On August 13 2011 03:41 Crying wrote:
I don't know even if we reset password will we be fine
I already resetted password and got new but there is one but

If GOMTV got SQL'd and database was exported than its pretty fucked up..alot of accounts will be compromised if GOM doesnt fill the gap right now..

I doubt they are trying anything else than just getting paypal accounts from it by using the same email and pw's to log in, on top of that the emails themselves too. Dont think they care enough about the actual GOM accounts.


Maybe they really really just wanted to watch the HQ GSL and GSTL streams =P

This sucks though............
Jojo131
Profile Joined January 2011
Brazil1631 Posts
Last Edited: 2011-08-12 18:49:35
August 12 2011 18:48 GMT
#97
Thank you for the notice R1CH, will do.
Also really glad I have different passwords for GOMtv and my actual e-mail.
Still, worth making sure that nothing happened.
Termit
Profile Joined December 2010
Sweden3466 Posts
August 12 2011 18:48 GMT
#98
fucking shit...........
( ̄。 ̄)~zzz ◕ ◡ ◕
rasnj
Profile Joined May 2010
United States1959 Posts
August 12 2011 18:48 GMT
#99
On August 13 2011 03:41 Crying wrote:
I don't know even if we reset password will we be fine
I already resetted password and got new but there is one but

If GOMTV got SQL'd and database was exported than its pretty fucked up..alot of accounts will be compromised if GOM doesnt fill the gap right now..

Every account is already compromised. As you say someone may have exported their whole user database and no matter how quick GOM acts they can't do much about that. If anyone did use their gomtv password for anything else important they need to change the password to those other things, and in particular if their email account has the same password. Changing your gom password will not necessarily do anything as someone may have your old password on file, and someone said the exploit still works.

Storing passwords in plaintext is obviously stupid, but given how badly designed many sites are people experienced with the Internet should have learned rudimentary protective measures (ideally unique passwords via an app like KeePass, but at least unique password for mail and financial management).

On August 13 2011 03:45 Phenny wrote:
God damnit I like to use the same few pwords for everything because there's too many different sites to keep track of any more, then shit like this happens and I run out

As R1CH recommended try using an application like KeePass. You remember one master password that you DO NOT use for anything else, then have it generate complicated unique passwords for all sites. Personally I also regularly write down a hard copy of my passwords in case of HD failure.
HTODethklok
Profile Joined November 2010
United States221 Posts
August 12 2011 18:50 GMT
#100
On August 13 2011 03:32 ZidaneTribal wrote:
Show nested quote +
On August 13 2011 03:30 HTODethklok wrote:
I just changed all my other passwords but left my Gom password the same. I wont be editing that one until the issue is resolved


lol that must have took a lot of work. how do u change all ur passwords so quickly


Opened up all accounts that use the same password as My gom account in different tabs in my browser then go through and change the passwords one at a time. Plus using CTRL+F to find the word Password on each web page helps find the change your password selection.
Guns for show... Knives for a pro HTODethklok.201 NA
Sicky
Profile Joined August 2010
United Kingdom121 Posts
August 12 2011 18:50 GMT
#101
Thanks Calasmere.
sTsCompleted
Profile Blog Joined May 2010
United States380 Posts
August 12 2011 18:50 GMT
#102
I changed my password, I hope my old password still isn't on there
stormchaser
Profile Joined January 2011
Canada1009 Posts
August 12 2011 18:51 GMT
#103
Thats ridiculous
RedJustice
Profile Blog Joined February 2011
United States1004 Posts
August 12 2011 18:51 GMT
#104
Glad I use one particular password and email address for all the sites and stuff I don't care about...

Guess I'm not really surprised this happened, but still kind of surprised companies don't take the time and care to do some basic security on this kind of thing. GL to all the people seriously compromised. :/
PoopLord
Profile Joined May 2010
537 Posts
August 12 2011 18:52 GMT
#105
I'm safe, but I'm concerned because I use the same password for other sites for online shopping ;___;
Hurricane Sponge
Profile Joined March 2010
868 Posts
August 12 2011 18:52 GMT
#106
This crap is exactly why I prefer finding the 'illegal' user re-streams of the GOM events instead of downloading their precious little player. Ridiculous that TL bans people for posting streams of the events when GOM has zero countermeasures to protect account information in place.
Beardedclam
Profile Joined September 2010
United States839 Posts
August 12 2011 18:52 GMT
#107
I used a password that I use a lot on an account there that I never verified the email address.Would it still show up on whatever logs they got?
"bye bye" - genius "#$@% you" - Idra------------|Genius|DRG|Keen|---------Breakfast.213
Crying
Profile Joined February 2011
Bulgaria778 Posts
August 12 2011 18:53 GMT
#108
They btw will need alot of time to get all the passwords and usernames...
For instance an 700usr/passwords is around 1hour to get and keep
Btw ,what was the exploit used,is it a SQL string based,time based??
Or just a perl exploit?
Determination~ Hard Work Surpass NATURAL GENIUS!
skipgamer
Profile Blog Joined April 2010
Australia701 Posts
August 12 2011 18:54 GMT
#109
Thumbs up for the KeePass link in the OP, it truly is a wonderful program.

And who would have thought my laziness in logging in via facebook would be so handy :D
Captain Peabody
Profile Blog Joined May 2009
United States3126 Posts
August 12 2011 18:55 GMT
#110
Well, I only use that password for facebook, soooo...

I don't think it's a big deal. About all they can do is hack my facebook, but I can't see that being worth anyone's time or money just to troll my friends.
Dies Irae venit. youtube.com/SnobbinsFilms
thee telescopes
Profile Joined August 2010
321 Posts
August 12 2011 18:55 GMT
#111
Do we know the problem has actually been fixed?
Deleted User 124618
Profile Joined November 2010
1142 Posts
August 12 2011 18:55 GMT
#112
THANK YOU for posting about this. I didn't lose any of my accounts
Mordiford
Profile Joined April 2011
4448 Posts
August 12 2011 18:55 GMT
#113
R1CH, I have a tremendous amount of respect for you.
Just thought you should know.

Oh yeah... And thanks for letting us know.
Siphyo
Profile Joined April 2011
Netherlands121 Posts
August 12 2011 18:55 GMT
#114
On August 13 2011 03:14 R1CH wrote:There appears to be zero security(really GOM?).


Changed my GOM account email recently. The confirmation mail was sent to the new address. Yeah..
HSY - KMK - Hyomin - Yoona - Sojin | NesTea - DRG - Puzzle - Bomber - NANIWA
zeru
Profile Blog Joined September 2010
8156 Posts
August 12 2011 18:55 GMT
#115
--- Nuked ---
Starfox
Profile Joined April 2010
Austria699 Posts
August 12 2011 18:56 GMT
#116
Hilarious, hey GOM, the 90s called, they want their safety measures back.
Greek Mythology 2.0: Imagine Sisyphos as a man who wants to watch all videos on youtube... and Tityos as one who HAS to watch all of them.
JinDesu
Profile Blog Joined August 2010
United States3990 Posts
August 12 2011 18:56 GMT
#117
On August 13 2011 03:52 Hurricane Sponge wrote:
This crap is exactly why I prefer finding the 'illegal' user re-streams of the GOM events instead of downloading their precious little player. Ridiculous that TL bans people for posting streams of the events when GOM has zero countermeasures to protect account information in place.


Of course. You knew that GOM had zero countermeasures in place before this so that is exactly why you watch illegal restreams. Brilliant argument here.
Yargh
scatmango2
Profile Joined November 2010
United States408 Posts
August 12 2011 18:56 GMT
#118
I got just one question. Why is R1CH such a motherfucking boss?
adbrl
Profile Joined July 2011
Germany7 Posts
August 12 2011 18:56 GMT
#119
Anyone knows when exactly GomTV was hacked, since i changed my PW yesterday to something i never used before, so hopefully it was after this.

I can't believe after everything happening at the moment regarding hacking etc. companies still store passwords in plain text...this should really be illegal by now!
crms
Profile Joined February 2010
United States11933 Posts
August 12 2011 18:57 GMT
#120
thankfully I use facebook. jeez. get your act together gom! text files?!?
http://i.imgur.com/fAUOr2c.png | Fighting games are great
Pumplekin
Profile Blog Joined April 2011
United Kingdom50 Posts
August 12 2011 18:58 GMT
#121
PLAIN TEXT. Oh man. A bunch of hashes to feed to some rainbow tables is bad enough, but seriously plaintext ?!?!?!?

I guess it is time to change my "I don't really care about it password" on a bunch of sites then, and leave it the same on GOM until I'm happy they have cleaned up whatever bug they had that exposed the information, and if someone wants to freeload of my account in the meantime, well, GOM kinda deserve it.
Loves Cows
werynais
Profile Joined October 2010
Germany1780 Posts
Last Edited: 2011-08-12 18:59:30
August 12 2011 18:58 GMT
#122
On August 13 2011 03:52 Hurricane Sponge wrote:
This crap is exactly why I prefer finding the 'illegal' user re-streams of the GOM events instead of downloading their precious little player. Ridiculous that TL bans people for posting streams of the events when GOM has zero countermeasures to protect account information in place.


If you have problems with your brain please see your doctor!
RenardDesMers
Profile Joined April 2011
France76 Posts
August 12 2011 18:58 GMT
#123
Strange GOMTV didn't provide information to its users.
The exploit might be still active, that could be why they don't want to communicate about it
If it's not, every minute they wait is a minute a hacker can use to access a website with the password he retrieved.
Nerski
Profile Blog Joined November 2010
United States1095 Posts
August 12 2011 18:58 GMT
#124
this is pretty silly that gom was storing the passwords in unencrypted methods. You would think a company that runs TV stations would have better security on a website taking money then that.
Twitter: @GoForNerski /// Youtube: Youtube.com/nerskisc
Wipples
Profile Joined November 2010
Canada269 Posts
August 12 2011 18:58 GMT
#125
I have a GOM account but I could never remember the password so i always signed in with twitter So I should be safe, but just in case ima change the password anyway.
rasnj
Profile Joined May 2010
United States1959 Posts
August 12 2011 18:59 GMT
#126
On August 13 2011 03:56 adbrl wrote:
Anyone knows when exactly GomTV was hacked, since i changed my PW yesterday to something i never used before, so hopefully it was after this.

I can't believe after everything happening at the moment regarding hacking etc. companies still store passwords in plain text...this should really be illegal by now!

I doubt it's possible to confirm when this first happened. Even if the ones who publicized this did it recently others may have downloaded the whole db months ago and just be waiting for a buyer (to spam mails for instance which is likely the most real risk).
LegionUK
Profile Joined May 2011
United Kingdom11 Posts
August 12 2011 19:00 GMT
#127
I've never trusted things like Keep Pass, would people actually recommend it?
Redmark
Profile Joined March 2010
Canada2129 Posts
August 12 2011 19:02 GMT
#128
On August 13 2011 04:00 LegionUK wrote:
I've never trusted things like Keep Pass, would people actually recommend it?

Rich recommended it before.
Baarn
Profile Joined April 2010
United States2702 Posts
Last Edited: 2011-08-12 19:05:22
August 12 2011 19:02 GMT
#129
Mr. Chae if you are following this thread use hash from now on. It's easy to setup and you would avert any future embarrassment. This also applies to any budding website developers.
There's no S in KT. :P
wei2coolman
Profile Joined November 2010
United States60033 Posts
August 12 2011 19:03 GMT
#130
Did no one learn from Sony's mistake?!!!!?!?!?!?!?!?!?!
liftlift > tsm
LegionUK
Profile Joined May 2011
United Kingdom11 Posts
August 12 2011 19:03 GMT
#131
On August 13 2011 04:02 Redmark wrote:
Show nested quote +
On August 13 2011 04:00 LegionUK wrote:
I've never trusted things like Keep Pass, would people actually recommend it?

Rich recommended it before.


Yeah I saw that, just wondered if anyone else has any experience using it though.
Fionn
Profile Blog Joined October 2009
United States23455 Posts
August 12 2011 19:03 GMT
#132
Luckily that I just use 10minute email and random numbers for whenever I use GOM or any site that requires information.
Writerhttps://twitter.com/FionnOnFire
Hurricane Sponge
Profile Joined March 2010
868 Posts
August 12 2011 19:03 GMT
#133
On August 13 2011 03:56 JinDesu wrote:
Show nested quote +
On August 13 2011 03:52 Hurricane Sponge wrote:
This crap is exactly why I prefer finding the 'illegal' user re-streams of the GOM events instead of downloading their precious little player. Ridiculous that TL bans people for posting streams of the events when GOM has zero countermeasures to protect account information in place.


Of course. You knew that GOM had zero countermeasures in place before this so that is exactly why you watch illegal restreams. Brilliant argument here.


I had my suspicions, and it looks like I was right. Just because I'm paranoid doesn't mean they're NOT all out to get me.
mav451
Profile Joined May 2010
United States1596 Posts
August 12 2011 19:04 GMT
#134
I believe the term is "losing face". Translate to language of choice
With no power comes no responsibility?
ChowChillaCharlie
Profile Joined April 2010
Sweden677 Posts
August 12 2011 19:04 GMT
#135
I can't remember my password nor what i used as a nick, so now i can't even get a mail sent to me with my information...
Infinity Gaming
Profile Joined February 2011
United States44 Posts
August 12 2011 19:05 GMT
#136
I just sent out about 3000 emails to anyone registered on the Infinity Sites to help spread the word.
Head of Infinity Gaming --- http://infgaming.net
Assirra
Profile Joined August 2010
Belgium4169 Posts
Last Edited: 2011-08-12 19:06:16
August 12 2011 19:05 GMT
#137
On August 13 2011 03:43 Jank wrote:
Show nested quote +
On August 13 2011 03:41 Chaosvuistje wrote:
God damnit, plain text?

Come on... why does EVERY website out there seem to be made by a complete security noob! This is first grade database protection people =.= . Sigh...

It's really not surprising. I'm working on my computer science bachelors right now and security is barely ever touched upon. A class that covers databases never even bothered telling students to use prepared statements. I know several of my classmates turned in projects that were completely vulnerable to SQL injection. I doubt half of my classmates know what salting a hash means rofl.

Seriously? i followed a course CCNA (network) and i don't know how much security got drilled into our heads. It went to the point where at least 1/4th of the whole thing was about all possible security methods.
FliedLice
Profile Blog Joined April 2010
Germany7494 Posts
August 12 2011 19:05 GMT
#138
Good thing I started using KeyPass just earlier this week because I had like 25 failed login attempts on my e-mail account...
Kevmeister @ Dota2
Kamikiri
Profile Joined October 2010
United States1319 Posts
August 12 2011 19:07 GMT
#139
Well this is lovely, taught me a lesson I used the same email and password i used to sign in with gomtv as my msn email which got hacked today, could just be coincidence but meh.
Jank
Profile Blog Joined March 2008
United States308 Posts
Last Edited: 2011-08-12 19:09:54
August 12 2011 19:09 GMT
#140
On August 13 2011 04:05 Assirra wrote:
Show nested quote +
On August 13 2011 03:43 Jank wrote:
On August 13 2011 03:41 Chaosvuistje wrote:
God damnit, plain text?

Come on... why does EVERY website out there seem to be made by a complete security noob! This is first grade database protection people =.= . Sigh...

It's really not surprising. I'm working on my computer science bachelors right now and security is barely ever touched upon. A class that covers databases never even bothered telling students to use prepared statements. I know several of my classmates turned in projects that were completely vulnerable to SQL injection. I doubt half of my classmates know what salting a hash means rofl.

Seriously? i followed a course CCNA (network) and i don't know how much security got drilled into our heads. It went to the point where at least 1/4th of the whole thing was about all possible security methods.

Well a course for a cisco cert is a lot more likely to focus on security. Computer science is more theory and math and less practical shit. The problem is the majority of students graduating with a cs degree will go into software development where they will plague the world with their incompetence.
"You don't know you're wearing a leash if you sit by the peg all day." - Michael Parenti
Raidern
Profile Joined February 2005
Brazil3811 Posts
August 12 2011 19:12 GMT
#141
in any case I changed passwords from twitter and paypal -_-
For the Swarm!
Khanz
Profile Joined April 2010
France214 Posts
August 12 2011 19:12 GMT
#142
Thank you R1CH. What would I be without TL and their favorite mascotte.
Don't worry, zombies eat brains. You're safe
mmdmmd
Profile Joined June 2007
722 Posts
August 12 2011 19:13 GMT
#143
Reading the reddit thread. Only paying customers affected?
bonifaceviii
Profile Joined May 2010
Canada2890 Posts
August 12 2011 19:13 GMT
#144
On August 13 2011 03:19 lbmaian wrote:
Wow, I didn't expect to be thanking Facebook for my password safekeeping.

Seriously. Welp, I guess there's something to be said for having to disable GOM on my Facebook after every time I log in!
Stay a while and listen || http://www.teamliquid.net/forum/viewmessage.php?topic_id=354018
DeepBlu2
Profile Blog Joined April 2004
United States975 Posts
August 12 2011 19:14 GMT
#145
Shouldn't b e a problem as I use different passwords. I'm dissapointed in gom for not encrypting any of the data. That is something that should be done.
u gotta sk8
Bobster
Profile Joined January 2011
Germany3075 Posts
August 12 2011 19:16 GMT
#146
On August 13 2011 03:16 SniXSniPe wrote:
Thankfully I always logged in via Twitter =)

Same here.

Actually glad I used that feature for once.
Kaiwa
Profile Blog Joined August 2010
Netherlands2209 Posts
August 12 2011 19:16 GMT
#147
No encryption, I don't understand how corporations still fail to see how important it is.
Anyway, I use facebook login so I guess that means not in the crossfire?
시크릿 / 씨스타 / 에이핑크 / 윤하 / 가비앤제이
Glowbox
Profile Joined June 2010
Netherlands330 Posts
Last Edited: 2011-10-26 22:21:47
August 12 2011 19:16 GMT
#148
Storing in plaintext is absolutely unacceptable. I cannot even begin to explain how stupid this is by GOMtv. I'm not gonna check until I hear some official word from GOMtv but even then I'm hesitant. Time to find some restream links....
valaki
Profile Joined June 2009
Hungary2476 Posts
August 12 2011 19:17 GMT
#149
On August 13 2011 04:16 Bobster wrote:
Show nested quote +
On August 13 2011 03:16 SniXSniPe wrote:
Thankfully I always logged in via Twitter =)

Same here.

Actually glad I used that feature for once.


x2, I'm glad, at least for myself.
ggaemo fan
lostmage333
Profile Joined October 2010
United States28 Posts
August 12 2011 19:18 GMT
#150
On August 13 2011 03:45 Crying wrote:
SHA-1 256/512 even an MD5 can take months to crack.
And MD5 salted the salt can be isolated ,and thus negated.


Your 14 character long password with uppercase, lowercase, symbols, and numbers isn't anything that won't fail to a sufficiently large rainbowtable attack within minutes. Sure, salting passwords makes them no stronger versus bruteforce/dictionary attacks, but adding a 20 character salt makes it significantly stronger versus rainbowtables, unless a new set of rainbowtables is generated to target that specific salt, which takes a long, long time (but can be reused for extremely fast and efficient attacks on the whole database).

All the SHA algorithms also vulnerable to rainbowtables attacks.


It's funny how you call out people for not knowing basic cryptography, when you yourself don't know some of the most basic attack methods. I'm not claiming to be some expert, since I'm not, but I do know that you've stated some clearly incorrect statements.

That said, it's still sad that GOM stored passwords in plaintext. Just use this as an opportunity to understand the "do not resuse passwords" warning that many sites give. Hopefully it'll get resolved soon.
HydroXy
Profile Joined May 2010
United States513 Posts
August 12 2011 19:20 GMT
#151
Really, GomTV? Don't expect me to purchase anything anymore if you can't keep my information safe.
Caveman255
Profile Joined September 2010
Israel79 Posts
August 12 2011 19:21 GMT
#152
Retards...
PepperoniPiZZa
Profile Blog Joined October 2010
Sierra Leone1660 Posts
August 12 2011 19:21 GMT
#153
Is there any way for me to check wether or not my account has been compromised? I think I remember sony providing such a service after they had their data stolen?
Quote?
nalgene
Profile Joined October 2010
Canada2153 Posts
Last Edited: 2011-08-12 19:25:21
August 12 2011 19:22 GMT
#154
Not really surprised that it'd be compromised... considering you can just dl the hq vods from their site without... and they haven't made any significant changes since 8 months ago...just a token for authentication( since december 2010 or so )...and their app is poorly designed, too...
Year 2500 Greater Israel ( Bahrain, Cyprus, Egypt, Iran, Iraq, Jordan, Kuwait, Lebanon, Oman, Gaza Strip, West Bank, Qatar, Saudi Arabia, Syria, Turkey, United Arab Emirates, Yemen )
KDot2
Profile Blog Joined March 2011
United States1213 Posts
August 12 2011 19:22 GMT
#155
I use twitter and for the last week or so I keep getting emails saying my twitter was hacked....

related or coincidence ?
Aim Here
Profile Blog Joined December 2009
Scotland672 Posts
Last Edited: 2011-08-12 19:23:37
August 12 2011 19:23 GMT
#156
It would be nice if I learned about this from GOMTV first. So far, the only acknowledgement by GOM is a single post on the GOMTV forum by a worried random user.

Do they even know there's a security problem, and if so, why aren't they telling anyone?
ChowChillaCharlie
Profile Joined April 2010
Sweden677 Posts
August 12 2011 19:24 GMT
#157
Even though i can't remember my GOMtv pass im fairly certain it wasn't the same as the one i use for my hotmail, should i still change it you think?
Jedclark
Profile Blog Joined February 2011
United Kingdom903 Posts
August 12 2011 19:25 GMT
#158
I hope it is just "hacktivism" to get Gom to improve security.
"They make it so scrubnubs can PM me. They make it so I can't ignore scrubnubs!" - "I'm gonna show you how great I am." MKP fan since GSL Open Season 2 #hipsternerd
Saishuuheiki
Profile Joined November 2010
United States188 Posts
August 12 2011 19:25 GMT
#159
Not to say this is the case, but I think it's like midnight there, so a press release might be delayed a bit
sopas
Profile Joined July 2011
509 Posts
August 12 2011 19:26 GMT
#160
good thing i made a hotmal just for gomtv acc then. changed pws anyway and guess haveto change soon again if we get confirmation from gom
Crying
Profile Joined February 2011
Bulgaria778 Posts
August 12 2011 19:26 GMT
#161
On August 13 2011 04:18 lostmage333 wrote:
Show nested quote +
On August 13 2011 03:45 Crying wrote:
SHA-1 256/512 even an MD5 can take months to crack.
And MD5 salted the salt can be isolated ,and thus negated.


Your 14 character long password with uppercase, lowercase, symbols, and numbers isn't anything that won't fail to a sufficiently large rainbowtable attack within minutes. Sure, salting passwords makes them no stronger versus bruteforce/dictionary attacks, but adding a 20 character salt makes it significantly stronger versus rainbowtables, unless a new set of rainbowtables is generated to target that specific salt, which takes a long, long time (but can be reused for extremely fast and efficient attacks on the whole database).

All the SHA algorithms also vulnerable to rainbowtables attacks.


It's funny how you call out people for not knowing basic cryptography, when you yourself don't know some of the most basic attack methods. I'm not claiming to be some expert, since I'm not, but I do know that you've stated some clearly incorrect statements.

That said, it's still sad that GOM stored passwords in plaintext. Just use this as an opportunity to understand the "do not resuse passwords" warning that many sites give. Hopefully it'll get resolved soon.


Im familiar with the rainbow tables but hacked by rainbow tables means that this password u chose is already in the table...RT is also a dictionary attack if im not mistaken,and if ur password is SOCCER its gonna be cracked within seconds,but if its s0cc3rrrr8765 its not gonna get hacked by rainbow table..
Determination~ Hard Work Surpass NATURAL GENIUS!
Chise
Profile Joined December 2010
Japan507 Posts
August 12 2011 19:26 GMT
#162
Thanks for the information, I just changed my gomtv and paypal password.
xBillehx
Profile Blog Joined June 2009
United States1289 Posts
August 12 2011 19:26 GMT
#163
On August 13 2011 04:23 Aim Here wrote:
It would be nice if I learned about this from GOMTV first. So far, the only acknowledgement by GOM is a single post on the GOMTV forum by a worried random user.

Do they even know there's a security problem, and if so, why aren't they telling anyone?

It's 4am, the majority of them are probably sleeping.
Taengoo ♥
MyLastSerenade
Profile Joined February 2010
Germany710 Posts
August 12 2011 19:27 GMT
#164
Thanks R1ch

I hope they learn from it ~~
pureability
Profile Blog Joined November 2010
United States137 Posts
Last Edited: 2011-08-12 19:30:00
August 12 2011 19:28 GMT
#165
thanks for letting me know. I will be using keepass now. Looks easy enough to use.

Question though. Say you are at a friends house or something and want to look something up. Can you gain access to these pws any other way? No way I can remember 30random characters lol
Mutaahh
Profile Joined June 2007
Netherlands859 Posts
August 12 2011 19:28 GMT
#166
imo its a crime when you dont safe passwords safe enough
I want to fly
Kamikiri
Profile Joined October 2010
United States1319 Posts
August 12 2011 19:29 GMT
#167
Has gomtv said anything about this yet?
IcedBacon
Profile Joined May 2011
Canada906 Posts
August 12 2011 19:29 GMT
#168
I suppose I'm fortunate that I changed my password a few weeks ago so a friend could watch one series :>
"I went Zerg because Artosis is a douchebag." -IdrA
Shield
Profile Blog Joined August 2009
Bulgaria4824 Posts
Last Edited: 2011-08-12 19:31:21
August 12 2011 19:30 GMT
#169
This reminds me how protected you can be with facebook. Even if you tell your password to anyone, unknown devices/computers cannot login without SMS code which you get automatically from Facebook. ^^ Unless your telephone gets stolen, there's no way.
I wish all websites were like this.
Jyvblamo
Profile Blog Joined June 2006
Canada13788 Posts
August 12 2011 19:30 GMT
#170
This is ass for someone like me who uses the same password for everything. That ought to teach me...
FliedLice
Profile Blog Joined April 2010
Germany7494 Posts
August 12 2011 19:30 GMT
#171
On August 13 2011 04:03 LegionUK wrote:
Show nested quote +
On August 13 2011 04:02 Redmark wrote:
On August 13 2011 04:00 LegionUK wrote:
I've never trusted things like Keep Pass, would people actually recommend it?

Rich recommended it before.


Yeah I saw that, just wondered if anyone else has any experience using it though.



It's pretty easy to use, they have a small beginner tutorial on they page that helps you to set it up... Been using it for a week not and didn't encounter any problems. I imagine it could become a bit bothersome if you are using someone elses pc and want to do a quick check of your Facebook or something like that, since you're going to nee KeyPass and you PW data file on that pc as far as i can tell :o
Kevmeister @ Dota2
Artik
Profile Joined October 2010
United States71 Posts
August 12 2011 19:30 GMT
#172
Thank god I use a different password on my paypal :x
Liberate me ex inferis
StimMarine
Profile Joined March 2011
723 Posts
August 12 2011 19:31 GMT
#173
Thanks very much for this thread. I have now updated a number of my passwords on different websites. GOMTV should really invest in data security.
entocheets
Profile Blog Joined July 2010
Australia367 Posts
Last Edited: 2011-08-12 19:32:52
August 12 2011 19:32 GMT
#174
http://www.baekdal.com/tips/password-security-usability

Bit disappointing that passwords were being kept in plain text. There's only so much a user can do to keep their password safe..!

Changing my password on GOMTV. Cheers R1CH
##creepers 4 lyf
xlep
Profile Joined December 2009
Germany274 Posts
August 12 2011 19:32 GMT
#175
Thanks for the Info R1CH
skill is scissors beating rock
PHILtheTANK
Profile Joined March 2011
United States1834 Posts
August 12 2011 19:34 GMT
#176
Thanks for the headsup RICH u saved the day once again.
Jieun <3
Deleted User 61629
Profile Blog Joined March 2010
1664 Posts
August 12 2011 19:34 GMT
#177
--- Nuked ---
branflakes14
Profile Joined July 2010
2082 Posts
August 12 2011 19:34 GMT
#178
GOM site isn't letting me change my password. Lovely.
DrBoo
Profile Joined April 2010
Canada1177 Posts
August 12 2011 19:34 GMT
#179
On August 13 2011 04:28 pureability wrote:
thanks for letting me know. I will be using keepass now. Looks easy enough to use.

Question though. Say you are at a friends house or something and want to look something up. Can you gain access to these pws any other way? No way I can remember 30random characters lol


You can save your keepass database on a USB stick then just make sure to carry your USB around. It takes like 10 seconds to install keepass on someone elses computer if you really need to access something on their computer.
"DrBoo is an elaborate troll" -Pufftrees
Deleted User 183001
Profile Joined May 2011
2939 Posts
August 12 2011 19:35 GMT
#180
Okay, that isn't pretty. The log-in information was just there in the database with zero encryption? Oh boy, GOM, please hire someone that knows at least basic server / database security ;(.
Chenz
Profile Joined November 2010
Sweden1197 Posts
August 12 2011 19:35 GMT
#181
You guys should avoid changing your password on GOMtv until it's been confirmed that the security flaw has been fixed, unless you're changing it to an unique password.

Damn, MLG seems to be down. Can't access my profile to change my password.
FarbrorAbavna
Profile Joined July 2009
Sweden4856 Posts
August 12 2011 19:35 GMT
#182
unique passwd and usr for gomtv so that finally pays off, sucks for those who dont though
Do you really want chat rooms?
Superouman
Profile Blog Joined August 2007
France2195 Posts
August 12 2011 19:36 GMT
#183
Thanks for warning us.
Search "[SO]" on B.net to find all my maps ||| Cloud Kingdom / Turbo Cruise '84 / Bone Temple / Eternal Empire / Zen / Purity and Industry / Golden Wall / Fortitude / Beckett Industries / Waterfall
KhAmun
Profile Blog Joined September 2010
United States1005 Posts
August 12 2011 19:38 GMT
#184
Thanks for the heads up R1CH, and I'll surely be using KeePass from now on.
sOvrn
Profile Joined April 2010
United States678 Posts
August 12 2011 19:38 GMT
#185
Shit, thanks for the heads up. Changed my password and going to check out that Keepass website.
My favorites: Terran - Maru // Protoss - SoS // Zerg - soO ~~~ fighting!
Shield
Profile Blog Joined August 2009
Bulgaria4824 Posts
August 12 2011 19:38 GMT
#186
Obviously GOM should hire R1CH in order to support their servers! :D
Double Letters
Profile Joined March 2011
United States58 Posts
August 12 2011 19:38 GMT
#187
Can we talk about the whole plaintext thing for a second? It feels like me, with no actual security training, would be be better at securing half the world's websites.

How much was the Sony security guy (the one that also decided to sore passwords in plain text) getting paid? Pay me half I can do that job easily, since apparently despite having no actual education in security, I know more than him/her.

How about the guy at GOM who decided to store passwords in plaintext? How much did they pay him to make such awful security decisions?

It's frustrating that over and over again this shit happens, and companies keep using poor security regardless.
abc
Ownos
Profile Joined July 2010
United States2147 Posts
Last Edited: 2011-08-12 19:40:23
August 12 2011 19:39 GMT
#188
I'm not too worried. Oh and the passwords as plain text deal... GOD WTF... I can sort of forgive GOM cause they are small. But PSN doing that was LOL do they not have experienced men on board? Storing PW as tokens is like the most basic thing.
...deeper and deeper into the bowels of El Diablo
blahz0r
Profile Joined December 2010
3030 Posts
August 12 2011 19:39 GMT
#189
Thanks for the info! Time to change around some passwords to be safe...
Liquipedia
Crying
Profile Joined February 2011
Bulgaria778 Posts
August 12 2011 19:40 GMT
#190
It seems to me that mainly the Asian websites are having plain text stored passwords,PSN now GOMTV ,i cant recall major big corporation in USA/EUROPE that had such problems?
Determination~ Hard Work Surpass NATURAL GENIUS!
MrSexington
Profile Blog Joined July 2010
United States1768 Posts
August 12 2011 19:40 GMT
#191
Wow, that sucks.

#wtfgomtv
StimMarine
Profile Joined March 2011
723 Posts
August 12 2011 19:41 GMT
#192
On August 13 2011 04:40 MrSexington wrote:
Wow, that sucks.

#wtfgomtv


This isn't Twitter.
Mortal
Profile Blog Joined November 2010
2943 Posts
August 12 2011 19:41 GMT
#193
Pretty terrible storage by GOM. Good thing I use different pw's for everything, but still, plain text is a joke.
The universe created an audience for itself.
Juliette
Profile Blog Joined September 2010
United States6003 Posts
August 12 2011 19:41 GMT
#194
wow :|
gonna start making sure my passwords wont poop on me from now on ty for the heads up
OKAY FROM THAT PERSPECTIVE I SEE WHAT YOU'RE TALKING ABOUT
Crying
Profile Joined February 2011
Bulgaria778 Posts
August 12 2011 19:42 GMT
#195
Is there any clarification what kind of attack was used?

SQL?
Perl exploit?
?!?!?
Determination~ Hard Work Surpass NATURAL GENIUS!
ZombiesOMG
Profile Joined October 2010
United States282 Posts
August 12 2011 19:43 GMT
#196
I only use this email address for gomtv and TL, so changing the pw for those 2 plus the gmail account I think I'll be alright.

Bad move on the plaintext thing, though.
Ponyo
Profile Blog Joined January 2011
United States1231 Posts
August 12 2011 19:43 GMT
#197
darn! and gom is the only site where i used a throw away pass, mostly because I was sharing my account with buds for one season where i bought HD.
ponyo.848
Titorelli
Profile Joined March 2011
2492 Posts
August 12 2011 19:44 GMT
#198
Why is everone thanking Facebook? Did I miss something?

And its only the Gomtv.net PW no credit card infos whatsoever?
"Everybody poops.... after Tasteless kills them" Artosis
LittleAtari
Profile Joined August 2010
Jordan1090 Posts
August 12 2011 19:44 GMT
#199
Question: Right now my GOMTV password is not the same as my other passwords, however, a few months ago, it was. Should i still go and change my other passwords?
obsKura
Profile Joined March 2011
Ireland1061 Posts
August 12 2011 19:45 GMT
#200
Hi R1CH, thanks for the info.

Did you already report this to GOMtv/Mr. Chae?
C9 ~^v^~ In EE-sama we trust. ~^v^~ C9
gullberg
Profile Blog Joined February 2011
Sweden1301 Posts
August 12 2011 19:45 GMT
#201
What if I logged in via twitter/facebook. Has it been compromised?
sVnteen
Profile Joined January 2011
Germany2238 Posts
August 12 2011 19:45 GMT
#202
On August 13 2011 03:18 Keap wrote:
GOM is so unprofessional. The level of play of their players is amazing, but the business side of the Korean SC2 scene is really lacking to say the least.



that happens to the best companies

sometimes there is just bad luck
MY LIFE STARTS NOW ♥
bo0
Profile Joined April 2011
Belgium550 Posts
August 12 2011 19:47 GMT
#203
crap, my gomtv password is one I use for a lot of stuff

thankfully, nothing finance-related :D couldn't rly give a crap if my email get's hacked, my friends now I don't intentionally send spam anyways
4rChon
Profile Blog Joined December 2010
150 Posts
August 12 2011 19:48 GMT
#204
Thanks for posting this mr. R1CH! I had small bowel movements till I read about facebook/twitter users are safe...
LittLeD
Profile Joined May 2010
Sweden7973 Posts
August 12 2011 19:48 GMT
#205
On August 13 2011 04:45 gullberg wrote:
What if I logged in via twitter/facebook. Has it been compromised?

Did you read the OP?
☆Grubby ☆| Tod|DeMusliM|ThorZaiN|SaSe|Moon|Mana| ☆HerO ☆
duckTemplar
Profile Joined February 2011
United States200 Posts
August 12 2011 19:48 GMT
#206
Oh they have my email , my password and access to my paypal now, rather unfortunatly, I just paid for GSL August a few days ago.
The first word Kerrigan said to Raynor was "...You Pig!", to Raynor's response "What? ... oh you're a psychic"
AJMcSpiffy
Profile Blog Joined May 2010
United States1154 Posts
August 12 2011 19:48 GMT
#207
This sucks for GOM, but thankfully nobodies bank information is at risk. Also major thanks to R1CH for bringing this to the forum and also showing keepass, this seems great
If the quarter was in your right hand, that would've been micro
StimMarine
Profile Joined March 2011
723 Posts
August 12 2011 19:48 GMT
#208
It's actually incredibly, frustratingly, and unreasonably expensive for private companies to have proper data security. It's a bit like how businesses pay exorbitant prices for their computers hardware from 'IT business solutions" companies.
Ownos
Profile Joined July 2010
United States2147 Posts
August 12 2011 19:48 GMT
#209
So what could be motivation for this? Did someone really want to see some GSL that badly without paying? Everyone change your PWs, allow no freeloaders!
...deeper and deeper into the bowels of El Diablo
StimMarine
Profile Joined March 2011
723 Posts
August 12 2011 19:49 GMT
#210
On August 13 2011 04:48 duckTemplar wrote:
Oh they have my email , my password and access to my paypal now, rather unfortunatly, I just paid for GSL August a few days ago.


Hurry up and change your paypal password then.
R1CH
Profile Blog Joined May 2007
Netherlands10341 Posts
August 12 2011 19:49 GMT
#211
On August 13 2011 04:42 Crying wrote:
Is there any clarification what kind of attack was used?

SQL?
Perl exploit?
?!?!?

Looks like SQL injection from what I saw.
AdministratorTwitter: @R1CH_TL
TL+ Member
gullberg
Profile Blog Joined February 2011
Sweden1301 Posts
Last Edited: 2011-08-12 19:51:17
August 12 2011 19:50 GMT
#212
On August 13 2011 04:48 LittLeD wrote:
Show nested quote +
On August 13 2011 04:45 gullberg wrote:
What if I logged in via twitter/facebook. Has it been compromised?

Did you read the OP?

Not really, freaked out since I use that password for alot of important stuff <.<

Good to know that I'm not affected, lol.

Stored in text? lol'd
Mithriel
Profile Joined November 2010
Netherlands2969 Posts
August 12 2011 19:50 GMT
#213
SEriously.... i mean seriously............ ffs
There is no shame in defeat so long as the spirit is unconquered. | Cheering for Maru, Innovation and MMA!
Kerotan
Profile Blog Joined May 2008
England2109 Posts
August 12 2011 19:51 GMT
#214
On August 13 2011 03:14 R1CH wrote:
I have independently verified that at least some usernames, passwords and email addresses have been compromised.

I love that people just glaze over this, I may be a computer nooby, but in my eyes R1CH you are a wizard.

Also thank fuck for signing in with twitter, I thought that was a bullshit method at first.
Nerdette // External revolution - Internal revolution // Fabulous // I raise my hands to heaven of curiosity // I don't know what to ask for // What has it got for me? // Kerribear
namste
Profile Joined October 2010
Finland2292 Posts
August 12 2011 19:51 GMT
#215
On August 13 2011 04:45 sVnteen wrote:
Show nested quote +
On August 13 2011 03:18 Keap wrote:
GOM is so unprofessional. The level of play of their players is amazing, but the business side of the Korean SC2 scene is really lacking to say the least.



that happens to the best companies

sometimes there is just bad luck


Heard that some quite small unheard company called Sony did a similar thing, saving data in a simple text.
IM hwaitiing ~ IMMvp #1 | Bang Min Ah <3<3
jarrydesque
Profile Joined November 2010
584 Posts
August 12 2011 19:52 GMT
#216
Thanks for the heads up. I changed all my passwords again just in case.
#1 Kennigit fanboy/stalker
NineKOne
Profile Joined February 2011
Canada92 Posts
August 12 2011 19:52 GMT
#217
md5();

how hard is that gom?
"It's over 9000!" -V
KazeHydra
Profile Blog Joined August 2010
Japan2788 Posts
August 12 2011 19:52 GMT
#218
Can't believe the passwords weren't even encrypted -_- Well, I was overdue for a password change anyway. Thanks for the keepass link, definitely gonna use that instead of my poorly hidden notepad file.
"Because I know this promise that won’t disappear will turn even a cause of tears into strength. You taught me that if I can believe, there is nothing that cannot come true." - Nana Mizuki (Yakusoku) 17:36 ils kaze got me into nana 17:36 ils by his blog
AXygnus
Profile Blog Joined November 2010
Portugal1008 Posts
August 12 2011 19:53 GMT
#219
On August 13 2011 04:50 gullberg wrote:
Show nested quote +
On August 13 2011 04:48 LittLeD wrote:
On August 13 2011 04:45 gullberg wrote:
What if I logged in via twitter/facebook. Has it been compromised?

Did you read the OP?

Not really, freaked out since I use that password for alot of important stuff <.<

Good to know that I'm not affected, lol.

Stored in text? lol'd



You should use different passwords for different stuff... I have always done so, but they were rather simple, since they were so many and I had to remember them by head. Didn't know about that program R1CH mentioned in the OP, so that makes the job a lot easier.
"To create, to recreate. To create, to recreate. Down to the last seed, I stand with a dark stare. Still silent. Still frighteningly silent."
Vipsanius
Profile Joined February 2011
Netherlands708 Posts
August 12 2011 19:55 GMT
#220
Ok, updated passwords for all important websites. Facebook, Twitter, gomtv, etc.
Glowbox
Profile Joined June 2010
Netherlands330 Posts
August 12 2011 19:55 GMT
#221
On August 13 2011 04:52 NineKOne wrote:
md5();

how hard is that gom?


MD5 is bad aswell, as explained earlier in this thread.

Ideally you want to use something like bcrypt: http://codahale.com/how-to-safely-store-a-password/
theDragoon
Profile Joined June 2010
Canada307 Posts
August 12 2011 19:55 GMT
#222
I used an email I never use, and a password that you could consider as a "throwaway" password, meaning I only use it on sites I don't fully trust and don't really care about. But I do use this password pretty much everywhere and I've given it out to some friends already.
-stOpSKY-
Profile Joined September 2010
Canada498 Posts
August 12 2011 19:56 GMT
#223
I really find it hard to believe that any company would still store personal information in plaintext. What a joke.
Thanks for updating the community R1CH, you are the man!
Shield
Profile Blog Joined August 2009
Bulgaria4824 Posts
August 12 2011 19:56 GMT
#224
On August 13 2011 04:45 sVnteen wrote:
Show nested quote +
On August 13 2011 03:18 Keap wrote:
GOM is so unprofessional. The level of play of their players is amazing, but the business side of the Korean SC2 scene is really lacking to say the least.



that happens to the best companies

sometimes there is just bad luck


Not encrypting passwords != luck at all
This is stupidity.
Serelitz
Profile Joined April 2011
Netherlands2895 Posts
August 12 2011 19:56 GMT
#225
Has this happened before? I had someone from south korea access my gmail a few months back when my GOMTV pass was the same as my email's (I tend to cycle my email along with newest passwords so I don't forget it). I made a post about it then in a thread about hacked gmail accounts here.
R1CH
Profile Blog Joined May 2007
Netherlands10341 Posts
August 12 2011 19:57 GMT
#226
On August 13 2011 04:55 Glowbox wrote:
Ideally you want to use something like bcrypt: http://codahale.com/how-to-safely-store-a-password/

For those curious, this is how TL passwords are stored.
AdministratorTwitter: @R1CH_TL
TL+ Member
Sneakyz
Profile Joined October 2010
Sweden2361 Posts
August 12 2011 19:57 GMT
#227
I guess this is a good reason to change my 3 years old blizzard pass XD
I have found the Iron to be my greatest friend. It never freaks out on me, never runs. Friends may come and go. But two hundred pounds is always two hundred pounds.
vyyye
Profile Joined July 2010
Sweden3917 Posts
August 12 2011 19:57 GMT
#228
I just remembered that I changed my gom password to some obscure password I really never use, + it has a dummy e-mail. I generally don't use my dummy e-mail or different passwords.
Wow, lucky.
BootySmakaRaX
Profile Joined November 2010
Japan82 Posts
August 12 2011 19:57 GMT
#229
Protip: never store your customers passwords in rich text files -_-;;
RELEASE THE GRACKEN
HeIios
Profile Joined May 2010
Sweden2523 Posts
August 12 2011 19:58 GMT
#230
Glad I used a unique, easy-to-remember password for GOM. Sad to see some kids doing this.
Wombutt
Profile Joined April 2011
United States159 Posts
August 12 2011 20:00 GMT
#231
is it just the most recent password? or were old ones also stored
All Dae
VTArlock
Profile Blog Joined December 2009
United States1763 Posts
August 12 2011 20:00 GMT
#232
O jeez...r1ch I don't understand why you don't just do ALL of the security for the world. At least then someone trustworthy would be in charge.
Why?
Crying
Profile Joined February 2011
Bulgaria778 Posts
August 12 2011 20:01 GMT
#233
On August 13 2011 04:57 R1CH wrote:
Show nested quote +
On August 13 2011 04:55 Glowbox wrote:
Ideally you want to use something like bcrypt: http://codahale.com/how-to-safely-store-a-password/

For those curious, this is how TL passwords are stored.


The difference between TL website and GOMTV is that TL isn't at all vunerable to SQL and i think is really well written(props to the ones that did the site)
However GOM seems bad since its hacked

Someone says MD5 is good way,it is good if the passwords aren't whole words like:mother,sister,football,basketball because every MD5 cracking website already has their MD5's ,however if they are like mmm0007h333R pretty much the MD5 will never get cracked or will take months,years.Hackers dont like waiting XD
Determination~ Hard Work Surpass NATURAL GENIUS!
Vei
Profile Joined March 2010
United States2845 Posts
August 12 2011 20:03 GMT
#234
how fucking dumb can a service be, shit like this is unacceptable.
www.justin.tv/veisc2 ~ 720p + commentary
Kamikiri
Profile Joined October 2010
United States1319 Posts
August 12 2011 20:03 GMT
#235
Has gomtv released any official statements yet?
Tegin
Profile Joined November 2010
United States840 Posts
August 12 2011 20:04 GMT
#236
Glad I use different passwords for all my accounts! Thanks for the heads up R1CH!
Pain is weakness leaving the body.
Crying
Profile Joined February 2011
Bulgaria778 Posts
August 12 2011 20:05 GMT
#237
The funny thing is that there is nothing under "News" at GOM website??
Wtf is this R1CH knows that attack occured when GOM has no clue
HIRE R1CH !
Determination~ Hard Work Surpass NATURAL GENIUS!
Copymizer
Profile Joined November 2010
Denmark2095 Posts
August 12 2011 20:05 GMT
#238
just changed my gomtv acc password.
~~Yo man ! MBCGame HERO Fighting !! Holy check !
RHMVNovus
Profile Joined October 2010
United States738 Posts
August 12 2011 20:08 GMT
#239
Is there any way this can get posted on the front page?

I probably would have missed it were it not for Milkis's retweet.
Droning his sorrows in massive amounts of macro
DisneylandSC
Profile Joined November 2010
Netherlands435 Posts
August 12 2011 20:08 GMT
#240
Thanks for letting us know. And epic fail on GOMTV's part. Storing passwords in plain text AND not letting us know their site has been compromised.
-AtRi-
Profile Joined December 2010
123 Posts
August 12 2011 20:10 GMT
#241
sick. this is what i get for using the same password for most websites -_-
Hokay
Profile Joined May 2007
United States738 Posts
Last Edited: 2011-08-12 20:13:37
August 12 2011 20:10 GMT
#242
My gmail account (for school) says there has been suspicious activity on my email account, and that I have to verify myself through phone or text :/

I checked my email and found someone tried to email all my contact lists:

(no subject)

to ggonzale, monkeyskratch, cross.andy, bcebecioglu, bighitter, dpol85, james, JTarzia
show details Aug 11 (2 days ago)
im sure my friends are all tired of always loaning me money I was at
the end of the road this couldnt have worked out better!
://rallispor.com/CarlSpencer74.ht now I can afford season tickets
You will thank me for this!



I edited the link so no one accidentally clicks on it. Should I be worried?
blabber
Profile Blog Joined June 2007
United States4448 Posts
Last Edited: 2011-08-12 20:12:10
August 12 2011 20:11 GMT
#243
On August 13 2011 05:10 Hokay wrote:
My gmail account (for school) says there has been suspicious activity on my email account, and that I have to verify myself through phone or text :/

I checked my email and found someone tried to email all my contact lists:

(no subject)

to ggonzale, monkeyskratch, cross.andy, bcebecioglu, bighitter, dpol85, james, JTarzia
show details Aug 11 (2 days ago)
im sure my friends are all tired of always loaning me money I was at
the end of the road this couldnt have worked out better!
://rallispor.com/CarlSpencer74.htm now I can afford season tickets
You will thank me for this!



I edited the link so no one accidentally clicks on it. Should I be worried?

yes you should be worried. change your password immediately
blabberrrrr
ExO_
Profile Blog Joined September 2009
United States2316 Posts
August 12 2011 20:13 GMT
#244
So are 100% of accounts compromised? And is it only accounts that have paid that were compromised or are all types of accounts (like the free ones used to watch the SQ live stream) compromised as well?
Zocat
Profile Joined April 2010
Germany2229 Posts
August 12 2011 20:13 GMT
#245
On August 13 2011 05:05 Crying wrote:
The funny thing is that there is nothing under "News" at GOM website??
Wtf is this R1CH knows that attack occured when GOM has no clue
HIRE R1CH !


Because R1CH isnt employed by GOM. He posted the news at 3am KST.
Do you work at 3am? I doubt it.

OT:
Plaintext. L O L.
ravemir
Profile Joined April 2011
Portugal595 Posts
August 12 2011 20:15 GMT
#246
On August 13 2011 04:57 R1CH wrote:
Show nested quote +
On August 13 2011 04:55 Glowbox wrote:
Ideally you want to use something like bcrypt: http://codahale.com/how-to-safely-store-a-password/

For those curious, this is how TL passwords are stored.

Really? Isn't that supposedly too expensive on the login operation?
"more gg, more skill"
R1CH
Profile Blog Joined May 2007
Netherlands10341 Posts
August 12 2011 20:17 GMT
#247
On August 13 2011 05:15 ravemir wrote:
Show nested quote +
On August 13 2011 04:57 R1CH wrote:
On August 13 2011 04:55 Glowbox wrote:
Ideally you want to use something like bcrypt: http://codahale.com/how-to-safely-store-a-password/

For those curious, this is how TL passwords are stored.

Really? Isn't that supposedly too expensive on the login operation?

Not if you balance the iterations properly. A few hundred ms extra on the login isn't noticeable by most people and is plenty enough to defeat brute force attacks.
AdministratorTwitter: @R1CH_TL
TL+ Member
ChowChillaCharlie
Profile Joined April 2010
Sweden677 Posts
August 12 2011 20:18 GMT
#248
Turns out i used the same pass for my hotmail as i did for GOMtv (couldn't remember my GOM pass at first), just glad i had the time to change it before i got hacked.

Seriously, GOM needs a slap in the face for this shit.
kyophan
Profile Joined January 2010
United States113 Posts
August 12 2011 20:18 GMT
#249
Sigh, gomtv was the only site that I used the same password as my email. Thanks for the heads up.
AgentZero
Profile Joined October 2010
United States28 Posts
August 12 2011 20:19 GMT
#250
On August 13 2011 05:05 Copymizer wrote:
just changed my gomtv acc password.


Honestly, until gom makes a statement I'm not even going to visit their website. We know that there is a possible compromise of account information but who knows if they loaded their website with all kinds of goodies.
delHospital
Profile Blog Joined December 2010
Poland261 Posts
Last Edited: 2011-08-12 20:20:16
August 12 2011 20:19 GMT
#251
On August 13 2011 05:15 ravemir wrote:
Show nested quote +
On August 13 2011 04:57 R1CH wrote:
On August 13 2011 04:55 Glowbox wrote:
Ideally you want to use something like bcrypt: http://codahale.com/how-to-safely-store-a-password/

For those curious, this is how TL passwords are stored.

Really? Isn't that supposedly too expensive on the login operation?

You can choose the number of iterations, it is usually lower for logging in and higher for file encryption.

E: ninja'd D:
Titorelli
Profile Joined March 2011
2492 Posts
August 12 2011 20:19 GMT
#252
Can someone tell me if my financial data is safe or not? I did NOT pay via paypal since I dont have a paypal account
"Everybody poops.... after Tasteless kills them" Artosis
EndOfTime88
Profile Joined February 2011
Austria259 Posts
August 12 2011 20:20 GMT
#253
I'm not too surprised to find this out. I bought the first two seasons of GSL with two separate new emails that I didn't use for anything else, and received phishing emails back then on both of them. I guess their security isn't that great. :/...

I'll keep purchasing GSL though. x]
"Time is what we want most,but what we use worst."-William Penn
cronican
Profile Joined February 2009
Canada424 Posts
August 12 2011 20:23 GMT
#254
Thanks R1CH! Helpful as always.
R1CH
Profile Blog Joined May 2007
Netherlands10341 Posts
August 12 2011 20:25 GMT
#255
On August 13 2011 05:19 Titorelli wrote:
Can someone tell me if my financial data is safe or not? I did NOT pay via paypal since I dont have a paypal account

You still paid through PayPal since there is no other way to pay. PayPal lets you checkout even without an account.
AdministratorTwitter: @R1CH_TL
TL+ Member
EsMuyVien
Profile Joined July 2011
United States408 Posts
August 12 2011 20:26 GMT
#256
Goddammit. Fucking idiots.
If what I think is happening is happening - it better not be.
ravemir
Profile Joined April 2011
Portugal595 Posts
August 12 2011 20:26 GMT
#257
On August 13 2011 05:17 R1CH wrote:
Show nested quote +
On August 13 2011 05:15 ravemir wrote:
On August 13 2011 04:57 R1CH wrote:
On August 13 2011 04:55 Glowbox wrote:
Ideally you want to use something like bcrypt: http://codahale.com/how-to-safely-store-a-password/

For those curious, this is how TL passwords are stored.

Really? Isn't that supposedly too expensive on the login operation?

Not if you balance the iterations properly. A few hundred ms extra on the login isn't noticeable by most people and is plenty enough to defeat brute force attacks.


True, I read that it ain't ACTUAL Blowfish cyphering, but a modified function, and that you can also adjust the calculation rate.

But tell me this, if you want to adjust the iterations, won't you have to re-calculate every password for each user?
"more gg, more skill"
CardG
Profile Joined March 2011
France131 Posts
August 12 2011 20:27 GMT
#258
I just changed my GomTV account, but i can't log in ... i dont receive the e-mail to confirm all o that :/ anyone?
Badboyrune
Profile Blog Joined May 2010
Sweden2247 Posts
August 12 2011 20:28 GMT
#259
I find it absolutely mind boggling that people still store passwords in plain text. Are there any reasons for not encrypting passwords more than sheer laziness (even that is not a valid reason due to the easiness of encrypting passwords)? I just don't understand why you would ever set it up like that, still it seems to not be very uncommon even among big companies.
"If yellow does start SC2, I should start handsomenerd diaper busniess and become a rich man" - John the Translator
Kralic
Profile Blog Joined March 2010
Canada2628 Posts
August 12 2011 20:29 GMT
#260
Well I am glad I decided to play robin hood and let my friend view all of the previous seasons of GSL and GSTL, so I changed my password to something stupid for him months ago.
Brood War forever!
vyyye
Profile Joined July 2010
Sweden3917 Posts
August 12 2011 20:29 GMT
#261
On August 13 2011 05:28 Badboyrune wrote:
I find it absolutely mind boggling that people still store passwords in plain text. Are there any reasons for not encrypting passwords more than sheer laziness (even that is not a valid reason due to the easiness of encrypting passwords)? I just don't understand why you would ever set it up like that, still it seems to not be very uncommon even among big companies.

Should be bloody common after SONY got hacked, thought that would make nearly everyone think twice about security.
EndOfTime88
Profile Joined February 2011
Austria259 Posts
August 12 2011 20:32 GMT
#262
On August 13 2011 03:28 EtohEtoh wrote:
Show nested quote +
On August 13 2011 03:26 ArnaudF wrote:
On August 13 2011 03:24 R1CH wrote:
Someone just pointed out that the exploit through which this information was gained may still exist, so you may want to hold off changing passwords until GomTV confirm it is safe.


And I read this just after I changed my password xd

same lol


Same. -__-
"Time is what we want most,but what we use worst."-William Penn
AgentZero
Profile Joined October 2010
United States28 Posts
August 12 2011 20:32 GMT
#263
On August 13 2011 05:29 vyyye wrote:
Show nested quote +
On August 13 2011 05:28 Badboyrune wrote:
I find it absolutely mind boggling that people still store passwords in plain text. Are there any reasons for not encrypting passwords more than sheer laziness (even that is not a valid reason due to the easiness of encrypting passwords)? I just don't understand why you would ever set it up like that, still it seems to not be very uncommon even among big companies.

Should be bloody common after SONY got hacked, thought that would make nearly everyone think twice about security.


Sadly many companies think exactly twice about security. They think about it once when they are designing their system then when they get the bill they think twice about having security.
hYdeOut
Profile Joined May 2011
Australia25 Posts
August 12 2011 20:35 GMT
#264
Changed my PayPal password just to be safe. Glad I have non funds on there but my credit card is linked. No recent transaction history so looks like I'm safe.
Grimsong
Profile Joined August 2010
United States252 Posts
August 12 2011 20:36 GMT
#265
Korean teams withdraw from NASL > Gom compromised...

/tinfoil hat
Kyyuna
Profile Joined October 2010
United States1222 Posts
August 12 2011 20:37 GMT
#266
<3 r1ch for keepass, making my life so much easier :D
Cokefreak
Profile Joined June 2011
Finland8095 Posts
August 12 2011 20:38 GMT
#267
This certainly sucks...
FallDownMarigold
Profile Blog Joined December 2010
United States3710 Posts
August 12 2011 20:38 GMT
#268
I use my real full name as my login, and social security number + credit card number as my password.

xxxxxxb
Profile Joined October 2009
155 Posts
August 12 2011 20:39 GMT
#269
Thanks for the advice, just finished changing some passwords. I'll trust R1CH and get that keepass thing ... don't disappoint me, please. :p
vyyye
Profile Joined July 2010
Sweden3917 Posts
August 12 2011 20:39 GMT
#270
On August 13 2011 05:38 FallDownMarigold wrote:
I use my real full name as my login, and social security number + credit card number as my password.


And I thought Login : Password was the dumbest login/pass combo, holy shit.
Cokefreak
Profile Joined June 2011
Finland8095 Posts
August 12 2011 20:40 GMT
#271
On August 13 2011 05:39 vyyye wrote:
Show nested quote +
On August 13 2011 05:38 FallDownMarigold wrote:
I use my real full name as my login, and social security number + credit card number as my password.


And I thought Login : Password was the dumbest login/pass combo, holy shit.

Sadly I have to agree :/
R1CH
Profile Blog Joined May 2007
Netherlands10341 Posts
Last Edited: 2011-08-12 20:43:43
August 12 2011 20:41 GMT
#272
On August 13 2011 05:26 ravemir wrote:
But tell me this, if you want to adjust the iterations, won't you have to re-calculate every password for each user?

Most systems store the algorithm and settings with the password hash and salt. For example, if your password hash is $2a$10$WyJ.NSYEmLixexXspQyoEOVYGK55cDjQd2cZedBN4t9.., the 2a identifies the algorithm (blowfish) and the 10 identifies the iterations (2^10). So if suddenly PCs become 100x faster I can just increase the 10 in our config and all new passwords become more secure, and old passwords are upgraded on successful logon.
AdministratorTwitter: @R1CH_TL
TL+ Member
TheRPGAddict
Profile Joined October 2010
United States1403 Posts
August 12 2011 20:42 GMT
#273
I am so glad I took the lazy way out and just used my facebook.
dala
Profile Joined August 2010
Sweden477 Posts
August 12 2011 20:43 GMT
#274
Boooooo Gom!
ballasdontcry
Profile Joined January 2011
Canada595 Posts
August 12 2011 20:44 GMT
#275
I guess I will use FB/Twitter on Gom to login from now on... who would've thought that using those makes you safer? Hahah.

In any case, changed my pw's already to the more important things I'm aware of. Email is already a unique pw and paypal requires a security token generator so I'm covered.
Saechiis
Profile Blog Joined May 2010
Netherlands4989 Posts
August 12 2011 20:44 GMT
#276
I knew it, YellOw is a KeSPA spy.
I think esports is pretty nice.
Bollard
Profile Joined June 2011
8 Posts
August 12 2011 20:45 GMT
#277
Reading the bcrypt article made me laugh, every single way we encrypt our data at work appears in the 'DO NOT USE' list. md5, SHA and Salts.
b0urne420
Profile Joined December 2010
Canada112 Posts
August 12 2011 20:48 GMT
#278
you serious GOM? this shit got me so frustrated. had to change a lot of my passwords because of this, and that process is such a bitch.
crawlingchaos
Profile Joined March 2011
Canada2025 Posts
August 12 2011 20:48 GMT
#279
Laziness ftw. Thank god I never bothered to change the original password they handed out when I created my account, since I certainly do use the same for all my accounts o.O
They say that life's a carousel, spinning fast you've gotta ride it well, the world is full of kings and queens who blind your eyes and steal your dreams, it's heaven and hell, oh well.
Ventor
Profile Joined February 2011
United States336 Posts
August 12 2011 20:49 GMT
#280
Great scott! Sound the alarms!
oGsMc - EGHuK - White-Ra - SlayerSBoxeR - STBomber Fighting!~
Voltaire
Profile Joined September 2010
United States1485 Posts
Last Edited: 2011-08-12 20:50:41
August 12 2011 20:50 GMT
#281
Yikes. I hope there won't be a repeat occurrence.
As long as people believe in absurdities they will continue to commit atrocities.
nonsence
Profile Joined July 2010
United States57 Posts
August 12 2011 20:51 GMT
#282
On August 13 2011 05:17 R1CH wrote:
Show nested quote +
On August 13 2011 05:15 ravemir wrote:
On August 13 2011 04:57 R1CH wrote:
On August 13 2011 04:55 Glowbox wrote:
Ideally you want to use something like bcrypt: http://codahale.com/how-to-safely-store-a-password/

For those curious, this is how TL passwords are stored.

Really? Isn't that supposedly too expensive on the login operation?

Not if you balance the iterations properly. A few hundred ms extra on the login isn't noticeable by most people and is plenty enough to defeat brute force attacks.


COOL, i hadn't heard of bcrypt, I just finished integrating a java version into my software Thanks TL
OMG Bear is driving! How is that possible?
DiamondTear
Profile Joined June 2010
Finland165 Posts
August 12 2011 20:51 GMT
#283
Changed GOM password, got not confirmation email (hotmail), can't log in.
slicknav
Profile Joined January 2011
1409 Posts
August 12 2011 20:51 GMT
#284
this should really be put on the front page of TL somewhere. This is kinda serious if personal information has been compromised.
blah blah blah...
Multis
Profile Joined May 2010
Finland21 Posts
August 12 2011 20:52 GMT
#285
Thanks for the heads up!
EndOfTime88
Profile Joined February 2011
Austria259 Posts
August 12 2011 20:53 GMT
#286
On August 13 2011 05:51 DiamondTear wrote:
Changed GOM password, got not confirmation email (hotmail), can't log in.


I'm having the same problem right now.
"Time is what we want most,but what we use worst."-William Penn
FallDownMarigold
Profile Blog Joined December 2010
United States3710 Posts
August 12 2011 20:53 GMT
#287
On August 13 2011 05:39 vyyye wrote:
Show nested quote +
On August 13 2011 05:38 FallDownMarigold wrote:
I use my real full name as my login, and social security number + credit card number as my password.


And I thought Login : Password was the dumbest login/pass combo, holy shit.


It's all good now, I just changed my account name to my home address and my password to my bank routing number.
thee telescopes
Profile Joined August 2010
321 Posts
August 12 2011 20:54 GMT
#288
On August 13 2011 05:51 slicknav wrote:
this should really be put on the front page of TL somewhere. This is kinda serious if personal information has been compromised.


Kinda annoying that there's nothing on Gom's site about this.
nooboon
Profile Blog Joined July 2011
2602 Posts
August 12 2011 20:54 GMT
#289
I don't know whats more surprising, GomTV getting hacked, or that R1CH found out who had been hack by himself.
CardG
Profile Joined March 2011
France131 Posts
August 12 2011 20:55 GMT
#290
On August 13 2011 05:53 EndOfTime88 wrote:
Show nested quote +
On August 13 2011 05:51 DiamondTear wrote:
Changed GOM password, got not confirmation email (hotmail), can't log in.


I'm having the same problem right now.

Same.
Badboyrune
Profile Blog Joined May 2010
Sweden2247 Posts
Last Edited: 2011-08-12 20:56:53
August 12 2011 20:55 GMT
#291
On August 13 2011 05:41 R1CH wrote:
Show nested quote +
On August 13 2011 05:26 ravemir wrote:
But tell me this, if you want to adjust the iterations, won't you have to re-calculate every password for each user?

Most systems store the algorithm and settings with the password hash and salt. For example, if your password hash is $2a$10$WyJ.NSYEmLixexXspQyoEOVYGK55cDjQd2cZedBN4t9.., the 2a identifies the algorithm (blowfish) and the 10 identifies the iterations (2^10). So if suddenly PCs become 100x faster I can just increase the 10 in our config and all new passwords become more secure, and old passwords are upgraded on successful logon.


I think this is the point where Hot_Bid posts:

I don’t understand the check_password function, why don’t you compare with the
stored hash in the BBDD? Something like this:
function check_password(password, nickname) {
//get user from nickname user = User.objects.get(nickname=nickname)
return user.hash_stored == hash(password)
Btw in your function check_password I suppose that in order to calculate again the
hash I’d have to do it with the cost parameter, something like this:
// this will be used to compare a password against a hash
public static function check_password($hash, $password) {
$new_hash = hash($password);
return ($hash == $new_hash);
"If yellow does start SC2, I should start handsomenerd diaper busniess and become a rich man" - John the Translator
Integra
Profile Blog Joined January 2008
Sweden5626 Posts
August 12 2011 20:56 GMT
#292
On August 13 2011 03:14 R1CH wrote:
There's a post on reddit that suggests that GOMTV has been compromised. I have independently verified that at least some usernames, passwords and email addresses have been compromised.

There appears to be zero security on the passwords as they were stored in plain text (really GOM?). This means if you use your GomTV password anywhere else, you should change it and consider it compromised. To clarify, your GomTV.net username, email address, PayPal real name and your GomTV.net password are likely compromised. Personal information such as your address may be compromised too if it was stored. You should also change your GomTV password to prevent unauthorized account access, although the exploit through which the information was compromised may still exist.

Since payments are processed through PayPal, there is no risk of your financial information being compromised, unless you used your PayPal password when signing up for GomTV (don't do this). Users who logged in via SNS should be safe as Twitter / Facebook authentication is token based, not password based.

If you aren't already, you should really use unique passwords for each website since this happens more often than you think (ever hear someone say they were "hacked"? this is likely how it happens) and not all websites will disclose if they get compromised. Use http://keepass.info/ for password management.

R1CH, from what I can deduct they simply used a SQL Injection to list all the data, if it's that simple then why does it matter if we change the password, they will still get it, you could change it a million times.
"Dark Pleasure" | | I survived the Locust war of May 3, 2014
Eleaven
Profile Joined September 2010
772 Posts
August 12 2011 20:57 GMT
#293
man i was seriously worried till you get to the facebook part.. phew
SilentShout
Profile Joined March 2011
686 Posts
August 12 2011 20:57 GMT
#294
Just got done changing a lot of my passwords... Just in case. My fault for using the same pass for so many sites, but better to be safe than sorry. Or so they say
Toons
Profile Joined November 2010
Australia136 Posts
August 12 2011 20:57 GMT
#295
^ Read further down, he says this ...

Change your pass to something completely obscure until they figure it out
Probes and pylons
strexer
Profile Blog Joined September 2010
United States54 Posts
August 12 2011 20:59 GMT
#296
You have to be kidding me, of course the only place I use my email password is GOMTV, I hope I'm not too late.
TOCHMY
Profile Blog Joined June 2010
Sweden1692 Posts
August 12 2011 20:59 GMT
#297
fuck hackers ffs i cant keep track on all my passwords ( some dipshit tried to login to my facebook from japan.
Yoona <3 ¯\_(ツ)_/¯ Look! It's Totoro! ☉.☉☂
ma70
Profile Joined October 2010
253 Posts
August 12 2011 21:04 GMT
#298
Thank you for posting this. I immediately changed my GOMTV.net/Email/Paypal password to different things....
Soulish
Profile Joined April 2010
Canada1403 Posts
August 12 2011 21:05 GMT
#299
On August 13 2011 03:18 radim wrote:
Show nested quote +
On August 13 2011 03:14 R1CH wrote:
...the passwords as they were stored in plain text...

are you serious? oh my god :x

Being stored in plain text doesn't mean they arent encrypted
me all in, he drone drone drone, me win
nOondn
Profile Joined March 2011
564 Posts
August 12 2011 21:05 GMT
#300
OMG GOM .... so careless, they are not professional in business
Mid Master Terran @ kr server fighting !!!
Roggay
Profile Joined April 2010
Switzerland6320 Posts
August 12 2011 21:06 GMT
#301
I use the same password for nearly everything EXCEPT my Bnet account, so I don't really care, the rest is not really important (I don't know what they would do with my other accounts).
Kentor *
Profile Blog Joined December 2007
United States5784 Posts
Last Edited: 2011-08-12 21:07:21
August 12 2011 21:06 GMT
#302
On August 13 2011 05:56 Integra wrote:
Show nested quote +
On August 13 2011 03:14 R1CH wrote:
There's a post on reddit that suggests that GOMTV has been compromised. I have independently verified that at least some usernames, passwords and email addresses have been compromised.

There appears to be zero security on the passwords as they were stored in plain text (really GOM?). This means if you use your GomTV password anywhere else, you should change it and consider it compromised. To clarify, your GomTV.net username, email address, PayPal real name and your GomTV.net password are likely compromised. Personal information such as your address may be compromised too if it was stored. You should also change your GomTV password to prevent unauthorized account access, although the exploit through which the information was compromised may still exist.

Since payments are processed through PayPal, there is no risk of your financial information being compromised, unless you used your PayPal password when signing up for GomTV (don't do this). Users who logged in via SNS should be safe as Twitter / Facebook authentication is token based, not password based.

If you aren't already, you should really use unique passwords for each website since this happens more often than you think (ever hear someone say they were "hacked"? this is likely how it happens) and not all websites will disclose if they get compromised. Use http://keepass.info/ for password management.

R1CH, from what I can deduct they simply used a SQL Injection to list all the data, if it's that simple then why does it matter if we change the password, they will still get it, you could change it a million times.

Change it to something that you don't use anywhere else.
Integra
Profile Blog Joined January 2008
Sweden5626 Posts
August 12 2011 21:08 GMT
#303
what, they used plain text to store the password....... WTF, encryption is a build in feature in PHP and there existst thousands of professionally made salt functions out there. WHY are people so dammn retarded when it comes to security!
"Dark Pleasure" | | I survived the Locust war of May 3, 2014
ravemir
Profile Joined April 2011
Portugal595 Posts
August 12 2011 21:10 GMT
#304
On August 13 2011 05:41 R1CH wrote:
Show nested quote +
On August 13 2011 05:26 ravemir wrote:
But tell me this, if you want to adjust the iterations, won't you have to re-calculate every password for each user?

Most systems store the algorithm and settings with the password hash and salt. For example, if your password hash is $2a$10$WyJ.NSYEmLixexXspQyoEOVYGK55cDjQd2cZedBN4t9.., the 2a identifies the algorithm (blowfish) and the 10 identifies the iterations (2^10). So if suddenly PCs become 100x faster I can just increase the 10 in our config and all new passwords become more secure, and old passwords are upgraded on successful logon.


Good point! The password will have matching smaller value until a valid login after you make the system wide change.
"more gg, more skill"
Integra
Profile Blog Joined January 2008
Sweden5626 Posts
August 12 2011 21:11 GMT
#305
On August 13 2011 06:06 Kentor wrote:
Show nested quote +
On August 13 2011 05:56 Integra wrote:
On August 13 2011 03:14 R1CH wrote:
There's a post on reddit that suggests that GOMTV has been compromised. I have independently verified that at least some usernames, passwords and email addresses have been compromised.

There appears to be zero security on the passwords as they were stored in plain text (really GOM?). This means if you use your GomTV password anywhere else, you should change it and consider it compromised. To clarify, your GomTV.net username, email address, PayPal real name and your GomTV.net password are likely compromised. Personal information such as your address may be compromised too if it was stored. You should also change your GomTV password to prevent unauthorized account access, although the exploit through which the information was compromised may still exist.

Since payments are processed through PayPal, there is no risk of your financial information being compromised, unless you used your PayPal password when signing up for GomTV (don't do this). Users who logged in via SNS should be safe as Twitter / Facebook authentication is token based, not password based.

If you aren't already, you should really use unique passwords for each website since this happens more often than you think (ever hear someone say they were "hacked"? this is likely how it happens) and not all websites will disclose if they get compromised. Use http://keepass.info/ for password management.

R1CH, from what I can deduct they simply used a SQL Injection to list all the data, if it's that simple then why does it matter if we change the password, they will still get it, you could change it a million times.

Change it to something that you don't use anywhere else.


IF people used the same password that they used on GOM they better dammn be changing those passwords on all the other sites as well. I mean you don't know what kind of databasetype that is being used, what if the hacker thinks up the bright idea to rollback the Server image to revert the changes of the password you did, then he will get the passwords anyway.
"Dark Pleasure" | | I survived the Locust war of May 3, 2014
Penecks
Profile Joined August 2010
United States600 Posts
August 12 2011 21:19 GMT
#306
Sooo is there any point changing the password you used on the GOM site or is there still shit happening that would cause that new password to be compromised?
straight poppin
TaKemE
Profile Joined April 2010
Denmark1045 Posts
August 12 2011 21:21 GMT
#307
I dont know anything about this but is the only proof of this happening that one screenshot? couldnt someone who knows about that stuff easy make a "fake" screenshot?
Jibba
Profile Blog Joined October 2007
United States22883 Posts
August 12 2011 21:22 GMT
#308
On August 13 2011 06:08 Integra wrote:
what, they used plain text to store the password....... WTF, encryption is a build in feature in PHP and there existst thousands of professionally made salt functions out there. WHY are people so dammn retarded when it comes to security!

After this kind of stupidity, I just stop purchasing/supporting people. ;o Same goes for Sony.
ModeratorNow I'm distant, dark in this anthrobeat
Integra
Profile Blog Joined January 2008
Sweden5626 Posts
August 12 2011 21:23 GMT
#309
On August 13 2011 06:21 TaKemE wrote:
I dont know anything about this but is the only proof of this happening that one screenshot? couldnt someone who knows about that stuff easy make a "fake" screenshot?

It's been verified.
"Dark Pleasure" | | I survived the Locust war of May 3, 2014
forgottendreams
Profile Joined August 2010
United States1771 Posts
August 12 2011 21:25 GMT
#310
There's still no email notification or news on GOMTV.net yet....I feel sorry for all the people who don't know because they don't frequent TeamLiquid.net or PlayXP.
thee telescopes
Profile Joined August 2010
321 Posts
August 12 2011 21:27 GMT
#311
On August 13 2011 06:25 forgottendreams wrote:
There's still no email notification or news on GOMTV.net yet....I feel sorry for all the people who don't know because they don't frequent TeamLiquid.net or PlayXP.


This is really irresponsible.
pog0
Profile Joined June 2010
United States30 Posts
August 12 2011 21:28 GMT
#312
Sucks as that is my password for many things but different accounts and variations. Le sigh.
tuho12345
Profile Blog Joined July 2011
4482 Posts
August 12 2011 21:29 GMT
#313
what about my facebook account? I use that to sign in
RogueStatus
Profile Joined August 2010
266 Posts
August 12 2011 21:33 GMT
#314
On August 13 2011 06:29 tuho12345 wrote:
what about my facebook account? I use that to sign in

Facebook is going down by the 5th of November anyways. lol
sixfour
Profile Blog Joined December 2009
England11061 Posts
August 12 2011 21:38 GMT
#315
wow, i'm sure glad i don't have a gomtv account
p: stats, horang2, free, jangbi z: soulkey, zero, shine, hydra t: leta, hiya, sea
L3g3nd_
Profile Joined July 2010
New Zealand10461 Posts
August 12 2011 21:41 GMT
#316
probably about time i change my pass words. good job gom, good job.
https://twitter.com/#!/IrisAnother
grobo
Profile Blog Joined February 2007
Japan6199 Posts
August 12 2011 21:41 GMT
#317
Thanks GOM, i appreciate you treating my information like shit.

Forget about me paying a single cent to you in the future
We make signature, then defense it.
betaV1.25
Profile Joined April 2010
425 Posts
August 12 2011 21:43 GMT
#318
Amateur night at gom.tv.

-plain text pswrds
-no communication
-no taking down and fixing the site

At the very least dissapointing
Infenwe
Profile Joined September 2009
Denmark170 Posts
Last Edited: 2011-08-12 21:50:54
August 12 2011 21:48 GMT
#319
Instantly deleted account over this. If they are so fucking incompetent that they store password in plaintext and they don't even have the common decency to communicate about it, then they're not to be trusted with anything any more.

Bye, GOM.

Now off to fix stuff...
close the world - txen eht nepo
MicroTastiC
Profile Joined January 2011
375 Posts
Last Edited: 2011-08-12 21:50:29
August 12 2011 21:50 GMT
#320
such a shame that GOMtv would spend more time preventing their content being leaked rather than securing their clients personal information as well!
Wihl
Profile Blog Joined June 2010
Sweden472 Posts
August 12 2011 21:50 GMT
#321
Oh my... I have 3-4 passwords I rotate between depending on how important the data is (from 7 letters to 40 depending on the importance) but I still use the password I had on gomtv for a lot of stuff... Sigh, its gonna take a while to fix all of this. Thank you GOM for storing our personal info in plain text. Retarded.
hugman
Profile Joined June 2009
Sweden4644 Posts
August 12 2011 21:51 GMT
#322
I use junk emails and passwords for almost anything so worst case someone steals a random forum account somewhere ~ohnoes~

Thanks for the heads up
lim1017
Profile Joined April 2010
Canada1278 Posts
August 12 2011 21:51 GMT
#323
why isnt there anything about this on their site warning people?...
LambtrOn
Profile Blog Joined September 2010
United States671 Posts
August 12 2011 21:56 GMT
#324
This is a good wake up call. Just changed a bunch of my passwords.
dudecrush
Profile Joined August 2010
Canada418 Posts
August 12 2011 21:57 GMT
#325
The proverbial ball has been dropped...
Titorelli
Profile Joined March 2011
2492 Posts
August 12 2011 21:59 GMT
#326
Guys... it is 7h on a saturday in Korea.... they dont have an emergency anti hacking team that informs ppl on their site
"Everybody poops.... after Tasteless kills them" Artosis
DarkEnergy
Profile Joined June 2011
Netherlands542 Posts
August 12 2011 22:00 GMT
#327
i knew it was a mistake singing up there QQ
Thats right stimmed marines can outrun aeroplanes.Tasteless
FallDownMarigold
Profile Blog Joined December 2010
United States3710 Posts
Last Edited: 2011-08-12 22:03:23
August 12 2011 22:02 GMT
#328
On August 13 2011 06:59 Titorelli wrote:
Guys... it is 7h on a saturday in Korea.... they dont have an emergency anti hacking team that informs ppl on their site


BUT ITS PRIMETIME IN 'MURICA so I fully expect the world to bend over backwards to do everything in favor of what's best for 'MURICA.

just kidding but yeah you make a very reasonable point.

p.s. those of us that are socially-savvy and use facebook to sign in have nothing to worry about, right? (jk about the social savvy part)
jdelator
Profile Blog Joined September 2007
United States89 Posts
August 12 2011 22:03 GMT
#329
How did you independently verify this info R1CH?
Badgesc
Profile Blog Joined February 2011
France111 Posts
August 12 2011 22:05 GMT
#330
Why are you guys complaining about GOM not doing anything yet ? As far as I know it was known at 3 am KST...
Chanuk
Profile Joined March 2011
Germany13 Posts
Last Edited: 2011-08-12 22:08:04
August 12 2011 22:07 GMT
#331
Thanks for the quick info! I just installed Keepass and going to change all my passwords now.

Good job R1CH / TL
vivere militare est
Sabu113
Profile Blog Joined August 2009
United States11075 Posts
August 12 2011 22:08 GMT
#332
Should have always known to be wary of Gom. Wealth of an operation probably influences the level of security.
Biomine is a drunken chick who is on industrial strength amphetamines and would just grab your dick and jerk it as hard and violently as she could while screaming 'OMG FUCK ME', because she saw it in a Sasha Grey video ...-Wombat_Ni
Titorelli
Profile Joined March 2011
2492 Posts
August 12 2011 22:10 GMT
#333
Yeah about Keepass... I dont get it. It saves all my passwords and it is itself password protected. But if someone gets that password its the same as having one password for all my accounts lol cause he can just look all of them up in Keepass?
"Everybody poops.... after Tasteless kills them" Artosis
Clearout
Profile Blog Joined April 2010
Norway1060 Posts
August 12 2011 22:10 GMT
#334
Thanks for letting me know. I'm an idiot enough to have the same email and pass on both gom and paypal.
really?
FinnGamer
Profile Blog Joined December 2010
Germany2426 Posts
August 12 2011 22:11 GMT
#335
Good to know , luckily I used twitter to sign in, sucks for GOM though, did this happen to the korean website too?
"hopefully swing the favor in your advantage." - Day[9]
Glowbox
Profile Joined June 2010
Netherlands330 Posts
Last Edited: 2011-08-12 22:26:46
August 12 2011 22:16 GMT
#336
On August 13 2011 07:10 Titorelli wrote:
Yeah about Keepass... I dont get it. It saves all my passwords and it is itself password protected. But if someone gets that password its the same as having one password for all my accounts lol cause he can just look all of them up in Keepass?


But how will he get that password? If you are keylogged you are compromised either way. Now if only your GOMtv pass gets hacked everything else is still secure. Of course you could remember each password ....

edit: also plenty o tips to make it more secure (for example: http://www.geeksengine.com/article/keepass-8.html)
CrazyCow
Profile Joined August 2010
United States308 Posts
August 12 2011 22:16 GMT
#337
Wow, that sucks. Luckily my password for most sites is the one that they randomly assign when you say you forgot your password.
CAPSLOCKED
Profile Joined April 2011
563 Posts
August 12 2011 22:19 GMT
#338
Ouch, suddenly really happy it wouldn't let me sign up with my main gmail account and forced me to make some throw-away yahoo account
kwaky
Profile Joined October 2010
Korea (South)94 Posts
August 12 2011 22:29 GMT
#339
Can someone explain to me why I have to change my password to accounts the hacker doesn't know about? If my GomTV password was pass1234 and I used this password for my teamliquid account, why should I change my teamliquid password? The guy who has my GomTV info doesn't know I browse teamliquid, and even if he did, he doesn't know my TL login name. (teamliquid in this case is just an example)

Of course it is recommended to change passwords to everything to be safe, but technically there is no reason to change any passwords, right? (except for your e-mail, granted you use the same password)
Razuik
Profile Joined October 2010
United States409 Posts
August 12 2011 22:33 GMT
#340
On August 13 2011 07:29 kwaky wrote:
Can someone explain to me why I have to change my password to accounts the hacker doesn't know about? If my GomTV password was pass1234 and I used this password for my teamliquid account, why should I change my teamliquid password? The guy who has my GomTV info doesn't know I browse teamliquid, and even if he did, he doesn't know my TL login name. (teamliquid in this case is just an example)

Of course it is recommended to change passwords to everything to be safe, but technically there is no reason to change any passwords, right? (except for your e-mail, granted you use the same password)

Chances are most people use the same email for GOM as they do for Battle.net. Now do most people play SC2 and watch GSL? Also, a lot of people keep the same password for both.
Resistentialism
Profile Blog Joined October 2010
Canada688 Posts
August 12 2011 22:33 GMT
#341
On August 13 2011 07:29 kwaky wrote:
Can someone explain to me why I have to change my password to accounts the hacker doesn't know about? If my GomTV password was pass1234 and I used this password for my teamliquid account, why should I change my teamliquid password? The guy who has my GomTV info doesn't know I browse teamliquid, and even if he did, he doesn't know my TL login name. (teamliquid in this case is just an example)

Of course it is recommended to change passwords to everything to be safe, but technically there is no reason to change any passwords, right? (except for your e-mail, granted you use the same password)


You use the same password but a different username on different sites?

Why not do it the other way around, then, and be a touch safer?
kwaky
Profile Joined October 2010
Korea (South)94 Posts
Last Edited: 2011-08-12 22:47:27
August 12 2011 22:40 GMT
#342
On August 13 2011 07:33 Razuik wrote:
Chances are most people use the same email for GOM as they do for Battle.net. Now do most people play SC2 and watch GSL? Also, a lot of people keep the same password for both.


Yeah I understand the e-mail part.

On August 13 2011 07:33 Resistentialism wrote:
You use the same password but a different username on different sites?

Why not do it the other way around, then, and be a touch safer?


My post was just an example. (and as a matter of fact most of my usernames and passwords are different for each site)

I guess my post was more of a rhetorical question. Also if people use the same login/password for a lot of things, it makes sense to change your info.

Sorry it was my fault I assumed EVERYONE used different logins/passwords. D'oh. It definitely is better to be safe than sorry though!
Enki
Profile Blog Joined January 2007
United States2548 Posts
August 12 2011 22:42 GMT
#343
I heard their stored all the passwords in plain text, just like Sony did. Fucking incompetent.
"Practice, practice, practice. And when you're not practicing you should be practicing. It's the only way to get better. The only way." I run the Smix Fanclub!
ravemir
Profile Joined April 2011
Portugal595 Posts
August 12 2011 22:42 GMT
#344
On August 13 2011 07:33 Resistentialism wrote:
Show nested quote +
On August 13 2011 07:29 kwaky wrote:
Can someone explain to me why I have to change my password to accounts the hacker doesn't know about? If my GomTV password was pass1234 and I used this password for my teamliquid account, why should I change my teamliquid password? The guy who has my GomTV info doesn't know I browse teamliquid, and even if he did, he doesn't know my TL login name. (teamliquid in this case is just an example)

Of course it is recommended to change passwords to everything to be safe, but technically there is no reason to change any passwords, right? (except for your e-mail, granted you use the same password)


You use the same password but a different username on different sites?

Why not do it the other way around, then, and be a touch safer?


Also, you'd be suprised the ammount of information that can gathered about you just by knowing your e-mail, as it's a very insecure protocol.
"more gg, more skill"
Lord_J
Profile Joined April 2011
Kenya1085 Posts
August 12 2011 22:44 GMT
#345
Eh, that's pretty sloppy, but in my case there's nothing of value that can be compromised with any of that information.
No relation to Monsieur J.
rasnj
Profile Joined May 2010
United States1959 Posts
August 12 2011 22:44 GMT
#346
On August 13 2011 07:40 kwaky wrote:
Show nested quote +
On August 13 2011 07:33 Resistentialism wrote:
On August 13 2011 07:29 kwaky wrote:
Can someone explain to me why I have to change my password to accounts the hacker doesn't know about? If my GomTV password was pass1234 and I used this password for my teamliquid account, why should I change my teamliquid password? The guy who has my GomTV info doesn't know I browse teamliquid, and even if he did, he doesn't know my TL login name. (teamliquid in this case is just an example)

Of course it is recommended to change passwords to everything to be safe, but technically there is no reason to change any passwords, right? (except for your e-mail, granted you use the same password)


You use the same password but a different username on different sites?

Why not do it the other way around, then, and be a touch safer?


My post was just an example. (and as a matter of fact most of my usernames and passwords are different for each site) I guess my post was more of a rhetorical question.

For most people a search for their gom username and their e-mail yields further information about them and usually enough information to find more accounts. Unless attackers specifically target you, then as long as your e-mail, paypal and battle.net passwords are different then you are not likely to be attacked IMO, but rather safe than sorry. Especially when it doesn't take much to be safe.
Day[9]
Profile Blog Joined April 2003
United States7366 Posts
August 12 2011 22:49 GMT
#347
Anyone know WHEN the passwords were hacked? I changed my pw about a week or two ago >.<. I'm hoping it was VERY recent, as that would save me a shitton of headaches.
Whenever I encounter some little hitch, or some of my orbs get out of orbit, nothing pleases me so much as to make the crooked straight and crush down uneven places. www.day9.tv
Javah
Profile Joined August 2010
France739 Posts
Last Edited: 2011-08-12 22:51:55
August 12 2011 22:49 GMT
#348
Just changed my GOMtv password (and I'll probably do it again once GOM confirms it's safe). Good thing I didn't use this password anywhere else.

Edit : OMG I just posted with Day[9] ♥♥ (browsing TL between Battle.net Invit matchs :D )
⚀⚅
mprs
Profile Joined April 2010
Canada2933 Posts
Last Edited: 2011-08-12 22:55:07
August 12 2011 22:52 GMT
#349
On August 13 2011 07:49 Day[9] wrote:
Anyone know WHEN the passwords were hacked? I changed my pw about a week or two ago >.<. I'm hoping it was VERY recent, as that would save me a shitton of headaches.


Well the exploit, I am assuming, has been around since the beginning. So while this particular case was made public now, it could have happened yesterday, the day before, the year before, or again 10 minutes ago.
We talkin about PRACTICE
CaptainTwig
Profile Joined August 2010
United Kingdom532 Posts
August 12 2011 22:53 GMT
#350
On August 13 2011 07:49 Day[9] wrote:
Anyone know WHEN the passwords were hacked? I changed my pw about a week or two ago >.<. I'm hoping it was VERY recent, as that would save me a shitton of headaches.


Seems no one has that info at the moment.
Nightrage
Profile Joined October 2010
Greece212 Posts
August 12 2011 22:53 GMT
#351
I changed my password just in case. Thanks for the warning!
It ain't easy being cheesy
rofa
Profile Joined July 2011
United States6 Posts
August 12 2011 22:54 GMT
#352
from what i understand, mprs is correct. the exploit has been around for awhile but has only been made public now so it could have happened any time. the fact that certain accounts were suddenly misused and hacked doesn't give hard evidence as to when the breach actually took place. we'll probably have to wait for GOMs statement for that
Kr1pos
Profile Joined January 2008
Norway67 Posts
August 12 2011 22:55 GMT
#353
No one should assume anything about when it was hacked/cracked. It's lucky we even know about it as if the user hadn't posted the screenshot no-one would be the wiser. Also, we can't know no one already used the same exploit he did previously.

Anyone who used the same password on GOMTV elsewhere should change it immediatly.
DeepBlu2
Profile Blog Joined April 2004
United States975 Posts
Last Edited: 2011-08-12 22:58:49
August 12 2011 22:57 GMT
#354
On August 13 2011 07:49 Day[9] wrote:
Anyone know WHEN the passwords were hacked? I changed my pw about a week or two ago >.<. I'm hoping it was VERY recent, as that would save me a shitton of headaches.



There isn't a way of telling. The only thing to go off was the post of the image, which was very, very recent. However, this could have happened weeks, possibly months ago, and gone unnoticed. I would take the extra precaution if I were you, but you don't have to worry about any financial information unless your paypal password was the same, ofcourse. Check the sent folder in all your emails and make sure no spam mail got sent. That's when you have to start worrying. And Nice Casting at the Invitational!
u gotta sk8
escruting
Profile Joined June 2010
Spain229 Posts
Last Edited: 2011-08-12 22:58:30
August 12 2011 22:58 GMT
#355
Do we know if this has been solved? Until we dont know it has been solved its meaningless to change the password.
My Life for Aiur
ApBuLLet
Profile Joined September 2010
United States604 Posts
August 12 2011 22:58 GMT
#356
On August 13 2011 07:29 kwaky wrote:
Can someone explain to me why I have to change my password to accounts the hacker doesn't know about? If my GomTV password was pass1234 and I used this password for my teamliquid account, why should I change my teamliquid password? The guy who has my GomTV info doesn't know I browse teamliquid, and even if he did, he doesn't know my TL login name. (teamliquid in this case is just an example)

Of course it is recommended to change passwords to everything to be safe, but technically there is no reason to change any passwords, right? (except for your e-mail, granted you use the same password)


There is a good chance that the information was stolen for a reason and that whoever did it will be looking to use the information in a specific way. I don't think it would be for credit card numbers etc, because as R1CH said, all transactions on gomtv.net are done through paypal. Personally, I use the same email for gomtv.net and my battle.net account, and I am sure I am not alone. If you also use the same password for both accounts, your battle.net account can be compromised as well (and your email for that matter). With such access to your personal information, somebody who knows what they're looking for can find a lot of information about you and probably get whatever they are looking for, whether it be credit card numbers or whatever.

I don't know if this is related in any way, but I received an email this morning from Blizzard saying they were investigated my battle.net account because they suspect that I have been trying to sell my World of WarCraft account (which has been inactive for months, as in I am not paying for it and cannot play the game). I received this email literally within an hour after reading this thread about GOM being compromised, and I am also on a very new computer which I am very careful with as far as viruses etc. Nor have I been trying to sell my somewhat worthless WoW account... which is also on the same battle.net account as my SC2, lol.

These incidents may be unrelated, I am not sure yet and I'm waiting for Blizzard to give me more information on the situation (which they probably won't). However, my point is that there are ways for people to hurt you even with limited information, unless you are very good about keeping yourself secure by using many different usernames, passwords, and email addresses, for your accounts on battle.net, websites you use, etc.
Incanus
Profile Joined October 2009
Canada695 Posts
August 12 2011 22:58 GMT
#357
On August 13 2011 06:08 Integra wrote:
what, they used plain text to store the password....... WTF, encryption is a build in feature in PHP and there existst thousands of professionally made salt functions out there. WHY are people so dammn retarded when it comes to security!

Stupider than not encrypting your passwords is allowing SQL injection in the first place.

Ok, same level of stupidity.
Flash: "Why am I so good?" *sob sob*
Vinski
Profile Joined November 2010
505 Posts
August 12 2011 22:59 GMT
#358
Man I hope this isn't why I couldn't sign into my e-mail and have to change my password because of account lock.
"Sound is in a bad marriage, instead of divorcing her and keeping half your shit, he just committed suicide"
BadBinky
Profile Blog Joined May 2004
Finland649 Posts
August 12 2011 23:01 GMT
#359
On August 13 2011 07:58 ApBuLLet wrote:
Show nested quote +
On August 13 2011 07:29 kwaky wrote:
Can someone explain to me why I have to change my password to accounts the hacker doesn't know about? If my GomTV password was pass1234 and I used this password for my teamliquid account, why should I change my teamliquid password? The guy who has my GomTV info doesn't know I browse teamliquid, and even if he did, he doesn't know my TL login name. (teamliquid in this case is just an example)

Of course it is recommended to change passwords to everything to be safe, but technically there is no reason to change any passwords, right? (except for your e-mail, granted you use the same password)


There is a good chance that the information was stolen for a reason and that whoever did it will be looking to use the information in a specific way. I don't think it would be for credit card numbers etc, because as R1CH said, all transactions on gomtv.net are done through paypal. Personally, I use the same email for gomtv.net and my battle.net account, and I am sure I am not alone. If you also use the same password for both accounts, your battle.net account can be compromised as well (and your email for that matter). With such access to your personal information, somebody who knows what they're looking for can find a lot of information about you and probably get whatever they are looking for, whether it be credit card numbers or whatever.

I don't know if this is related in any way, but I received an email this morning from Blizzard saying they were investigated my battle.net account because they suspect that I have been trying to sell my World of WarCraft account (which has been inactive for months, as in I am not paying for it and cannot play the game). I received this email literally within an hour after reading this thread about GOM being compromised, and I am also on a very new computer which I am very careful with as far as viruses etc. Nor have I been trying to sell my somewhat worthless WoW account... which is also on the same battle.net account as my SC2, lol.

These incidents may be unrelated, I am not sure yet and I'm waiting for Blizzard to give me more information on the situation (which they probably won't). However, my point is that there are ways for people to hurt you even with limited information, unless you are very good about keeping yourself secure by using many different usernames, passwords, and email addresses, for your accounts on battle.net, websites you use, etc.


The blizzard mail is fake.
It's more important to be tough than to have any fun.
Jiddra
Profile Joined October 2010
Sweden2685 Posts
August 12 2011 23:02 GMT
#360
How a site with money transactions can have such bad safety is strange. Passwords in plain text is so 1992.

Have a unigue password for gom, that is now changed. Have gom said anything about the new password being safe, or is it stored in the same idiotic way?

I am not young enough to know everything.
Lansky
Profile Joined June 2010
44 Posts
August 12 2011 23:04 GMT
#361
Oh ffs. I don't use the password for anything else that really matters but OCD is still gonna make me go change them anyway. Plain text? Really GOM?


I'd recommend this thread be spot lighted if I knew how to do so any other way than by typing this.
Barbiero
Profile Blog Joined September 2010
Brazil5259 Posts
August 12 2011 23:04 GMT
#362
Lol thank god the email I use for GOM is completely unique, and its not possible to get another account out of it :D

Either way, changed the passwords just in case.
♥ The world needs more hearts! ♥
ApBuLLet
Profile Joined September 2010
United States604 Posts
August 12 2011 23:04 GMT
#363
On August 13 2011 08:01 BadBinky wrote:
Show nested quote +
On August 13 2011 07:58 ApBuLLet wrote:
On August 13 2011 07:29 kwaky wrote:
Can someone explain to me why I have to change my password to accounts the hacker doesn't know about? If my GomTV password was pass1234 and I used this password for my teamliquid account, why should I change my teamliquid password? The guy who has my GomTV info doesn't know I browse teamliquid, and even if he did, he doesn't know my TL login name. (teamliquid in this case is just an example)

Of course it is recommended to change passwords to everything to be safe, but technically there is no reason to change any passwords, right? (except for your e-mail, granted you use the same password)


There is a good chance that the information was stolen for a reason and that whoever did it will be looking to use the information in a specific way. I don't think it would be for credit card numbers etc, because as R1CH said, all transactions on gomtv.net are done through paypal. Personally, I use the same email for gomtv.net and my battle.net account, and I am sure I am not alone. If you also use the same password for both accounts, your battle.net account can be compromised as well (and your email for that matter). With such access to your personal information, somebody who knows what they're looking for can find a lot of information about you and probably get whatever they are looking for, whether it be credit card numbers or whatever.

I don't know if this is related in any way, but I received an email this morning from Blizzard saying they were investigated my battle.net account because they suspect that I have been trying to sell my World of WarCraft account (which has been inactive for months, as in I am not paying for it and cannot play the game). I received this email literally within an hour after reading this thread about GOM being compromised, and I am also on a very new computer which I am very careful with as far as viruses etc. Nor have I been trying to sell my somewhat worthless WoW account... which is also on the same battle.net account as my SC2, lol.

These incidents may be unrelated, I am not sure yet and I'm waiting for Blizzard to give me more information on the situation (which they probably won't). However, my point is that there are ways for people to hurt you even with limited information, unless you are very good about keeping yourself secure by using many different usernames, passwords, and email addresses, for your accounts on battle.net, websites you use, etc.


The blizzard mail is fake.


No, it is not. It is from a Blizzard email for sure. I would know if it was fake trust me.
Javah
Profile Joined August 2010
France739 Posts
August 12 2011 23:05 GMT
#364
On August 13 2011 08:02 Jiddra wrote:password for gom, that is now changed. Have gom said anything about the new password being safe, or is it stored in the same idiotic way?

So far it seems that GOM has not released any statement regarding this compromission. Sun is rising in Korea, so it should not be long before they say something.
⚀⚅
BadBinky
Profile Blog Joined May 2004
Finland649 Posts
August 12 2011 23:05 GMT
#365
On August 13 2011 08:04 ApBuLLet wrote:
Show nested quote +
On August 13 2011 08:01 BadBinky wrote:
On August 13 2011 07:58 ApBuLLet wrote:
On August 13 2011 07:29 kwaky wrote:
Can someone explain to me why I have to change my password to accounts the hacker doesn't know about? If my GomTV password was pass1234 and I used this password for my teamliquid account, why should I change my teamliquid password? The guy who has my GomTV info doesn't know I browse teamliquid, and even if he did, he doesn't know my TL login name. (teamliquid in this case is just an example)

Of course it is recommended to change passwords to everything to be safe, but technically there is no reason to change any passwords, right? (except for your e-mail, granted you use the same password)


There is a good chance that the information was stolen for a reason and that whoever did it will be looking to use the information in a specific way. I don't think it would be for credit card numbers etc, because as R1CH said, all transactions on gomtv.net are done through paypal. Personally, I use the same email for gomtv.net and my battle.net account, and I am sure I am not alone. If you also use the same password for both accounts, your battle.net account can be compromised as well (and your email for that matter). With such access to your personal information, somebody who knows what they're looking for can find a lot of information about you and probably get whatever they are looking for, whether it be credit card numbers or whatever.

I don't know if this is related in any way, but I received an email this morning from Blizzard saying they were investigated my battle.net account because they suspect that I have been trying to sell my World of WarCraft account (which has been inactive for months, as in I am not paying for it and cannot play the game). I received this email literally within an hour after reading this thread about GOM being compromised, and I am also on a very new computer which I am very careful with as far as viruses etc. Nor have I been trying to sell my somewhat worthless WoW account... which is also on the same battle.net account as my SC2, lol.

These incidents may be unrelated, I am not sure yet and I'm waiting for Blizzard to give me more information on the situation (which they probably won't). However, my point is that there are ways for people to hurt you even with limited information, unless you are very good about keeping yourself secure by using many different usernames, passwords, and email addresses, for your accounts on battle.net, websites you use, etc.


The blizzard mail is fake.


No, it is not. It is from a Blizzard email for sure. I would know if it was fake trust me.


Whatever click the link or send them some information like they ask then lol.
It's more important to be tough than to have any fun.
Cartel
Profile Joined September 2010
Canada255 Posts
August 12 2011 23:07 GMT
#366
Thanks for the heads up. Keepass is such a cool program starting to use it now.
ApBuLLet
Profile Joined September 2010
United States604 Posts
Last Edited: 2011-08-12 23:08:37
August 12 2011 23:07 GMT
#367
On August 13 2011 08:05 BadBinky wrote:
Show nested quote +
On August 13 2011 08:04 ApBuLLet wrote:
On August 13 2011 08:01 BadBinky wrote:
On August 13 2011 07:58 ApBuLLet wrote:
On August 13 2011 07:29 kwaky wrote:
Can someone explain to me why I have to change my password to accounts the hacker doesn't know about? If my GomTV password was pass1234 and I used this password for my teamliquid account, why should I change my teamliquid password? The guy who has my GomTV info doesn't know I browse teamliquid, and even if he did, he doesn't know my TL login name. (teamliquid in this case is just an example)

Of course it is recommended to change passwords to everything to be safe, but technically there is no reason to change any passwords, right? (except for your e-mail, granted you use the same password)


There is a good chance that the information was stolen for a reason and that whoever did it will be looking to use the information in a specific way. I don't think it would be for credit card numbers etc, because as R1CH said, all transactions on gomtv.net are done through paypal. Personally, I use the same email for gomtv.net and my battle.net account, and I am sure I am not alone. If you also use the same password for both accounts, your battle.net account can be compromised as well (and your email for that matter). With such access to your personal information, somebody who knows what they're looking for can find a lot of information about you and probably get whatever they are looking for, whether it be credit card numbers or whatever.

I don't know if this is related in any way, but I received an email this morning from Blizzard saying they were investigated my battle.net account because they suspect that I have been trying to sell my World of WarCraft account (which has been inactive for months, as in I am not paying for it and cannot play the game). I received this email literally within an hour after reading this thread about GOM being compromised, and I am also on a very new computer which I am very careful with as far as viruses etc. Nor have I been trying to sell my somewhat worthless WoW account... which is also on the same battle.net account as my SC2, lol.

These incidents may be unrelated, I am not sure yet and I'm waiting for Blizzard to give me more information on the situation (which they probably won't). However, my point is that there are ways for people to hurt you even with limited information, unless you are very good about keeping yourself secure by using many different usernames, passwords, and email addresses, for your accounts on battle.net, websites you use, etc.


The blizzard mail is fake.


No, it is not. It is from a Blizzard email for sure. I would know if it was fake trust me.


Whatever click the link or send them some information like they ask then lol.


The link that goes to blizzard's website (us.battle.net)? Yeah, I clicked it. Also the email is from blizzard.com, which if you type that in your search bar you will see, goes straight to blizzards site. They did not ask for any personal information at all. They only notified me of the situation and that is it. I'm not stupid.
Jameser
Profile Joined July 2010
Sweden951 Posts
Last Edited: 2011-08-12 23:11:58
August 12 2011 23:09 GMT
#368
between this and the whole PSN thing it's clear that password security is something you only care about to the extent that your customer base believes you are handling it responsibly... pretty retarded as it can potentially have devastating effects on a person.

anyway, maybe this is an eyeopener for the (unfortunately) majority of people who just use an easy to remember password for all sites and logins
bratal1x
Profile Joined April 2011
Australia14 Posts
August 12 2011 23:16 GMT
#369
Thanks for the info R1CH, glad I don't have the same password for other sites that I did on GOM.
warbean
Profile Joined August 2010
United States11 Posts
August 12 2011 23:18 GMT
#370
I also just got this email from Blizzard for my WoW account that has been inactive for 9 months now. Looks like somehow got into my character and got himself banned. I use the same email for GomTv and Battle.net, although I usually sign in through SNS Twitter. Seems to be too much of a coincidence.

+ Show Spoiler +

English speaking customers: Please refer to the start of this mail
Para los clientes españoles: Por favor vayan hasta el fin de este email


***Notice of Account Closure***

Account Name: WARBEAN1

Reason for Closure: Terms of Use Violation -- Exploitative Activity: Abuse of the Economy

This account was closed because one or more characters were identified exchanging, or contributing to the exchange of, in-game property (items or gold) for "real-world" currency. This exchange process negatively impacts the World of Warcraft game environment by detracting from the value of the in-game economy.

Even if this is the result of account sharing, the account owner can still be held responsible for the penalty because of the impact it had on the game environment.

We've found the above behavior is many times directly related to groups responsible for compromising World of Warcraft accounts; we take these issues very seriously. To better understand our position against exploitative activity and the risks involved, please review this article: http://us.blizzard.com/support/article.xml?locale=en_US&articleId=25455

The exploitative activity that took place on this account violates the World of Warcraft Terms of Use. We ask you take a moment to review these terms at http://us.blizzard.com/company/legal/index.html. Note that additional Terms of Use violations may result in more severe actions against this account, up to and including permanent closure.

If you believe your account was compromised, please submit an in-game petition or fill the contact email form at http://us.blizzard.com/support/webform.xml?locale=en_US. Our support staff will assist you as soon as possible. If you are unable to access your account due to the password being changed, please visit our Login Support site here: https://us.battle.net/account/support/password-reset.html

For any disputes of this action or further information on Exploitive Activity, please visit the Exploitative Activity FAQ and contact page here: http://us.blizzard.com/support/article/exploitfaq

Regards,

Customer Services
Blizzard Entertainment
http://us.battle.net/wow/en/
-------------------------------------------------------


***Notificación de Clausura de Cuenta***

Nombre de Cuenta: WARBEAN1

Razón por la Clausura: Violación de las Condiciones de Uso – Actividad Explotadora: Abuso de la Economía

Esta cuenta fue clausurada porque uno o más personajes se identificaron comerciando, o contribuyendo al comercio de, la propiedad dentro del juego (objetos u oro) por moneda “real.” Este proceso de comercio negativamente impacta al ambiente de World of Warcraft por detraer del valor de la economía dentro del juego.

Aunque esto sea a resultado de la compartición de la cuenta, el dueño de la cuenta aun puede ser responsable por la penalización debido al impacto que tuvo en el ambiente del juego.

Hemos conseguido que el comportamiento superior muchas veces sea directamente relacionado a los grupos responsables por comprometer las cuentas de World of Warcraft; nosotros tomamos estos asuntos muy seriamente. Para mejor entender nuestra posición sobre la actividad explotadora y los riesgos involucrados, por favor revise este artículo: (http://us.blizzard.com/support/article.xml?locale=en_US&articleId=25455).

La actividad explotadora que ocurrió en esta cuenta está en contra de las Condiciones de Uso de World of Warcraft. Le pedimos que se tome un momento para revisar estos términos: (http://us.blizzard.com/company/legal/index.html). Note que cualquier violación adicional de las Condiciones de Uso pueden resultar en más severas medidas en contra de esta cuenta, hasta e incluyendo la clausura permanente.

Si cree que su cuenta haya sido comprometida, por favor abra una petición dentro del juego o llene el formulario de contacto por email: (https://us.blizzard.com/support/webform.xml?locale=es_MX). Nuestro equipo de soporte le asistirá lo más pronto posible. Si no puede acceder a su cuenta debido a un cambio de contraseña, por favor visite nuestro sitio de Asistencia de Ingreso aquí: (https://us.battle.net/account/support/password-reset.html).

Para cualquier disputa sobre esta medida, o para más información sobre la Actividad Explotadora, por favor visite la página de contacto y Preguntas Frecuentes (FAQ) aquí: (http://us.blizzard.com/support/article.xml?locale=es_MX&tag=exploitfaq).

Saludos,

Atención al Cliente
Blizzard Entertainment
http://us.battle.net/wow/es/
Krede
Profile Joined December 2010
Denmark139 Posts
August 12 2011 23:19 GMT
#371
Thx for providing info.

Just redid a lot of my passwords and created a couple of new ones...Even though its not bank details I got a little scared
Here's the thing about bowling: There's not enough maps. There's two maps on bowling. Bumper Map and Dust_2
Integra
Profile Blog Joined January 2008
Sweden5626 Posts
August 12 2011 23:21 GMT
#372
On August 13 2011 08:18 warbean wrote:
I also just got this email from Blizzard for my WoW account that has been inactive for 9 months now. Looks like somehow got into my character and got himself banned. I use the same email for GomTv and Battle.net, although I usually sign in through SNS Twitter. Seems to be too much of a coincidence.

+ Show Spoiler +

English speaking customers: Please refer to the start of this mail
Para los clientes españoles: Por favor vayan hasta el fin de este email


***Notice of Account Closure***

Account Name: WARBEAN1

Reason for Closure: Terms of Use Violation -- Exploitative Activity: Abuse of the Economy

This account was closed because one or more characters were identified exchanging, or contributing to the exchange of, in-game property (items or gold) for "real-world" currency. This exchange process negatively impacts the World of Warcraft game environment by detracting from the value of the in-game economy.

Even if this is the result of account sharing, the account owner can still be held responsible for the penalty because of the impact it had on the game environment.

We've found the above behavior is many times directly related to groups responsible for compromising World of Warcraft accounts; we take these issues very seriously. To better understand our position against exploitative activity and the risks involved, please review this article: http://us.blizzard.com/support/article.xml?locale=en_US&articleId=25455

The exploitative activity that took place on this account violates the World of Warcraft Terms of Use. We ask you take a moment to review these terms at http://us.blizzard.com/company/legal/index.html. Note that additional Terms of Use violations may result in more severe actions against this account, up to and including permanent closure.

If you believe your account was compromised, please submit an in-game petition or fill the contact email form at http://us.blizzard.com/support/webform.xml?locale=en_US. Our support staff will assist you as soon as possible. If you are unable to access your account due to the password being changed, please visit our Login Support site here: https://us.battle.net/account/support/password-reset.html

For any disputes of this action or further information on Exploitive Activity, please visit the Exploitative Activity FAQ and contact page here: http://us.blizzard.com/support/article/exploitfaq

Regards,

Customer Services
Blizzard Entertainment
http://us.battle.net/wow/en/
-------------------------------------------------------


***Notificación de Clausura de Cuenta***

Nombre de Cuenta: WARBEAN1

Razón por la Clausura: Violación de las Condiciones de Uso – Actividad Explotadora: Abuso de la Economía

Esta cuenta fue clausurada porque uno o más personajes se identificaron comerciando, o contribuyendo al comercio de, la propiedad dentro del juego (objetos u oro) por moneda “real.” Este proceso de comercio negativamente impacta al ambiente de World of Warcraft por detraer del valor de la economía dentro del juego.

Aunque esto sea a resultado de la compartición de la cuenta, el dueño de la cuenta aun puede ser responsable por la penalización debido al impacto que tuvo en el ambiente del juego.

Hemos conseguido que el comportamiento superior muchas veces sea directamente relacionado a los grupos responsables por comprometer las cuentas de World of Warcraft; nosotros tomamos estos asuntos muy seriamente. Para mejor entender nuestra posición sobre la actividad explotadora y los riesgos involucrados, por favor revise este artículo: (http://us.blizzard.com/support/article.xml?locale=en_US&articleId=25455).

La actividad explotadora que ocurrió en esta cuenta está en contra de las Condiciones de Uso de World of Warcraft. Le pedimos que se tome un momento para revisar estos términos: (http://us.blizzard.com/company/legal/index.html). Note que cualquier violación adicional de las Condiciones de Uso pueden resultar en más severas medidas en contra de esta cuenta, hasta e incluyendo la clausura permanente.

Si cree que su cuenta haya sido comprometida, por favor abra una petición dentro del juego o llene el formulario de contacto por email: (https://us.blizzard.com/support/webform.xml?locale=es_MX). Nuestro equipo de soporte le asistirá lo más pronto posible. Si no puede acceder a su cuenta debido a un cambio de contraseña, por favor visite nuestro sitio de Asistencia de Ingreso aquí: (https://us.battle.net/account/support/password-reset.html).

Para cualquier disputa sobre esta medida, o para más información sobre la Actividad Explotadora, por favor visite la página de contacto y Preguntas Frecuentes (FAQ) aquí: (http://us.blizzard.com/support/article.xml?locale=es_MX&tag=exploitfaq).

Saludos,

Atención al Cliente
Blizzard Entertainment
http://us.battle.net/wow/es/


I've just recieved emails, note not email but EMAILS from Blizz as well. They all seem to be fake though. they are all claiming various stuff, like I have to give away my bank account info to prove that i am the holder of the wow account etc. My information has been leaked, that's for sure.
"Dark Pleasure" | | I survived the Locust war of May 3, 2014
Krede
Profile Joined December 2010
Denmark139 Posts
August 12 2011 23:25 GMT
#373
On August 13 2011 08:21 Integra wrote:
Show nested quote +
On August 13 2011 08:18 warbean wrote:
I also just got this email from Blizzard for my WoW account that has been inactive for 9 months now. Looks like somehow got into my character and got himself banned. I use the same email for GomTv and Battle.net, although I usually sign in through SNS Twitter. Seems to be too much of a coincidence.

+ Show Spoiler +

English speaking customers: Please refer to the start of this mail
Para los clientes españoles: Por favor vayan hasta el fin de este email


***Notice of Account Closure***

Account Name: WARBEAN1

Reason for Closure: Terms of Use Violation -- Exploitative Activity: Abuse of the Economy

This account was closed because one or more characters were identified exchanging, or contributing to the exchange of, in-game property (items or gold) for "real-world" currency. This exchange process negatively impacts the World of Warcraft game environment by detracting from the value of the in-game economy.

Even if this is the result of account sharing, the account owner can still be held responsible for the penalty because of the impact it had on the game environment.

We've found the above behavior is many times directly related to groups responsible for compromising World of Warcraft accounts; we take these issues very seriously. To better understand our position against exploitative activity and the risks involved, please review this article: http://us.blizzard.com/support/article.xml?locale=en_US&articleId=25455

The exploitative activity that took place on this account violates the World of Warcraft Terms of Use. We ask you take a moment to review these terms at http://us.blizzard.com/company/legal/index.html. Note that additional Terms of Use violations may result in more severe actions against this account, up to and including permanent closure.

If you believe your account was compromised, please submit an in-game petition or fill the contact email form at http://us.blizzard.com/support/webform.xml?locale=en_US. Our support staff will assist you as soon as possible. If you are unable to access your account due to the password being changed, please visit our Login Support site here: https://us.battle.net/account/support/password-reset.html

For any disputes of this action or further information on Exploitive Activity, please visit the Exploitative Activity FAQ and contact page here: http://us.blizzard.com/support/article/exploitfaq

Regards,

Customer Services
Blizzard Entertainment
http://us.battle.net/wow/en/
-------------------------------------------------------


***Notificación de Clausura de Cuenta***

Nombre de Cuenta: WARBEAN1

Razón por la Clausura: Violación de las Condiciones de Uso – Actividad Explotadora: Abuso de la Economía

Esta cuenta fue clausurada porque uno o más personajes se identificaron comerciando, o contribuyendo al comercio de, la propiedad dentro del juego (objetos u oro) por moneda “real.” Este proceso de comercio negativamente impacta al ambiente de World of Warcraft por detraer del valor de la economía dentro del juego.

Aunque esto sea a resultado de la compartición de la cuenta, el dueño de la cuenta aun puede ser responsable por la penalización debido al impacto que tuvo en el ambiente del juego.

Hemos conseguido que el comportamiento superior muchas veces sea directamente relacionado a los grupos responsables por comprometer las cuentas de World of Warcraft; nosotros tomamos estos asuntos muy seriamente. Para mejor entender nuestra posición sobre la actividad explotadora y los riesgos involucrados, por favor revise este artículo: (http://us.blizzard.com/support/article.xml?locale=en_US&articleId=25455).

La actividad explotadora que ocurrió en esta cuenta está en contra de las Condiciones de Uso de World of Warcraft. Le pedimos que se tome un momento para revisar estos términos: (http://us.blizzard.com/company/legal/index.html). Note que cualquier violación adicional de las Condiciones de Uso pueden resultar en más severas medidas en contra de esta cuenta, hasta e incluyendo la clausura permanente.

Si cree que su cuenta haya sido comprometida, por favor abra una petición dentro del juego o llene el formulario de contacto por email: (https://us.blizzard.com/support/webform.xml?locale=es_MX). Nuestro equipo de soporte le asistirá lo más pronto posible. Si no puede acceder a su cuenta debido a un cambio de contraseña, por favor visite nuestro sitio de Asistencia de Ingreso aquí: (https://us.battle.net/account/support/password-reset.html).

Para cualquier disputa sobre esta medida, o para más información sobre la Actividad Explotadora, por favor visite la página de contacto y Preguntas Frecuentes (FAQ) aquí: (http://us.blizzard.com/support/article.xml?locale=es_MX&tag=exploitfaq).

Saludos,

Atención al Cliente
Blizzard Entertainment
http://us.battle.net/wow/es/


I've just recieved emails, note not email but EMAILS from Blizz as well. They all seem to be fake though. they are all claiming various stuff, like I have to give away my bank account info to prove that i am the holder of the wow account etc. My information has been leaked, that's for sure.


This. This is why GOM should be ashamed of them selves for not protecting our info
Here's the thing about bowling: There's not enough maps. There's two maps on bowling. Bumper Map and Dust_2
Goldfish
Profile Blog Joined August 2010
2230 Posts
Last Edited: 2011-08-12 23:26:16
August 12 2011 23:25 GMT
#374
Anyone know how hackers got into GOMtv.net? I'm sort of a nub at this but is it because they use outdated software (I know some forums may still use real old versions of invisionboard or w/e for example which may have security exploits) or because something GOM didn't do?

Basically how do websites protect themselves from getting hacked (well at least easily hacked) and how did GOM get hacked? Just curious.
https://connect.microsoft.com/WindowsServerFeedback/feedback/details/741495/biggest-explorer-annoyance-automatic-sorting-windows-7-server-2008-r2-and-vista#details Allow Disable Auto Arrange in Windows 7+
Antoine
Profile Blog Joined May 2010
United States7481 Posts
August 12 2011 23:26 GMT
#375
On August 13 2011 08:21 Integra wrote:
Show nested quote +
On August 13 2011 08:18 warbean wrote:
I also just got this email from Blizzard for my WoW account that has been inactive for 9 months now. Looks like somehow got into my character and got himself banned. I use the same email for GomTv and Battle.net, although I usually sign in through SNS Twitter. Seems to be too much of a coincidence.

+ Show Spoiler +

English speaking customers: Please refer to the start of this mail
Para los clientes españoles: Por favor vayan hasta el fin de este email


***Notice of Account Closure***

Account Name: WARBEAN1

Reason for Closure: Terms of Use Violation -- Exploitative Activity: Abuse of the Economy

This account was closed because one or more characters were identified exchanging, or contributing to the exchange of, in-game property (items or gold) for "real-world" currency. This exchange process negatively impacts the World of Warcraft game environment by detracting from the value of the in-game economy.

Even if this is the result of account sharing, the account owner can still be held responsible for the penalty because of the impact it had on the game environment.

We've found the above behavior is many times directly related to groups responsible for compromising World of Warcraft accounts; we take these issues very seriously. To better understand our position against exploitative activity and the risks involved, please review this article: http://us.blizzard.com/support/article.xml?locale=en_US&articleId=25455

The exploitative activity that took place on this account violates the World of Warcraft Terms of Use. We ask you take a moment to review these terms at http://us.blizzard.com/company/legal/index.html. Note that additional Terms of Use violations may result in more severe actions against this account, up to and including permanent closure.

If you believe your account was compromised, please submit an in-game petition or fill the contact email form at http://us.blizzard.com/support/webform.xml?locale=en_US. Our support staff will assist you as soon as possible. If you are unable to access your account due to the password being changed, please visit our Login Support site here: https://us.battle.net/account/support/password-reset.html

For any disputes of this action or further information on Exploitive Activity, please visit the Exploitative Activity FAQ and contact page here: http://us.blizzard.com/support/article/exploitfaq

Regards,

Customer Services
Blizzard Entertainment
http://us.battle.net/wow/en/
-------------------------------------------------------


***Notificación de Clausura de Cuenta***

Nombre de Cuenta: WARBEAN1

Razón por la Clausura: Violación de las Condiciones de Uso – Actividad Explotadora: Abuso de la Economía

Esta cuenta fue clausurada porque uno o más personajes se identificaron comerciando, o contribuyendo al comercio de, la propiedad dentro del juego (objetos u oro) por moneda “real.” Este proceso de comercio negativamente impacta al ambiente de World of Warcraft por detraer del valor de la economía dentro del juego.

Aunque esto sea a resultado de la compartición de la cuenta, el dueño de la cuenta aun puede ser responsable por la penalización debido al impacto que tuvo en el ambiente del juego.

Hemos conseguido que el comportamiento superior muchas veces sea directamente relacionado a los grupos responsables por comprometer las cuentas de World of Warcraft; nosotros tomamos estos asuntos muy seriamente. Para mejor entender nuestra posición sobre la actividad explotadora y los riesgos involucrados, por favor revise este artículo: (http://us.blizzard.com/support/article.xml?locale=en_US&articleId=25455).

La actividad explotadora que ocurrió en esta cuenta está en contra de las Condiciones de Uso de World of Warcraft. Le pedimos que se tome un momento para revisar estos términos: (http://us.blizzard.com/company/legal/index.html). Note que cualquier violación adicional de las Condiciones de Uso pueden resultar en más severas medidas en contra de esta cuenta, hasta e incluyendo la clausura permanente.

Si cree que su cuenta haya sido comprometida, por favor abra una petición dentro del juego o llene el formulario de contacto por email: (https://us.blizzard.com/support/webform.xml?locale=es_MX). Nuestro equipo de soporte le asistirá lo más pronto posible. Si no puede acceder a su cuenta debido a un cambio de contraseña, por favor visite nuestro sitio de Asistencia de Ingreso aquí: (https://us.battle.net/account/support/password-reset.html).

Para cualquier disputa sobre esta medida, o para más información sobre la Actividad Explotadora, por favor visite la página de contacto y Preguntas Frecuentes (FAQ) aquí: (http://us.blizzard.com/support/article.xml?locale=es_MX&tag=exploitfaq).

Saludos,

Atención al Cliente
Blizzard Entertainment
http://us.battle.net/wow/es/


I've just recieved emails, note not email but EMAILS from Blizz as well. They all seem to be fake though. they are all claiming various stuff, like I have to give away my bank account info to prove that i am the holder of the wow account etc. My information has been leaked, that's for sure.

i would say you've probably gotten these emails a lot longer than 1 day, i've had them slamming my spambox for like 5 years now
ModeratorFlash Sea Action Snow Midas | TheStC Ret Tyler MC | RIP 우정호
vyyye
Profile Joined July 2010
Sweden3917 Posts
August 12 2011 23:27 GMT
#376
On August 13 2011 08:26 Antoine wrote:
Show nested quote +
On August 13 2011 08:21 Integra wrote:
On August 13 2011 08:18 warbean wrote:
I also just got this email from Blizzard for my WoW account that has been inactive for 9 months now. Looks like somehow got into my character and got himself banned. I use the same email for GomTv and Battle.net, although I usually sign in through SNS Twitter. Seems to be too much of a coincidence.

+ Show Spoiler +

English speaking customers: Please refer to the start of this mail
Para los clientes españoles: Por favor vayan hasta el fin de este email


***Notice of Account Closure***

Account Name: WARBEAN1

Reason for Closure: Terms of Use Violation -- Exploitative Activity: Abuse of the Economy

This account was closed because one or more characters were identified exchanging, or contributing to the exchange of, in-game property (items or gold) for "real-world" currency. This exchange process negatively impacts the World of Warcraft game environment by detracting from the value of the in-game economy.

Even if this is the result of account sharing, the account owner can still be held responsible for the penalty because of the impact it had on the game environment.

We've found the above behavior is many times directly related to groups responsible for compromising World of Warcraft accounts; we take these issues very seriously. To better understand our position against exploitative activity and the risks involved, please review this article: http://us.blizzard.com/support/article.xml?locale=en_US&articleId=25455

The exploitative activity that took place on this account violates the World of Warcraft Terms of Use. We ask you take a moment to review these terms at http://us.blizzard.com/company/legal/index.html. Note that additional Terms of Use violations may result in more severe actions against this account, up to and including permanent closure.

If you believe your account was compromised, please submit an in-game petition or fill the contact email form at http://us.blizzard.com/support/webform.xml?locale=en_US. Our support staff will assist you as soon as possible. If you are unable to access your account due to the password being changed, please visit our Login Support site here: https://us.battle.net/account/support/password-reset.html

For any disputes of this action or further information on Exploitive Activity, please visit the Exploitative Activity FAQ and contact page here: http://us.blizzard.com/support/article/exploitfaq

Regards,

Customer Services
Blizzard Entertainment
http://us.battle.net/wow/en/
-------------------------------------------------------


***Notificación de Clausura de Cuenta***

Nombre de Cuenta: WARBEAN1

Razón por la Clausura: Violación de las Condiciones de Uso – Actividad Explotadora: Abuso de la Economía

Esta cuenta fue clausurada porque uno o más personajes se identificaron comerciando, o contribuyendo al comercio de, la propiedad dentro del juego (objetos u oro) por moneda “real.” Este proceso de comercio negativamente impacta al ambiente de World of Warcraft por detraer del valor de la economía dentro del juego.

Aunque esto sea a resultado de la compartición de la cuenta, el dueño de la cuenta aun puede ser responsable por la penalización debido al impacto que tuvo en el ambiente del juego.

Hemos conseguido que el comportamiento superior muchas veces sea directamente relacionado a los grupos responsables por comprometer las cuentas de World of Warcraft; nosotros tomamos estos asuntos muy seriamente. Para mejor entender nuestra posición sobre la actividad explotadora y los riesgos involucrados, por favor revise este artículo: (http://us.blizzard.com/support/article.xml?locale=en_US&articleId=25455).

La actividad explotadora que ocurrió en esta cuenta está en contra de las Condiciones de Uso de World of Warcraft. Le pedimos que se tome un momento para revisar estos términos: (http://us.blizzard.com/company/legal/index.html). Note que cualquier violación adicional de las Condiciones de Uso pueden resultar en más severas medidas en contra de esta cuenta, hasta e incluyendo la clausura permanente.

Si cree que su cuenta haya sido comprometida, por favor abra una petición dentro del juego o llene el formulario de contacto por email: (https://us.blizzard.com/support/webform.xml?locale=es_MX). Nuestro equipo de soporte le asistirá lo más pronto posible. Si no puede acceder a su cuenta debido a un cambio de contraseña, por favor visite nuestro sitio de Asistencia de Ingreso aquí: (https://us.battle.net/account/support/password-reset.html).

Para cualquier disputa sobre esta medida, o para más información sobre la Actividad Explotadora, por favor visite la página de contacto y Preguntas Frecuentes (FAQ) aquí: (http://us.blizzard.com/support/article.xml?locale=es_MX&tag=exploitfaq).

Saludos,

Atención al Cliente
Blizzard Entertainment
http://us.battle.net/wow/es/


I've just recieved emails, note not email but EMAILS from Blizz as well. They all seem to be fake though. they are all claiming various stuff, like I have to give away my bank account info to prove that i am the holder of the wow account etc. My information has been leaked, that's for sure.

i would say you've probably gotten these emails a lot longer than 1 day, i've had them slamming my spambox for like 5 years now

Same here, got Cursegaming/curse or whatever they're called these days to thank for that.
ApBuLLet
Profile Joined September 2010
United States604 Posts
August 12 2011 23:27 GMT
#377
On August 13 2011 08:18 warbean wrote:
I also just got this email from Blizzard for my WoW account that has been inactive for 9 months now. Looks like somehow got into my character and got himself banned. I use the same email for GomTv and Battle.net, although I usually sign in through SNS Twitter. Seems to be too much of a coincidence.

+ Show Spoiler +

English speaking customers: Please refer to the start of this mail
Para los clientes españoles: Por favor vayan hasta el fin de este email


***Notice of Account Closure***

Account Name: WARBEAN1

Reason for Closure: Terms of Use Violation -- Exploitative Activity: Abuse of the Economy

This account was closed because one or more characters were identified exchanging, or contributing to the exchange of, in-game property (items or gold) for "real-world" currency. This exchange process negatively impacts the World of Warcraft game environment by detracting from the value of the in-game economy.

Even if this is the result of account sharing, the account owner can still be held responsible for the penalty because of the impact it had on the game environment.

We've found the above behavior is many times directly related to groups responsible for compromising World of Warcraft accounts; we take these issues very seriously. To better understand our position against exploitative activity and the risks involved, please review this article: http://us.blizzard.com/support/article.xml?locale=en_US&articleId=25455

The exploitative activity that took place on this account violates the World of Warcraft Terms of Use. We ask you take a moment to review these terms at http://us.blizzard.com/company/legal/index.html. Note that additional Terms of Use violations may result in more severe actions against this account, up to and including permanent closure.

If you believe your account was compromised, please submit an in-game petition or fill the contact email form at http://us.blizzard.com/support/webform.xml?locale=en_US. Our support staff will assist you as soon as possible. If you are unable to access your account due to the password being changed, please visit our Login Support site here: https://us.battle.net/account/support/password-reset.html

For any disputes of this action or further information on Exploitive Activity, please visit the Exploitative Activity FAQ and contact page here: http://us.blizzard.com/support/article/exploitfaq

Regards,

Customer Services
Blizzard Entertainment
http://us.battle.net/wow/en/
-------------------------------------------------------


***Notificación de Clausura de Cuenta***

Nombre de Cuenta: WARBEAN1

Razón por la Clausura: Violación de las Condiciones de Uso – Actividad Explotadora: Abuso de la Economía

Esta cuenta fue clausurada porque uno o más personajes se identificaron comerciando, o contribuyendo al comercio de, la propiedad dentro del juego (objetos u oro) por moneda “real.” Este proceso de comercio negativamente impacta al ambiente de World of Warcraft por detraer del valor de la economía dentro del juego.

Aunque esto sea a resultado de la compartición de la cuenta, el dueño de la cuenta aun puede ser responsable por la penalización debido al impacto que tuvo en el ambiente del juego.

Hemos conseguido que el comportamiento superior muchas veces sea directamente relacionado a los grupos responsables por comprometer las cuentas de World of Warcraft; nosotros tomamos estos asuntos muy seriamente. Para mejor entender nuestra posición sobre la actividad explotadora y los riesgos involucrados, por favor revise este artículo: (http://us.blizzard.com/support/article.xml?locale=en_US&articleId=25455).

La actividad explotadora que ocurrió en esta cuenta está en contra de las Condiciones de Uso de World of Warcraft. Le pedimos que se tome un momento para revisar estos términos: (http://us.blizzard.com/company/legal/index.html). Note que cualquier violación adicional de las Condiciones de Uso pueden resultar en más severas medidas en contra de esta cuenta, hasta e incluyendo la clausura permanente.

Si cree que su cuenta haya sido comprometida, por favor abra una petición dentro del juego o llene el formulario de contacto por email: (https://us.blizzard.com/support/webform.xml?locale=es_MX). Nuestro equipo de soporte le asistirá lo más pronto posible. Si no puede acceder a su cuenta debido a un cambio de contraseña, por favor visite nuestro sitio de Asistencia de Ingreso aquí: (https://us.battle.net/account/support/password-reset.html).

Para cualquier disputa sobre esta medida, o para más información sobre la Actividad Explotadora, por favor visite la página de contacto y Preguntas Frecuentes (FAQ) aquí: (http://us.blizzard.com/support/article.xml?locale=es_MX&tag=exploitfaq).

Saludos,

Atención al Cliente
Blizzard Entertainment
http://us.battle.net/wow/es/


Yeah it does seem like a little bit more then a coincidence, but two cases isn't conclusive by any means. It would be interesting to see how many other people have run into the same incident as us. Also, my situation is just slightly different, my account is under investigation because they suspect I was trying to sell the account, not the items/gold on it (which I think I do have a fair amount of). But if someone was stealing accounts to make money from, I would assume that they would try to sell both the items/gold and the account, so the specific offense probably isn't all that important as the punishment is the same for either.
hifriend
Profile Blog Joined June 2009
China7935 Posts
August 12 2011 23:29 GMT
#378
Storing passwords in plain text shows such a blatant disregard for their customers security.. I'm disappointed.
ApBuLLet
Profile Joined September 2010
United States604 Posts
August 12 2011 23:30 GMT
#379
On August 13 2011 08:21 Integra wrote:
Show nested quote +
On August 13 2011 08:18 warbean wrote:
I also just got this email from Blizzard for my WoW account that has been inactive for 9 months now. Looks like somehow got into my character and got himself banned. I use the same email for GomTv and Battle.net, although I usually sign in through SNS Twitter. Seems to be too much of a coincidence.

+ Show Spoiler +

English speaking customers: Please refer to the start of this mail
Para los clientes españoles: Por favor vayan hasta el fin de este email


***Notice of Account Closure***

Account Name: WARBEAN1

Reason for Closure: Terms of Use Violation -- Exploitative Activity: Abuse of the Economy

This account was closed because one or more characters were identified exchanging, or contributing to the exchange of, in-game property (items or gold) for "real-world" currency. This exchange process negatively impacts the World of Warcraft game environment by detracting from the value of the in-game economy.

Even if this is the result of account sharing, the account owner can still be held responsible for the penalty because of the impact it had on the game environment.

We've found the above behavior is many times directly related to groups responsible for compromising World of Warcraft accounts; we take these issues very seriously. To better understand our position against exploitative activity and the risks involved, please review this article: http://us.blizzard.com/support/article.xml?locale=en_US&articleId=25455

The exploitative activity that took place on this account violates the World of Warcraft Terms of Use. We ask you take a moment to review these terms at http://us.blizzard.com/company/legal/index.html. Note that additional Terms of Use violations may result in more severe actions against this account, up to and including permanent closure.

If you believe your account was compromised, please submit an in-game petition or fill the contact email form at http://us.blizzard.com/support/webform.xml?locale=en_US. Our support staff will assist you as soon as possible. If you are unable to access your account due to the password being changed, please visit our Login Support site here: https://us.battle.net/account/support/password-reset.html

For any disputes of this action or further information on Exploitive Activity, please visit the Exploitative Activity FAQ and contact page here: http://us.blizzard.com/support/article/exploitfaq

Regards,

Customer Services
Blizzard Entertainment
http://us.battle.net/wow/en/
-------------------------------------------------------


***Notificación de Clausura de Cuenta***

Nombre de Cuenta: WARBEAN1

Razón por la Clausura: Violación de las Condiciones de Uso – Actividad Explotadora: Abuso de la Economía

Esta cuenta fue clausurada porque uno o más personajes se identificaron comerciando, o contribuyendo al comercio de, la propiedad dentro del juego (objetos u oro) por moneda “real.” Este proceso de comercio negativamente impacta al ambiente de World of Warcraft por detraer del valor de la economía dentro del juego.

Aunque esto sea a resultado de la compartición de la cuenta, el dueño de la cuenta aun puede ser responsable por la penalización debido al impacto que tuvo en el ambiente del juego.

Hemos conseguido que el comportamiento superior muchas veces sea directamente relacionado a los grupos responsables por comprometer las cuentas de World of Warcraft; nosotros tomamos estos asuntos muy seriamente. Para mejor entender nuestra posición sobre la actividad explotadora y los riesgos involucrados, por favor revise este artículo: (http://us.blizzard.com/support/article.xml?locale=en_US&articleId=25455).

La actividad explotadora que ocurrió en esta cuenta está en contra de las Condiciones de Uso de World of Warcraft. Le pedimos que se tome un momento para revisar estos términos: (http://us.blizzard.com/company/legal/index.html). Note que cualquier violación adicional de las Condiciones de Uso pueden resultar en más severas medidas en contra de esta cuenta, hasta e incluyendo la clausura permanente.

Si cree que su cuenta haya sido comprometida, por favor abra una petición dentro del juego o llene el formulario de contacto por email: (https://us.blizzard.com/support/webform.xml?locale=es_MX). Nuestro equipo de soporte le asistirá lo más pronto posible. Si no puede acceder a su cuenta debido a un cambio de contraseña, por favor visite nuestro sitio de Asistencia de Ingreso aquí: (https://us.battle.net/account/support/password-reset.html).

Para cualquier disputa sobre esta medida, o para más información sobre la Actividad Explotadora, por favor visite la página de contacto y Preguntas Frecuentes (FAQ) aquí: (http://us.blizzard.com/support/article.xml?locale=es_MX&tag=exploitfaq).

Saludos,

Atención al Cliente
Blizzard Entertainment
http://us.battle.net/wow/es/


I've just recieved emails, note not email but EMAILS from Blizz as well. They all seem to be fake though. they are all claiming various stuff, like I have to give away my bank account info to prove that i am the holder of the wow account etc. My information has been leaked, that's for sure.


Yeah Blizzard would not ask for personal information like that, as I am sure you know. This may or may not be a result of the gomtv compromise, I wouldn't be surprised either way really. It's worth noting though =).
Goldfish
Profile Blog Joined August 2010
2230 Posts
Last Edited: 2011-08-12 23:31:58
August 12 2011 23:30 GMT
#380
On August 13 2011 08:25 Goldfish wrote:
Anyone know how hackers got into GOMtv.net? I'm sort of a nub at this but is it because they use outdated software (I know some forums may still use real old versions of invisionboard or w/e for example which may have security exploits) or because something GOM didn't do?

Basically how do websites protect themselves from getting hacked (well at least easily hacked) and how did GOM get hacked? Just curious.


Adding to the above - is gomtv.net safe right now? I mean do hackers currently have the ability to install malware on the site and/or exploit anything else besides just stealing usernames and passwords?
https://connect.microsoft.com/WindowsServerFeedback/feedback/details/741495/biggest-explorer-annoyance-automatic-sorting-windows-7-server-2008-r2-and-vista#details Allow Disable Auto Arrange in Windows 7+
Integra
Profile Blog Joined January 2008
Sweden5626 Posts
Last Edited: 2011-08-12 23:32:46
August 12 2011 23:31 GMT
#381
On August 13 2011 08:26 Antoine wrote:
Show nested quote +
On August 13 2011 08:21 Integra wrote:
On August 13 2011 08:18 warbean wrote:
I also just got this email from Blizzard for my WoW account that has been inactive for 9 months now. Looks like somehow got into my character and got himself banned. I use the same email for GomTv and Battle.net, although I usually sign in through SNS Twitter. Seems to be too much of a coincidence.

+ Show Spoiler +

English speaking customers: Please refer to the start of this mail
Para los clientes españoles: Por favor vayan hasta el fin de este email


***Notice of Account Closure***

Account Name: WARBEAN1

Reason for Closure: Terms of Use Violation -- Exploitative Activity: Abuse of the Economy

This account was closed because one or more characters were identified exchanging, or contributing to the exchange of, in-game property (items or gold) for "real-world" currency. This exchange process negatively impacts the World of Warcraft game environment by detracting from the value of the in-game economy.

Even if this is the result of account sharing, the account owner can still be held responsible for the penalty because of the impact it had on the game environment.

We've found the above behavior is many times directly related to groups responsible for compromising World of Warcraft accounts; we take these issues very seriously. To better understand our position against exploitative activity and the risks involved, please review this article: http://us.blizzard.com/support/article.xml?locale=en_US&articleId=25455

The exploitative activity that took place on this account violates the World of Warcraft Terms of Use. We ask you take a moment to review these terms at http://us.blizzard.com/company/legal/index.html. Note that additional Terms of Use violations may result in more severe actions against this account, up to and including permanent closure.

If you believe your account was compromised, please submit an in-game petition or fill the contact email form at http://us.blizzard.com/support/webform.xml?locale=en_US. Our support staff will assist you as soon as possible. If you are unable to access your account due to the password being changed, please visit our Login Support site here: https://us.battle.net/account/support/password-reset.html

For any disputes of this action or further information on Exploitive Activity, please visit the Exploitative Activity FAQ and contact page here: http://us.blizzard.com/support/article/exploitfaq

Regards,

Customer Services
Blizzard Entertainment
http://us.battle.net/wow/en/
-------------------------------------------------------


***Notificación de Clausura de Cuenta***

Nombre de Cuenta: WARBEAN1

Razón por la Clausura: Violación de las Condiciones de Uso – Actividad Explotadora: Abuso de la Economía

Esta cuenta fue clausurada porque uno o más personajes se identificaron comerciando, o contribuyendo al comercio de, la propiedad dentro del juego (objetos u oro) por moneda “real.” Este proceso de comercio negativamente impacta al ambiente de World of Warcraft por detraer del valor de la economía dentro del juego.

Aunque esto sea a resultado de la compartición de la cuenta, el dueño de la cuenta aun puede ser responsable por la penalización debido al impacto que tuvo en el ambiente del juego.

Hemos conseguido que el comportamiento superior muchas veces sea directamente relacionado a los grupos responsables por comprometer las cuentas de World of Warcraft; nosotros tomamos estos asuntos muy seriamente. Para mejor entender nuestra posición sobre la actividad explotadora y los riesgos involucrados, por favor revise este artículo: (http://us.blizzard.com/support/article.xml?locale=en_US&articleId=25455).

La actividad explotadora que ocurrió en esta cuenta está en contra de las Condiciones de Uso de World of Warcraft. Le pedimos que se tome un momento para revisar estos términos: (http://us.blizzard.com/company/legal/index.html). Note que cualquier violación adicional de las Condiciones de Uso pueden resultar en más severas medidas en contra de esta cuenta, hasta e incluyendo la clausura permanente.

Si cree que su cuenta haya sido comprometida, por favor abra una petición dentro del juego o llene el formulario de contacto por email: (https://us.blizzard.com/support/webform.xml?locale=es_MX). Nuestro equipo de soporte le asistirá lo más pronto posible. Si no puede acceder a su cuenta debido a un cambio de contraseña, por favor visite nuestro sitio de Asistencia de Ingreso aquí: (https://us.battle.net/account/support/password-reset.html).

Para cualquier disputa sobre esta medida, o para más información sobre la Actividad Explotadora, por favor visite la página de contacto y Preguntas Frecuentes (FAQ) aquí: (http://us.blizzard.com/support/article.xml?locale=es_MX&tag=exploitfaq).

Saludos,

Atención al Cliente
Blizzard Entertainment
http://us.battle.net/wow/es/


I've just recieved emails, note not email but EMAILS from Blizz as well. They all seem to be fake though. they are all claiming various stuff, like I have to give away my bank account info to prove that i am the holder of the wow account etc. My information has been leaked, that's for sure.

i would say you've probably gotten these emails a lot longer than 1 day, i've had them slamming my spambox for like 5 years now

No, This is a new email account, I acquired it less than 2 weeks ago and the spam litteraly started a few hours ago! And the username they are calling me by in the emails is the same username I have on GomTV.Net and not my wow account!
"Dark Pleasure" | | I survived the Locust war of May 3, 2014
Jiddra
Profile Joined October 2010
Sweden2685 Posts
August 12 2011 23:45 GMT
#382
Rakaka.se is having some fun with it atleast This is the picture used in the news about GOM being hacked.

[image loading]
I am not young enough to know everything.
Goldfish
Profile Blog Joined August 2010
2230 Posts
August 12 2011 23:52 GMT
#383
Is gomtv.net safe right now? I mean do hackers currently have the ability to install malware on the site and/or exploit anything else besides just stealing usernames and passwords?

Well the reason I'm asking is because I know of other sites (mainly MMO fansites for example) which were compromised and had malware installed on it so if any javascripts were enabled, your computer would have likely been infected with some malware.

Is this threat a possibility with gomtv.net or is it just only an issue of taken usernames and passwords?

Again sort of a newb in terms of this stuff so I'm not sure if what happened can resort to this but I want to make sure.
https://connect.microsoft.com/WindowsServerFeedback/feedback/details/741495/biggest-explorer-annoyance-automatic-sorting-windows-7-server-2008-r2-and-vista#details Allow Disable Auto Arrange in Windows 7+
firehand101
Profile Blog Joined March 2011
Australia3152 Posts
August 12 2011 23:54 GMT
#384
I really cant be bothered changing every password I have, it is way too much work. I can only hope that no one hacks me
The opinions expressed by our users do not reflect the official position of TeamLiquid.net or its staff.
Integra
Profile Blog Joined January 2008
Sweden5626 Posts
August 12 2011 23:54 GMT
#385
On August 13 2011 08:45 Jiddra wrote:
Rakaka.se is having some fun with it atleast This is the picture used in the news about GOM being hacked.

[image loading]

Rakaka, prolly the biggest gossip gaming site of the world, but they are being honest about it so you can't blame them lol.
"Dark Pleasure" | | I survived the Locust war of May 3, 2014
-Cyrus-
Profile Joined June 2011
United States318 Posts
August 12 2011 23:57 GMT
#386
What the fuck? Why didn't GOM send emails out or at the very least put a notification on their main website telling us about this?
rasnj
Profile Joined May 2010
United States1959 Posts
Last Edited: 2011-08-13 00:00:33
August 12 2011 23:59 GMT
#387
On August 13 2011 08:30 Goldfish wrote:
Show nested quote +
On August 13 2011 08:25 Goldfish wrote:
Anyone know how hackers got into GOMtv.net? I'm sort of a nub at this but is it because they use outdated software (I know some forums may still use real old versions of invisionboard or w/e for example which may have security exploits) or because something GOM didn't do?

Basically how do websites protect themselves from getting hacked (well at least easily hacked) and how did GOM get hacked? Just curious.


Adding to the above - is gomtv.net safe right now? I mean do hackers currently have the ability to install malware on the site and/or exploit anything else besides just stealing usernames and passwords?

They basically did 2 things wrong. Firstly they stored the passwords unencrypted which is a big no no. They should never actually know your password. Just an encrypted version. This is so even if someone breaks their security (if you can imagine), then they can't get your pass.

Secondly their database was vulnerable to a very common type of attack known as sql injection. Basically you send a query that contains instructions and trick the database into executing those instructions which may for instance be "list all usernames and passwords". This is a common issue and usually easily preventable.

Both are very basic mistakes.

It's very unlikely they can install malware. At worst they can hijack accounts on gom and read your e-mail id, username, password and what you have bought on gom.

There is no reason to believe gom is safe at this point so changing passwords will probably not help, and either way the attackers have likely saved the passwords to a file already on their own systems.

You should change your password on any other service that has/had the same password as one you have ever used on gomtv.

Goldfish
Profile Blog Joined August 2010
2230 Posts
Last Edited: 2011-08-13 00:21:54
August 13 2011 00:07 GMT
#388
Thanks for the explanation rasnj. Ever since I played FFXI and seen so many sites compromised and have malware installed on them (MMO sites are always popular sites for target since MMO accounts can be worth a lot in cash value) I've been paranoid about this stuff so thanks for the explanation.
https://connect.microsoft.com/WindowsServerFeedback/feedback/details/741495/biggest-explorer-annoyance-automatic-sorting-windows-7-server-2008-r2-and-vista#details Allow Disable Auto Arrange in Windows 7+
chipmonklord17
Profile Joined February 2011
United States11944 Posts
Last Edited: 2011-08-13 00:13:32
August 13 2011 00:12 GMT
#389
out of curiosity why is this not on the home page by now...?
grobo
Profile Blog Joined February 2007
Japan6199 Posts
August 13 2011 00:31 GMT
#390
On August 13 2011 09:12 chipmonklord17 wrote:
out of curiosity why is this not on the home page by now...?


Timezones, bro
We make signature, then defense it.
EchoZ
Profile Blog Joined October 2010
Japan5041 Posts
August 13 2011 00:33 GMT
#391
Well this sucks?
Dear Sixsmith...
Jibba
Profile Blog Joined October 2007
United States22883 Posts
August 13 2011 00:33 GMT
#392
On August 13 2011 09:31 grobo wrote:
Show nested quote +
On August 13 2011 09:12 chipmonklord17 wrote:
out of curiosity why is this not on the home page by now...?


Timezones, bro

It's 9:30.
ModeratorNow I'm distant, dark in this anthrobeat
KhAmun
Profile Blog Joined September 2010
United States1005 Posts
August 13 2011 00:34 GMT
#393
The no encryptions on the passwords is just irresponsible, and I don't know profitable sites ever ever ever do that.
flooky
Profile Joined August 2011
44 Posts
August 13 2011 00:34 GMT
#394
zzzzzzzzzzzzzzzz.................................. that is my main email and password that i use for everything
AllHailCommonSense
Profile Joined August 2011
22 Posts
August 13 2011 00:34 GMT
#395
This + NASL fiasco = amazing KR professionalism.
Seiru
Profile Joined May 2011
United States40 Posts
August 13 2011 00:35 GMT
#396
I hope they post when they believe that they've secured the site....seems pointless to update your PW on GOMtv before that happens.
Lorizean
Profile Blog Joined March 2011
Germany1330 Posts
August 13 2011 00:38 GMT
#397
I really don't understand how somebody can write a website that stores passwords as plain text. It's not like it's hard to encrypt it.

Also, does anybody know if GOM saves some kind of password-change history? I have used another password (which I use for other purposes too) a while back, could the crackers have had access to that?
chipmonklord17
Profile Joined February 2011
United States11944 Posts
August 13 2011 00:43 GMT
#398
On August 13 2011 09:31 grobo wrote:
Show nested quote +
On August 13 2011 09:12 chipmonklord17 wrote:
out of curiosity why is this not on the home page by now...?


Timezones, bro


TLs homepage I mean
ApBuLLet
Profile Joined September 2010
United States604 Posts
August 13 2011 00:43 GMT
#399
On August 13 2011 09:38 Lorizean wrote:
I really don't understand how somebody can write a website that stores passwords as plain text. It's not like it's hard to encrypt it.

Also, does anybody know if GOM saves some kind of password-change history? I have used another password (which I use for other purposes too) a while back, could the crackers have had access to that?


I don't think anyone can answer that for you with certainty, so I would assume that yes they could have access to that. Hopefully GOM will have an official announcement about it sometime very soon to notify everyone about exactly what happened so that we can take the necessary precautions to keep our stuff safe. Until then, however, I would assume the worst just in case.
Integra
Profile Blog Joined January 2008
Sweden5626 Posts
Last Edited: 2011-08-13 00:48:18
August 13 2011 00:45 GMT
#400
On August 13 2011 09:38 Lorizean wrote:
I really don't understand how somebody can write a website that stores passwords as plain text. It's not like it's hard to encrypt it.

Also, does anybody know if GOM saves some kind of password-change history? I have used another password (which I use for other purposes too) a while back, could the crackers have had access to that?

I dobut they have a history of earlier passwords, nothing on the page suggests that it exists, what would even be purpose of that, it makes no sense to have one. There is however a chance that the hacker got access to a admin password, That way he could access the database backup rollback function (if such is supported by the table being used). That way he could simply rollback the database to a earlier datapoint and get any previous password you had before you changed it. It's prolly pretty safe though if you changed your password. Not much else you can do anyway.
"Dark Pleasure" | | I survived the Locust war of May 3, 2014
Probe1
Profile Blog Joined August 2010
United States17920 Posts
August 13 2011 00:45 GMT
#401
Thank god I used a random ass password for GOM. But regardless I'm still going to go and change around all my paypal stuff -_-
우정호 KT_VIOLET 1988 - 2012 While we are postponing, life speeds by
et
Profile Joined September 2010
Switzerland367 Posts
August 13 2011 00:47 GMT
#402
On August 13 2011 09:38 Lorizean wrote:
I really don't understand how somebody can write a website that stores passwords as plain text. It's not like it's hard to encrypt it.


It's not that hard to do better than plaintext, but simple hashing (with or without salt) isn't enough anymore. Too many people have bruteforce password cracking devices (commonly called graphic cards) nowadays, so you should do something like Key Stretching to delay that, and that is something you rarely see done.

On August 13 2011 09:38 Lorizean wrote:
Also, does anybody know if GOM saves some kind of password-change history? I have used another password (which I use for other purposes too) a while back, could the crackers have had access to that?


There is a simple guideline: If you don't know, assume the passwords are comprimised. The hole in the page isn't likely to be new, so there could be lots of people with access to the database from lots of dates in the past, there is no need for a "history" database. Your passwords should be considered compromised.
Explanations exist; they have existed for all time; there is always a well-known solution to every human problem — neat, plausible, and wrong. -- H. L. Mencken
Incanus
Profile Joined October 2009
Canada695 Posts
Last Edited: 2011-09-05 09:52:15
August 13 2011 00:50 GMT
#403
Edit: To be safe follow the suggestions above and below this post.
Flash: "Why am I so good?" *sob sob*
jcarlson08
Profile Joined March 2011
United States267 Posts
August 13 2011 00:50 GMT
#404
Glad I log on via Facebook....
Integra
Profile Blog Joined January 2008
Sweden5626 Posts
August 13 2011 00:51 GMT
#405
Reposting what I posted on the last thread in hopes that the guy who wrote the question will see it:
On August 13 2011 09:38 Lorizean wrote:
I really don't understand how somebody can write a website that stores passwords as plain text. It's not like it's hard to encrypt it.

Also, does anybody know if GOM saves some kind of password-change history? I have used another password (which I use for other purposes too) a while back, could the crackers have had access to that?

I dobut they have a history of earlier passwords, nothing on the page suggests that it exists, what would even be purpose of that, it makes no sense to have one. There is however a chance that the hacker got access to a admin password, That way he could access the database backup rollback function (if such is supported by the table being used). That way he could simply rollback the database to a earlier datapoint and get any previous password you had before you changed it. It's prolly pretty safe though if you changed your password. Not much else you can do anyway.

User was warned for this post
"Dark Pleasure" | | I survived the Locust war of May 3, 2014
Pondo
Profile Blog Joined August 2010
Australia283 Posts
August 13 2011 00:59 GMT
#406
What if my gom password was different to all my other passwords but only by one character? :S
Kon_Artis
Profile Joined July 2011
United States6 Posts
August 13 2011 01:01 GMT
#407
What if my gom password was different to all my other passwords but only by one character? :S
Same thing with me for some of my passwords.

I decided to just change everything to make sure it is safe. It only took me 5 minutes to change 3 passwords.
grobo
Profile Blog Joined February 2007
Japan6199 Posts
August 13 2011 01:02 GMT
#408
On August 13 2011 09:59 Pondo wrote:
What if my gom password was different to all my other passwords but only by one character? :S


Well, for all he knows the difference could be 2903724 different characters or numbers, it won't do him any good.
We make signature, then defense it.
genius_man16
Profile Joined February 2011
United States749 Posts
August 13 2011 01:03 GMT
#409
Plain text? For real? Jeeze man, I kinda lost some respect for Gom :/

Thanks for the info though, changing my password asap...
Dyrus | Vooby | Balls | Meteos | WildTurtle | Bjergsen | Cop | sexPeke | Xpecial | Aphromoo | Scarra |
Sanguinarius
Profile Joined January 2010
United States3427 Posts
August 13 2011 01:06 GMT
#410
plain text passwords?? Really GOM? Cmon. Time to upgrade a bit.

:-(

At least my gom password is only for that site.
Your strength is just an accident arising from the weakness of others -Heart of Darkness
DanielxD
Profile Joined August 2011
Peru52 Posts
August 13 2011 01:30 GMT
#411
Glad I used a random password
ty R1CH
Toyosatomimi no Miko <3!!
ReaperX
Profile Blog Joined January 2011
Hong Kong1758 Posts
Last Edited: 2011-08-13 01:33:17
August 13 2011 01:33 GMT
#412
omfg gom

least i use fb to connect
Artosis : Clide. idrA : Shut up.
Lmui
Profile Joined November 2010
Canada6215 Posts
August 13 2011 01:37 GMT
#413
oh god, gom just pulled a sony with plaintext user/pass combos =/. Hell of a way to store those... I'm glad i used the facebook signin since that seems more secure for the moment.
The KY
Profile Blog Joined October 2010
United Kingdom6252 Posts
August 13 2011 01:38 GMT
#414
'OH NO THAT'S MY PASSWORD AND EMAIL FOR EVERYTH-oh I use twitter to log in. Cool.'
mikell
Profile Joined August 2010
Australia352 Posts
August 13 2011 01:45 GMT
#415
it's a much bigger issue for sony than it was for GOM. ie. there was millions more accounts on sony psn than there was on GOM... in any case you should never be using the same password for every site because the fact is that any forum admin can grab your password information.
drone hard
Mawi
Profile Joined August 2010
Sweden4365 Posts
August 13 2011 02:16 GMT
#416
wow good thing i use different passwords for all websites but they got my email which i have lots of accounts on FML oh well its just forums accounts that i am inactive in other websites. mostly stupid "get beta access" websites
Forever Mirin Zyzz Son of Zeus Brother of Hercules Father of the Aesthetics
GreatestThreat
Profile Joined May 2010
United States631 Posts
August 13 2011 02:24 GMT
#417
I don't get what the big deal is. So they know my password for GOMTV? Lol.
"I'm ethereal! My children are legion, serial! They stick to my skin like beloved cysts... I TEAR AWAY WITH MY NAILS AND TEETH AND FISTS!"
Disquiet
Profile Joined January 2011
Australia628 Posts
August 13 2011 02:29 GMT
#418
Well now my email is probably going to be sent heaps of spam shit.
stevarius
Profile Joined August 2010
United States1394 Posts
Last Edited: 2011-08-13 02:32:34
August 13 2011 02:31 GMT
#419
G.G.

I just got a password recovery email on my gomtv email.

It's a legit WoW website link.... funny part is there was only a WoW trial on said email account. I kept my WoW account and Master's sc2 account on a different email....

*sigh*

Good job GOMTV. Now I'm going to be sent spam emails on top of legitimate emails of people trying to get into my email account with the legitimate recovery method. Oh, I'm also lucky that said email password is significantly different than the one I use for GOM.

Thank you R1CH for suggesting KeePass in recent history.
¯\_(ツ)_/¯
Voltaire
Profile Joined September 2010
United States1485 Posts
August 13 2011 02:35 GMT
#420
My parents alerted me that the email I use for GOM had sent them some spam emails (I also used the same password for GOM and that email address) Thankfully it's not my "official" email.
As long as people believe in absurdities they will continue to commit atrocities.
Toxi78
Profile Joined May 2010
966 Posts
August 13 2011 02:42 GMT
#421
well I have 6 euros on my paypal account, don't really care either way.
lee365
Profile Joined December 2010
United States448 Posts
August 13 2011 02:45 GMT
#422
Its really not that big of a problem, unless your scared of getting some spam mail. Hopefully GOM fixes their shit though
Terran Fighting! NoSoupfOu.517
nugget-92
Profile Joined March 2011
Australia83 Posts
August 13 2011 02:51 GMT
#423
Phew... was freaking out until I realised I had a slightly different email.

That and I'm broke as shit.
Well, the tomato's an anomaly. So successful with the ketchup and the sauce, but you can't find a good one.
weaknurse
Profile Joined October 2010
Australia320 Posts
August 13 2011 02:56 GMT
#424
Gom really need to ramp up their security and their Stream Quality.
laszmosis
Profile Joined September 2010
Australia112 Posts
August 13 2011 02:56 GMT
#425
Whoever done this is ruining esports!
0neder
Profile Joined July 2009
United States3733 Posts
August 13 2011 02:58 GMT
#426
On August 13 2011 11:56 laszmosis wrote:
Whoever done this is ruining esports!

Quoted for truthiness!
Mawi
Profile Joined August 2010
Sweden4365 Posts
August 13 2011 02:59 GMT
#427
Just logged in on my hotmail havent logged in for 6days which i use for gomtv and i have no contacts because its just for accounts and i have Viagra Emails,illegal pills, Free money,Click this link and get a Free ¤32äa" Bnet wtf(not my sc2bnet) and all this shit spam O_o fucking hell there are tons of them the scary part is i have never registered my email to bnet so no clue how i get that.
This is also the first time i have ever received so many spam emails.

First time this has ever happend to me. I never click on suspicious links I have learned from my own brain.

These emails have been sent 2days ago I guess they love me with all these shit spams

I have to admit i laughed when i saw Viagra emails and "illegal pills"

Forever Mirin Zyzz Son of Zeus Brother of Hercules Father of the Aesthetics
Lliane
Profile Joined September 2010
Japan101 Posts
August 13 2011 03:01 GMT
#428
Unfortunately most of the Korean Internet uses terrible Active X controls and Plain Text Passwords
야 오빠 ! 스타크래프트 너가 가르쳐주세요 !
thee telescopes
Profile Joined August 2010
321 Posts
August 13 2011 03:03 GMT
#429
On August 13 2011 11:59 Mawi wrote:
Just logged in on my hotmail havent logged in for 6days which i use for gomtv and i have no contacts because its just for accounts and i have Viagra Emails,illegal pills, Free money,Click this link and get a Free ¤32äa" Bnet wtf(not my sc2bnet) and all this shit spam O_o fucking hell there are tons of them the scary part is i have never registered my email to bnet so no clue how i get that.
This is also the first time i have ever received so many spam emails.

First time this has ever happend to me. I never click on suspicious links I have learned from my own brain.

These emails have been sent 2days ago I guess they love me with all these shit spams

I have to admit i laughed when i saw Viagra emails and "illegal pills"

The bnet email will probably be a phishing scam. They're super common because of the value of stolen wow items/accounts.
sCfO20
Profile Joined May 2011
176 Posts
August 13 2011 03:05 GMT
#430
Holy shit.

Facebook for the win!!!!??? I don't use facebook other than for GomTV, but shit i suppose it paid off. This is insane, is nowhere on the internet safe????
jnkw
Profile Joined November 2010
Canada347 Posts
August 13 2011 03:06 GMT
#431
PLAINTEXT? 500 minerals says the reason they're in this mess is that they didn't bother to sanitize their inputs.

I don't have an account, but this is outrageous incompetence on the part of their web development team.
Mawi
Profile Joined August 2010
Sweden4365 Posts
Last Edited: 2011-08-13 03:06:50
August 13 2011 03:06 GMT
#432
oh cheers three telescopes it made me less scared than I was hehe . I thought it could be a phishing scam but don't want to risk clicking on those emails.
Forever Mirin Zyzz Son of Zeus Brother of Hercules Father of the Aesthetics
Goldfish
Profile Blog Joined August 2010
2230 Posts
August 13 2011 03:12 GMT
#433
Well off topic - Does anyone know if gmail offers a premium service or any service where you can get your real name, ID, etc attached to your account so that you can recover it if stolen? Gmail is a good email service and I wouldn't mind paying some $ for a premium version with more benefits.

I didn't lose an email or anything (my GOMTV password is different from my regular email) but with this happening a lot I wouldn't mind better email security >.>.

One thing I'm worried about is that I use several gmail accounts and I'm afraid of getting locked out (according to their ToS, they can terminate gmail accounts without warning for any reason). I at least assume if there exists a premium service then maybe that would less likely happen.
https://connect.microsoft.com/WindowsServerFeedback/feedback/details/741495/biggest-explorer-annoyance-automatic-sorting-windows-7-server-2008-r2-and-vista#details Allow Disable Auto Arrange in Windows 7+
SoLaR[i.C]
Profile Blog Joined August 2003
United States2969 Posts
Last Edited: 2011-08-13 03:33:30
August 13 2011 03:32 GMT
#434
So let's say I use my gomtv.net password for my email, online banking, school stuff, facebook, teamliquid, paypal, battle.net, my SC2 account, and just about every other site I have an account for. So far I haven't experienced anything fishy.

What to do?
Goldfish
Profile Blog Joined August 2010
2230 Posts
Last Edited: 2011-08-13 03:39:51
August 13 2011 03:38 GMT
#435
On August 13 2011 12:32 SoLaR[i.C] wrote:
So let's say I use my gomtv.net password for my email, online banking, school stuff, facebook, teamliquid, paypal, battle.net, my SC2 account, and just about every other site I have an account for. So far I haven't experienced anything fishy.

What to do?


Change passwords on all them asap. While you haven't been hit yet, it's likely to occur sometime in the future. Someone who has the passwords may think about selling them to a third party or maybe even just posting on a public site just for the heck of it or they haven't finished checking all of them on email.

So it's likely going to happen eventually so it's best to change passwords ASAP.

If you're having trouble thinking of passwords - Just randomly think of random combos of letters and numbers and write them on a paper in a safe place (don't store on computer if possible).
https://connect.microsoft.com/WindowsServerFeedback/feedback/details/741495/biggest-explorer-annoyance-automatic-sorting-windows-7-server-2008-r2-and-vista#details Allow Disable Auto Arrange in Windows 7+
jnkw
Profile Joined November 2010
Canada347 Posts
August 13 2011 03:39 GMT
#436
On August 13 2011 12:32 SoLaR[i.C] wrote:
So let's say I use my gomtv.net password for my email, online banking, school stuff, facebook, teamliquid, paypal, battle.net, my SC2 account, and just about every other site I have an account for. So far I haven't experienced anything fishy.

What to do?


Ask yourself this question:

What would you do if you lost access to all of those sites, right now?

Change your passwords, right now. Your bank may not reimburse you for unauthorized transactions if you don't, since you're not taking appropriate action in response to a potentially leaked password.
SoLaR[i.C]
Profile Blog Joined August 2003
United States2969 Posts
August 13 2011 03:40 GMT
#437
On August 13 2011 12:38 Goldfish wrote:
Show nested quote +
On August 13 2011 12:32 SoLaR[i.C] wrote:
So let's say I use my gomtv.net password for my email, online banking, school stuff, facebook, teamliquid, paypal, battle.net, my SC2 account, and just about every other site I have an account for. So far I haven't experienced anything fishy.

What to do?


Change passwords on all them asap. While you haven't been hit yet, it's likely to occur sometime in the future. Someone who has the passwords may think about selling them to a third party or maybe even just posting on a public site just for the heck of it or they haven't finished checking all of them on email.

So it's likely going to happen eventually so it's best to change passwords ASAP.

If you're having trouble thinking of passwords - Just randomly think of random combos of letters and numbers and write them on a paper in a safe place (don't store on computer if possible).

God damnit GOM

This password is stored in my muscle memory and everything..
jnkw
Profile Joined November 2010
Canada347 Posts
August 13 2011 03:41 GMT
#438
On August 13 2011 12:40 SoLaR[i.C] wrote:
Show nested quote +
On August 13 2011 12:38 Goldfish wrote:
On August 13 2011 12:32 SoLaR[i.C] wrote:
So let's say I use my gomtv.net password for my email, online banking, school stuff, facebook, teamliquid, paypal, battle.net, my SC2 account, and just about every other site I have an account for. So far I haven't experienced anything fishy.

What to do?


Change passwords on all them asap. While you haven't been hit yet, it's likely to occur sometime in the future. Someone who has the passwords may think about selling them to a third party or maybe even just posting on a public site just for the heck of it or they haven't finished checking all of them on email.

So it's likely going to happen eventually so it's best to change passwords ASAP.

If you're having trouble thinking of passwords - Just randomly think of random combos of letters and numbers and write them on a paper in a safe place (don't store on computer if possible).

God damnit GOM

This password is stored in my muscle memory and everything..


If you've been using it for that long it's probably high time you changed it anyway.
shizi
Profile Joined February 2008
United States210 Posts
August 13 2011 03:44 GMT
#439
what the hell thats so ridiculous
changed my pw right away :|
jnkw
Profile Joined November 2010
Canada347 Posts
August 13 2011 03:46 GMT
#440
On August 13 2011 12:44 shizi wrote:
what the hell thats so ridiculous
changed my pw right away :|


Make sure you change it for every other site that uses that password too.
bwally
Profile Joined December 2010
United States670 Posts
August 13 2011 03:46 GMT
#441
Good thing I haven't been supporting GOM the last few GSL, idiots.
Cubu
Profile Blog Joined February 2011
1171 Posts
August 13 2011 03:48 GMT
#442
umm... gomtv is hurting esports?
Lifter
Profile Joined April 2011
United States126 Posts
August 13 2011 03:49 GMT
#443
Saw this earlier today and scrambled to change my passwords before I had to leave to work. Bad GOM
Goldfish
Profile Blog Joined August 2010
2230 Posts
August 13 2011 03:51 GMT
#444
I think this topic should be put on Featured News so it can be seen on the home page (so more people know to change their passwords on their email or other sites if they use the same email on all sites).
https://connect.microsoft.com/WindowsServerFeedback/feedback/details/741495/biggest-explorer-annoyance-automatic-sorting-windows-7-server-2008-r2-and-vista#details Allow Disable Auto Arrange in Windows 7+
BrogMaN
Profile Joined April 2010
United States108 Posts
August 13 2011 03:52 GMT
#445
Phew, thank god I have a unique password for GOM. Thanks for the heads-up R1CH!
Madness is a sane reaction to an insane world.
TheAlchemist89
Profile Blog Joined December 2010
160 Posts
August 13 2011 03:54 GMT
#446
Thank you for the heads up on this! This is insane that this data wasn't encrypted..... with all the data pilfering lately companies really need to concern themselves with protecting their users a lot better than they have been.
AugustDreams
Profile Joined April 2011
Australia127 Posts
August 13 2011 04:00 GMT
#447
Lucky I have a side email I use for Gom and nothing else, still its kinda stupid they wouldn't have more security on their stuff.
http://www.youtube.com/user/AugustDreams - My Let's Play Channel!
Stanlot
Profile Joined December 2010
United States5742 Posts
August 13 2011 04:00 GMT
#448
Has anyone at GOM made a statement about this yet?
MC: "Sentry Forcefield Forcefield Marauder... cage Marauder die die"
HeroHenry
Profile Joined November 2010
United States1723 Posts
August 13 2011 04:02 GMT
#449
Doesn't matter since I use facebook log in anyways.
Aetherial
Profile Joined August 2010
Australia917 Posts
August 13 2011 04:06 GMT
#450
They should probably hire better developers and IT staff...
thee telescopes
Profile Joined August 2010
321 Posts
August 13 2011 04:07 GMT
#451
On August 13 2011 13:00 Stanlot wrote:
Has anyone at GOM made a statement about this yet?


Nothing on their website. Guess they don't want to own up to it?
Froadac
Profile Blog Joined July 2009
United States6733 Posts
August 13 2011 04:09 GMT
#452
Phew. Facebook.
Zzoram
Profile Joined February 2008
Canada7115 Posts
August 13 2011 04:13 GMT
#453
Wait, so does this mean they fixed their security?
Zzoram
Profile Joined February 2008
Canada7115 Posts
August 13 2011 04:14 GMT
#454
On August 13 2011 12:46 bwally wrote:
Good thing I haven't been supporting GOM the last few GSL, idiots.


Oh come on. GOM has been producing excellent content. Just because their IT department sucks doesn't mean you should hate on GOM.

Sony had the exact same problem and they're worth orders of magnitude more than GOM as a company.
NoobSkills
Profile Joined August 2009
United States1601 Posts
August 13 2011 04:19 GMT
#455
On August 13 2011 03:14 R1CH wrote:
There's a post on reddit that suggests that GOMTV has been compromised. I have independently verified that at least some usernames, passwords and email addresses have been compromised.

There appears to be zero security on the passwords as they were stored in plain text (really GOM?). This means if you use your GomTV password anywhere else, you should change it and consider it compromised. To clarify, your GomTV.net username, email address, PayPal real name and your GomTV.net password are likely compromised. Personal information such as your address may be compromised too if it was stored. You should also change your GomTV password to prevent unauthorized account access, although the exploit through which the information was compromised may still exist.

Since payments are processed through PayPal, there is no risk of your financial information being compromised, unless you used your PayPal password when signing up for GomTV (don't do this). Users who logged in via SNS should be safe as Twitter / Facebook authentication is token based, not password based.

If you aren't already, you should really use unique passwords for each website since this happens more often than you think (ever hear someone say they were "hacked"? this is likely how it happens) and not all websites will disclose if they get compromised. Use http://keepass.info/ for password management.


R1CH thank you for this post.
jnkw
Profile Joined November 2010
Canada347 Posts
August 13 2011 04:23 GMT
#456
On August 13 2011 13:14 Zzoram wrote:
Show nested quote +
On August 13 2011 12:46 bwally wrote:
Good thing I haven't been supporting GOM the last few GSL, idiots.


Oh come on. GOM has been producing excellent content. Just because their IT department sucks doesn't mean you should hate on GOM.

Sony had the exact same problem and they're worth orders of magnitude more than GOM as a company.


Sony didn't store passwords in plaintext.

You have no idea how bad this from a security standpoint.
CrazyCow
Profile Joined August 2010
United States308 Posts
August 13 2011 04:24 GMT
#457
On August 13 2011 13:14 Zzoram wrote:
Show nested quote +
On August 13 2011 12:46 bwally wrote:
Good thing I haven't been supporting GOM the last few GSL, idiots.


Oh come on. GOM has been producing excellent content. Just because their IT department sucks doesn't mean you should hate on GOM.

Sony had the exact same problem and they're worth orders of magnitude more than GOM as a company.


It's not exactly the same, Sony had their passwords encrypted.
NoobSkills
Profile Joined August 2009
United States1601 Posts
Last Edited: 2011-08-13 04:27:39
August 13 2011 04:24 GMT
#458
On August 13 2011 13:23 jnkw wrote:
Show nested quote +
On August 13 2011 13:14 Zzoram wrote:
On August 13 2011 12:46 bwally wrote:
Good thing I haven't been supporting GOM the last few GSL, idiots.


Oh come on. GOM has been producing excellent content. Just because their IT department sucks doesn't mean you should hate on GOM.

Sony had the exact same problem and they're worth orders of magnitude more than GOM as a company.


Sony didn't store passwords in plaintext.

You have no idea how bad this from a security standpoint.


Sony did store their passwords in plain text.
Why would you post an outright lie... unless they retracted their first public statement.

Edit: They did retract what they said, though admitted to using a very crackable hash format. Either way Sony has much more money than GSL and still messed up. Also how hard is it to change your password?
TMStarcraft
Profile Joined September 2010
Australia686 Posts
August 13 2011 04:28 GMT
#459
Thanks for the heads up Rich.
||
jnkw
Profile Joined November 2010
Canada347 Posts
August 13 2011 04:29 GMT
#460
On August 13 2011 13:24 NoobSkills wrote:
Show nested quote +
On August 13 2011 13:23 jnkw wrote:
On August 13 2011 13:14 Zzoram wrote:
On August 13 2011 12:46 bwally wrote:
Good thing I haven't been supporting GOM the last few GSL, idiots.


Oh come on. GOM has been producing excellent content. Just because their IT department sucks doesn't mean you should hate on GOM.

Sony had the exact same problem and they're worth orders of magnitude more than GOM as a company.


Sony didn't store passwords in plaintext.

You have no idea how bad this from a security standpoint.


Sony did store their passwords in plain text.
Why would you post an outright lie... unless they retracted their first public statement.

Edit: They did retract what they said, though admitted to using a very crackable hash format. Either way Sony has much more money than GSL and still messed up. Also how hard is it to change your password?


1. I don't have a password with GOM
2. It's not about how easy it is to change my password (though you have to realize that people often reuse passwords across dozens of sites). It's the principle of making such a fundamental mistake when dealing with sensitive customer information.
nalgene
Profile Joined October 2010
Canada2153 Posts
August 13 2011 04:34 GMT
#461
You can still download all the vods from any of their 9 servers...
Year 2500 Greater Israel ( Bahrain, Cyprus, Egypt, Iran, Iraq, Jordan, Kuwait, Lebanon, Oman, Gaza Strip, West Bank, Qatar, Saudi Arabia, Syria, Turkey, United Arab Emirates, Yemen )
RaiKageRyu
Profile Joined August 2009
Canada4773 Posts
August 13 2011 04:35 GMT
#462
Well, its a good thing GOM uses payPal anyways.
Someone call down the Thunder?
NoobSkills
Profile Joined August 2009
United States1601 Posts
August 13 2011 05:36 GMT
#463
On August 13 2011 13:29 jnkw wrote:
Show nested quote +
On August 13 2011 13:24 NoobSkills wrote:
On August 13 2011 13:23 jnkw wrote:
On August 13 2011 13:14 Zzoram wrote:
On August 13 2011 12:46 bwally wrote:
Good thing I haven't been supporting GOM the last few GSL, idiots.


Oh come on. GOM has been producing excellent content. Just because their IT department sucks doesn't mean you should hate on GOM.

Sony had the exact same problem and they're worth orders of magnitude more than GOM as a company.


Sony didn't store passwords in plaintext.

You have no idea how bad this from a security standpoint.


Sony did store their passwords in plain text.
Why would you post an outright lie... unless they retracted their first public statement.

Edit: They did retract what they said, though admitted to using a very crackable hash format. Either way Sony has much more money than GSL and still messed up. Also how hard is it to change your password?


1. I don't have a password with GOM
2. It's not about how easy it is to change my password (though you have to realize that people often reuse passwords across dozens of sites). It's the principle of making such a fundamental mistake when dealing with sensitive customer information.


Same username
Same Password
Person who has that information knows what sites you use that username and password on.
Very unlikely.

2. Yes, it is irresponsible, but the level of encryption that most databases use is weak, so anyone can get you info anyway.
tdt
Profile Joined October 2010
United States3179 Posts
August 13 2011 05:42 GMT
#464
I always use 4 different passwords

One for forums
One for esites like newegg, gomtv, steam etc where money trades hands
One for real money sites like my bank or credit card
One for login's to computer/phone and other hardware

Should not be a problem
MC for president
giuocob
Profile Joined July 2010
United States149 Posts
August 13 2011 05:50 GMT
#465
On August 13 2011 14:36 NoobSkills wrote:
Show nested quote +
On August 13 2011 13:29 jnkw wrote:
On August 13 2011 13:24 NoobSkills wrote:
On August 13 2011 13:23 jnkw wrote:
On August 13 2011 13:14 Zzoram wrote:
On August 13 2011 12:46 bwally wrote:
Good thing I haven't been supporting GOM the last few GSL, idiots.


Oh come on. GOM has been producing excellent content. Just because their IT department sucks doesn't mean you should hate on GOM.

Sony had the exact same problem and they're worth orders of magnitude more than GOM as a company.


Sony didn't store passwords in plaintext.

You have no idea how bad this from a security standpoint.


Sony did store their passwords in plain text.
Why would you post an outright lie... unless they retracted their first public statement.

Edit: They did retract what they said, though admitted to using a very crackable hash format. Either way Sony has much more money than GSL and still messed up. Also how hard is it to change your password?


1. I don't have a password with GOM
2. It's not about how easy it is to change my password (though you have to realize that people often reuse passwords across dozens of sites). It's the principle of making such a fundamental mistake when dealing with sensitive customer information.


Same username
Same Password
Person who has that information knows what sites you use that username and password on.
Very unlikely.

2. Yes, it is irresponsible, but the level of encryption that most databases use is weak, so anyone can get you info anyway.


No, this goes beyond most things. Having security holes in their databasing is one thing, an amateur error that is rather embarrasing but understandable. The sheer incompetence shown by a site as professional as Gom by not even hashing their passwords is mindblowing. This is the sort of thing that often merits immediately sacking all responsible and writing a long-winded apology letter on their front page.
julianto
Profile Joined December 2010
2292 Posts
August 13 2011 05:51 GMT
#466
Thanks for introducing me to KeePass. Just downloaded it.
¯\_(ツ)_/¯
moltenlead
Profile Joined December 2010
Canada866 Posts
August 13 2011 06:03 GMT
#467
Damn, I tried the concept of a universal password. I guess that I am getting my password spreadsheet back T_T
Ben...
Profile Joined January 2011
Canada3485 Posts
August 13 2011 06:05 GMT
#468
I immediately changed that password and my Paypal to be safe. I should be okay as I used a unique email for that and had already changed any passwords like that one to other password because my Bnet account was compromised a few months back so I should be fine.
"Cliiiiiiiiiiiiiiiiide" -Tastosis
kyophan
Profile Joined January 2010
United States113 Posts
August 13 2011 06:14 GMT
#469
The gomtv site is down for me now.
b0urne420
Profile Joined December 2010
Canada112 Posts
August 13 2011 06:17 GMT
#470
im pretty angry at the fact that they still haven't made an official statement about this....
lowkontrast
Profile Blog Joined August 2010
United States855 Posts
August 13 2011 06:29 GMT
#471
Thank you for letting us know, really helpful.
L3gendary
Profile Joined October 2010
Canada1470 Posts
August 13 2011 06:30 GMT
#472
On August 13 2011 13:34 nalgene wrote:
You can still download all the vods from any of their 9 servers...


You can download vods? how
Watching Jaedong play purifies my eyes. -Coach Ju Hoon
Phant
Profile Joined August 2010
United States737 Posts
August 13 2011 06:31 GMT
#473
I just made a GOM account yesterday -_-.
fatguyallen
Profile Joined March 2009
Romania75 Posts
Last Edited: 2011-08-13 06:37:08
August 13 2011 06:33 GMT
#474
Passwords kept in plain text. Wow just wow

P.S.: On the other hand my memory with passwords is so bad that i can't really remember if i used this password on another site
Geniuszerg
Profile Blog Joined July 2010
Canada454 Posts
August 13 2011 07:35 GMT
#475
=_=.. i think the only other place i use my gom password is tl.. and a few random games, so i should be fine, i really hope this doesn't happen
imJealous
Profile Joined July 2010
United States1382 Posts
Last Edited: 2011-08-13 07:38:29
August 13 2011 07:38 GMT
#476
"omg gomtv is KILLING ESPORTS!"
... In life very little goes right. "Right" meaning the way one expected and the way one wanted it. One has no right to want or expect anything.
iba001
Profile Joined December 2010
Australia156 Posts
August 13 2011 07:43 GMT
#477
thanks alot for letting us know rich
Laneir
Profile Joined September 2010
United States1160 Posts
August 13 2011 07:55 GMT
#478
wow that sux. I really hope they take the step to not let this happen again
Follow me on Instagram @Chef_Betto
BashfulBen
Profile Blog Joined June 2011
Ireland29 Posts
August 13 2011 07:56 GMT
#479
can't login to change the password. ahwell, we'll see how this plays out. Maybe they'll gift us all a free season ticket, due to their minimal password security
Toons
Profile Joined November 2010
Australia136 Posts
August 13 2011 08:06 GMT
#480
The ability to change passwords on GomTV is disabled now (any chance this was disabled by the intruder, not Gom?)

A statement is really needed ...

[image loading]
Probes and pylons
mmm
Profile Joined March 2011
Germany40 Posts
August 13 2011 08:10 GMT
#481
always the same old shit.
a lot of effort to close down every single restream, but no effort to secure user data
TheSilverfox
Profile Joined December 2010
Sweden1928 Posts
August 13 2011 08:17 GMT
#482
Seems like there are something going on at GOMTV right now (probably to fix this problem) because I can't login right now on either my old or new password.

Anyone having the same problem?
Also known as Joinsimon on Twitter/Reddit
actionbastrd
Profile Blog Joined September 2010
Congo598 Posts
August 13 2011 08:19 GMT
#483
On August 13 2011 17:06 Toons wrote:
The ability to change passwords on GomTV is disabled now (any chance this was disabled by the intruder, not Gom?)

A statement is really needed ...

+ Show Spoiler +
[image loading]



I got that just a second ago. i hit okay, entered my pw and i could still change everything lol.

Got the verification e-mail in spam. changed my email and my pw. Just ignore that notice and it should still work, at least it did for me. GL!
It rained today inside my head...
Patriot.dlk
Profile Blog Joined October 2004
Sweden5462 Posts
August 13 2011 08:24 GMT
#484
Thank god I used a random password because of account sharing
nexitustl1
Profile Joined December 2010
156 Posts
August 13 2011 08:24 GMT
#485
wow i was talking with my mom earlier in the day (like 12 hrs ago) and she was telling me some Korean gaming network was compromised. I laughed and was like "if it was something relevant i would have herd about it by now, plus the koreans dont really have a gaming network that is big enough to be something we would hear about." thinking in my head something like PSN or something.

Well this just sucks luckily all my stuff was done through twitter but im still going to be changing all my passwords!
Sponge75
Profile Joined May 2011
England194 Posts
August 13 2011 08:30 GMT
#486
"Profile modification is not available at the moment, Please try again at a later time." Dam you GOM.
Sufinsil
Profile Joined January 2011
United States760 Posts
August 13 2011 08:36 GMT
#487
Looks like they took down the site finally.
stickyhands
Profile Joined May 2011
187 Posts
Last Edited: 2011-08-13 08:45:00
August 13 2011 08:44 GMT
#488
why the hell do they stock their passwords in plain text? -_-
| (• ◡•)|╯ ╰(❍ᴥ❍ʋ)
BigFan
Profile Blog Joined December 2010
TLADT24920 Posts
August 13 2011 08:52 GMT
#489
hmm, really unfortunate but I dunno if I was compromised or not. I created the account way back and can't even remember the password used. Last time I tried logging in, I couldn't remember my pass so I clicked the "forget password button" and got an email. I tried logging in using my email and the password and it took me to the password page. I tried putting in a new password but it kept on erroring or something, so, I either gave up and used my fb or tried to get the email resent and tried again with no luck. So, my question is: If I couldn't change the password then, does that mean that I'm pretty safe or is it possible that the next pass actually got put into the text but the website was acting up?
Former BW EiC"Watch Bakemonogatari or I will kill you." -Toad, April 18th, 2017
Shield
Profile Blog Joined August 2009
Bulgaria4824 Posts
August 13 2011 08:55 GMT
#490
On August 13 2011 17:36 Sufinsil wrote:
Looks like they took down the site finally.


How come gomtv.net doesn't work, while gomtv.com is ok, lol.
I guess they're on different servers.
Shableh
Profile Joined July 2011
Canada40 Posts
August 13 2011 09:01 GMT
#491
Storing passwords in plain text.... that's so ridiculous. If you actually make people pay for something you offer on your site, learn to give them a fuckin reliable service.

Oh wait no, the "honour" system in Korea will save us
I don't always herp, but when I herp, I derp
bech
Profile Joined August 2010
Denmark162 Posts
August 13 2011 09:02 GMT
#492
Thankfully I don't use the same password for my important stuff as I do on random websites, so I'm usually safe when this happens (unless people REALLY want to log into my different profiles on different forums). But please GOMTV, plaintext?!
XplayN.com - Danish SC2 news and events.
GFLOW
Profile Joined November 2010
United States48 Posts
August 13 2011 09:05 GMT
#493
wow, im changing all my info right now
Perseverance
Profile Joined February 2010
Japan2800 Posts
August 13 2011 09:05 GMT
#494
Oh shit...thanks for this info...
<3 Moonbattles
Twoinches
Profile Joined April 2010
United States131 Posts
August 13 2011 09:05 GMT
#495
wow just read this, thanks for the heads up!
Paris hilton Is my Lord and Savior
Shield
Profile Blog Joined August 2009
Bulgaria4824 Posts
August 13 2011 09:08 GMT
#496
On August 13 2011 18:05 skip89w6 wrote:
wow, im changing all my info right now


While gomtv.net is down? :D
KimJongChill
Profile Joined January 2011
United States6429 Posts
August 13 2011 09:09 GMT
#497
whoa what!?! scary..
MMA: U realise MMA: Most of my army EgIdra: fuck off MMA: Killed my orbital MMA: LOL MMA: just saying MMA: u werent loss
BigFan
Profile Blog Joined December 2010
TLADT24920 Posts
August 13 2011 09:11 GMT
#498
Just changed my info to some of the other account that I have at our websites. Still can't believe that they would make such a stupid mistake -_-;
Former BW EiC"Watch Bakemonogatari or I will kill you." -Toad, April 18th, 2017
Thug[ro]
Profile Joined October 2005
Romania340 Posts
August 13 2011 09:12 GMT
#499
fail rofl
Morta
Profile Joined February 2011
Germany557 Posts
August 13 2011 09:13 GMT
#500
Profile modification is not available at the moment. Please try again at a later time.


WTF Gom!?I wanna change my password now!
if i'am sad i stop being sad and play starcraft 2 instead.True Story.
AdelSC123
Profile Joined March 2010
France362 Posts
August 13 2011 09:14 GMT
#501
wtf, seriously gom ?

Lucky me i used twitter
JustPassingBy
Profile Blog Joined January 2011
10776 Posts
August 13 2011 09:15 GMT
#502
this, anyone?
http://imgs.xkcd.com/comics/password_strength.png

^^"
nexitustl1
Profile Joined December 2010
156 Posts
August 13 2011 09:18 GMT
#503
I like to thank R1CH for posting the http://keepass.info/ for anyone who wants a super easy way to keep super important accounts secure with easy to access long strong passwords that are encrypted (in the program) use this!

I'm already changing all my important stuff using this ty!
Swwww
Profile Blog Joined July 2010
Switzerland812 Posts
August 13 2011 09:29 GMT
#504
Ouch this is pretty shitty news, thankfully I use a special PW for gom but I imagine a lot of people don't...
"What is this TeamSupportGroup?" - mahnini.
SpeaKEaSY
Profile Blog Joined December 2010
United States1070 Posts
August 13 2011 09:32 GMT
#505
FFFFFFFFFFUUUUUUUUU-

I made like a bajillion accounts while trolling Artosis when they were still doing post match interviews, and I can't remember all of the accounts I made
Aim for perfection, settle for mediocrity - KawaiiRice 2014
danteafk
Profile Joined May 2011
307 Posts
Last Edited: 2011-08-13 09:34:55
August 13 2011 09:32 GMT
#506
using unique passwords for each websites. who does this ? doing this you would have like 1000 passwords you need to remind of.

@gomtv.net: profile modification is not available at this moment
okum
Profile Blog Joined February 2009
France5778 Posts
August 13 2011 09:44 GMT
#507
Why do websites still do this in 2011. God damn. This should be criminal.
Flash fan before it was cool | Coiner of "jangbang"
Fatze
Profile Blog Joined March 2011
Germany1342 Posts
August 13 2011 09:45 GMT
#508
On August 13 2011 13:02 HeroHenry wrote:
Doesn't matter since I use facebook log in anyways.


Same here :D
Comfort from bottles, cheers from beers the guitars are our weapons and we know how to kill!
NuclearJudas
Profile Blog Joined July 2011
6546 Posts
August 13 2011 09:45 GMT
#509
Just changed my password. Thanks for the warning, Rich.
Life is like Tetris. Your errors pile up but your accomplishments disappear. - Robert Ohlén | http://railroaddiary.wordpress.com/ - My words about stuff.
nalgene
Profile Joined October 2010
Canada2153 Posts
August 13 2011 09:53 GMT
#510
On August 13 2011 18:32 danteafk wrote:
using unique passwords for each websites. who does this ? doing this you would have like 1000 passwords you need to remind of.

@gomtv.net: profile modification is not available at this moment


just dl the keepass thing and you'll be able to store as many as you want without memorization...
Year 2500 Greater Israel ( Bahrain, Cyprus, Egypt, Iran, Iraq, Jordan, Kuwait, Lebanon, Oman, Gaza Strip, West Bank, Qatar, Saudi Arabia, Syria, Turkey, United Arab Emirates, Yemen )
JuiceBoxHero
Profile Joined January 2011
117 Posts
August 13 2011 09:55 GMT
#511
Just got a message when trying to log into the email i used for gom telling me they think my account has been compromised, i do not use the same password for gom and my email. Looks like someone might be using the info this sucks, what the hell gom. I would advise changing other passwords not the gom one as people have mentioned since gom has not tightened their security as far as i know
rebuffering
Profile Joined December 2010
Canada2436 Posts
August 13 2011 09:58 GMT
#512
So my best bet is to leave my gom pass the same since they havent fixed the issue yet, and just change my other passes? i should be safe that way right? even if they know my gom pass, and email address, as long as i change passwords elsewhere, im good right??? right!!!!?!?!?!?!?
http://www.twitch.tv/rebufferingg
Deleted User 124618
Profile Joined November 2010
1142 Posts
August 13 2011 10:00 GMT
#513
On August 13 2011 18:18 nexitustl1 wrote:
I like to thank R1CH for posting the http://keepass.info/ for anyone who wants a super easy way to keep super important accounts secure with easy to access long strong passwords that are encrypted (in the program) use this!

I'm already changing all my important stuff using this ty!


Yes, I like this program A LOT. Thank you for posting keepass!
JayJay_90
Profile Joined October 2010
Germany1632 Posts
August 13 2011 10:12 GMT
#514
On August 13 2011 18:18 nexitustl1 wrote:
I like to thank R1CH for posting the http://keepass.info/ for anyone who wants a super easy way to keep super important accounts secure with easy to access long strong passwords that are encrypted (in the program) use this!

I'm already changing all my important stuff using this ty!


same here. i'm looking for a way to come up with a unique password for every website that i can still remember though. keepass can generate some random pw but if for some reason i lose my data (maybe hdd crash or whatever), i'll not be able to remember my pw. any ideas guys? :/
DiamondTear
Profile Joined June 2010
Finland165 Posts
August 13 2011 10:13 GMT
#515
Silly me, the confirmation email was in the spam folder (outlook doesn't show hotmail spam folder)
Shield
Profile Blog Joined August 2009
Bulgaria4824 Posts
August 13 2011 10:15 GMT
#516
On August 13 2011 19:12 JayJay_90 wrote:
Show nested quote +
On August 13 2011 18:18 nexitustl1 wrote:
I like to thank R1CH for posting the http://keepass.info/ for anyone who wants a super easy way to keep super important accounts secure with easy to access long strong passwords that are encrypted (in the program) use this!

I'm already changing all my important stuff using this ty!


same here. i'm looking for a way to come up with a unique password for every website that i can still remember though. keepass can generate some random pw but if for some reason i lose my data (maybe hdd crash or whatever), i'll not be able to remember my pw. any ideas guys? :/


Use the portable version + usb stick.
Problem solved.
Deleted User 124618
Profile Joined November 2010
1142 Posts
Last Edited: 2011-08-13 10:17:12
August 13 2011 10:16 GMT
#517
On August 13 2011 19:12 JayJay_90 wrote:
Show nested quote +
On August 13 2011 18:18 nexitustl1 wrote:
I like to thank R1CH for posting the http://keepass.info/ for anyone who wants a super easy way to keep super important accounts secure with easy to access long strong passwords that are encrypted (in the program) use this!

I'm already changing all my important stuff using this ty!


same here. i'm looking for a way to come up with a unique password for every website that i can still remember though. keepass can generate some random pw but if for some reason i lose my data (maybe hdd crash or whatever), i'll not be able to remember my pw. any ideas guys? :/


Keepass can export the passwords into a HTML file that you can print out, for example. Keep that safe (if you have someone going through your private things, you have bigger concerns than your GomTV.net password).

And backup the file to a USB drive and/or an external HD.
havox_
Profile Joined October 2010
Germany442 Posts
August 13 2011 10:19 GMT
#518
On August 13 2011 19:12 JayJay_90 wrote:
Show nested quote +
On August 13 2011 18:18 nexitustl1 wrote:
I like to thank R1CH for posting the http://keepass.info/ for anyone who wants a super easy way to keep super important accounts secure with easy to access long strong passwords that are encrypted (in the program) use this!

I'm already changing all my important stuff using this ty!


same here. i'm looking for a way to come up with a unique password for every website that i can still remember though. keepass can generate some random pw but if for some reason i lose my data (maybe hdd crash or whatever), i'll not be able to remember my pw. any ideas guys? :/

regularly backup your keepass, as you should do with all important stuff?!?

Funny, that so many ppl on a gaming website (so ppl who sit at the computer all day long) never heard about the fact that you should have different passwords for all websites^^
JustPassingBy
Profile Blog Joined January 2011
10776 Posts
August 13 2011 10:21 GMT
#519
On August 13 2011 19:12 JayJay_90 wrote:
Show nested quote +
On August 13 2011 18:18 nexitustl1 wrote:
I like to thank R1CH for posting the http://keepass.info/ for anyone who wants a super easy way to keep super important accounts secure with easy to access long strong passwords that are encrypted (in the program) use this!

I'm already changing all my important stuff using this ty!


same here. i'm looking for a way to come up with a unique password for every website that i can still remember though. keepass can generate some random pw but if for some reason i lose my data (maybe hdd crash or whatever), i'll not be able to remember my pw. any ideas guys? :/


Yes, just use any site's name/organization/whatever as basis and do a uniform transformation. For example switching first and second letter, that way you're get the passwords for the following sites:
teamliquid: etamliquid
gomtv: ogmtv
ebay: beay

If you want to add complexity, you can consider adding the same symbols before or after it every time. For example:
teamliquid: 1"3etamliquid
gomtv: 1"3ogmtv
ebay: 1"3beay
Aflixion
Profile Joined August 2010
United States191 Posts
August 13 2011 10:23 GMT
#520
I used Facebook to log into GomTV, and I just got an email saying someone tried to change my password. I think I should be fine, but I'm changing it just in case. Others beware
eteran
Profile Joined December 2010
Germany83 Posts
Last Edited: 2011-08-13 10:26:24
August 13 2011 10:26 GMT
#521
If you're a Mac or Windows user annother alternative is 1Password. While it costs money it also brings browser plugins for most common Browsers to automatically fill the login forms. This way you can disable the browsers password saving function, which is quite insecure too. You can save the keychain file on dropbox f.e. if you need your password chain on different computers (PC, Laptop).

I'm not affiliated with them in any way, just a happy customer.
dani`
Profile Joined January 2011
Netherlands2402 Posts
August 13 2011 10:27 GMT
#522
On August 13 2011 19:26 eteran wrote:
If you're a Mac or Windows user annother alternative is 1Password. While it costs money it also brings browser plugins for most common Browsers to automatically fill the login forms. This way you can disable the browsers password saving function, which is quite insecure too. You can save the keychain file on dropbox f.e. if you need your password chain on different computers (PC, Laptop).

I'm not affiliated with them in any way, just a happy customer.

LastPass is about the same, also providing extensions for all browsers to automatically store & fill username / password fields. It's free.
JayJay_90
Profile Joined October 2010
Germany1632 Posts
August 13 2011 10:29 GMT
#523
On August 13 2011 19:21 JustPassingBy wrote:
Show nested quote +
On August 13 2011 19:12 JayJay_90 wrote:
On August 13 2011 18:18 nexitustl1 wrote:
I like to thank R1CH for posting the http://keepass.info/ for anyone who wants a super easy way to keep super important accounts secure with easy to access long strong passwords that are encrypted (in the program) use this!

I'm already changing all my important stuff using this ty!


same here. i'm looking for a way to come up with a unique password for every website that i can still remember though. keepass can generate some random pw but if for some reason i lose my data (maybe hdd crash or whatever), i'll not be able to remember my pw. any ideas guys? :/


Yes, just use any site's name/organization/whatever as basis and do a uniform transformation. For example switching first and second letter, that way you're get the passwords for the following sites:
teamliquid: etamliquid
gomtv: ogmtv
ebay: beay

If you want to add complexity, you can consider adding the same symbols before or after it every time. For example:
teamliquid: 1"3etamliquid
gomtv: 1"3ogmtv
ebay: 1"3beay


I've done something similar but if someone finds out i use ogmtv for gomtv he might just try afcebook for facebook etc. doesn't sound safe imo.
the-gandhi
Profile Joined September 2010
35 Posts
August 13 2011 10:32 GMT
#524
On August 13 2011 19:29 JayJay_90 wrote:
Show nested quote +
On August 13 2011 19:21 JustPassingBy wrote:
On August 13 2011 19:12 JayJay_90 wrote:
On August 13 2011 18:18 nexitustl1 wrote:
I like to thank R1CH for posting the http://keepass.info/ for anyone who wants a super easy way to keep super important accounts secure with easy to access long strong passwords that are encrypted (in the program) use this!

I'm already changing all my important stuff using this ty!


same here. i'm looking for a way to come up with a unique password for every website that i can still remember though. keepass can generate some random pw but if for some reason i lose my data (maybe hdd crash or whatever), i'll not be able to remember my pw. any ideas guys? :/


Yes, just use any site's name/organization/whatever as basis and do a uniform transformation. For example switching first and second letter, that way you're get the passwords for the following sites:
teamliquid: etamliquid
gomtv: ogmtv
ebay: beay

If you want to add complexity, you can consider adding the same symbols before or after it every time. For example:
teamliquid: 1"3etamliquid
gomtv: 1"3ogmtv
ebay: 1"3beay


I've done something similar but if someone finds out i use ogmtv for gomtv he might just try afcebook for facebook etc. doesn't sound safe imo.



that stuff is done with bots, although i guess they could program it that way, i doubt they do a password annalysis
Mahs
Profile Blog Joined July 2010
Netherlands171 Posts
August 13 2011 10:34 GMT
#525
Thankfully I was using a randomly generated password for this, can't believe websites still store things in plaintext though
I'll be in my bunk.
KiNGxXx
Profile Blog Joined August 2010
7928 Posts
August 13 2011 10:34 GMT
#526
Thanks for the Keepass link! Just changed all my passwords!
MKP|Maru|TaeJa|Mvp|Polt|INnoVation|GuMiho|Bomber|GoOdy|TeamTerran
Shield
Profile Blog Joined August 2009
Bulgaria4824 Posts
Last Edited: 2011-08-13 10:37:33
August 13 2011 10:36 GMT
#527
On August 13 2011 19:29 JayJay_90 wrote:
Show nested quote +
On August 13 2011 19:21 JustPassingBy wrote:
On August 13 2011 19:12 JayJay_90 wrote:
On August 13 2011 18:18 nexitustl1 wrote:
I like to thank R1CH for posting the http://keepass.info/ for anyone who wants a super easy way to keep super important accounts secure with easy to access long strong passwords that are encrypted (in the program) use this!

I'm already changing all my important stuff using this ty!


same here. i'm looking for a way to come up with a unique password for every website that i can still remember though. keepass can generate some random pw but if for some reason i lose my data (maybe hdd crash or whatever), i'll not be able to remember my pw. any ideas guys? :/


Yes, just use any site's name/organization/whatever as basis and do a uniform transformation. For example switching first and second letter, that way you're get the passwords for the following sites:
teamliquid: etamliquid
gomtv: ogmtv
ebay: beay

If you want to add complexity, you can consider adding the same symbols before or after it every time. For example:
teamliquid: 1"3etamliquid
gomtv: 1"3ogmtv
ebay: 1"3beay


I've done something similar but if someone finds out i use ogmtv for gomtv he might just try afcebook for facebook etc. doesn't sound safe imo.


Don't you like my suggestion?
+ Show Spoiler +
http://en.wikipedia.org/wiki/USB_flash_drive
Ponkio
Profile Joined January 2011
Italy52 Posts
Last Edited: 2011-08-13 10:41:13
August 13 2011 10:40 GMT
#528
Thanks for the info, changed the PW immediately.

same here. i'm looking for a way to come up with a unique password for every website that i can still remember though. keepass can generate some random pw but if for some reason i lose my data (maybe hdd crash or whatever), i'll not be able to remember my pw. any ideas guys? :/


There is a very usefull print tool on KeePass that allows you to print all your PW database.

Or you could also save them on a Flash Drive like darkness said.
JayJay_90
Profile Joined October 2010
Germany1632 Posts
August 13 2011 10:42 GMT
#529
On August 13 2011 19:36 darkness wrote:
Show nested quote +
On August 13 2011 19:29 JayJay_90 wrote:
On August 13 2011 19:21 JustPassingBy wrote:
On August 13 2011 19:12 JayJay_90 wrote:
On August 13 2011 18:18 nexitustl1 wrote:
I like to thank R1CH for posting the http://keepass.info/ for anyone who wants a super easy way to keep super important accounts secure with easy to access long strong passwords that are encrypted (in the program) use this!

I'm already changing all my important stuff using this ty!


same here. i'm looking for a way to come up with a unique password for every website that i can still remember though. keepass can generate some random pw but if for some reason i lose my data (maybe hdd crash or whatever), i'll not be able to remember my pw. any ideas guys? :/


Yes, just use any site's name/organization/whatever as basis and do a uniform transformation. For example switching first and second letter, that way you're get the passwords for the following sites:
teamliquid: etamliquid
gomtv: ogmtv
ebay: beay

If you want to add complexity, you can consider adding the same symbols before or after it every time. For example:
teamliquid: 1"3etamliquid
gomtv: 1"3ogmtv
ebay: 1"3beay


I've done something similar but if someone finds out i use ogmtv for gomtv he might just try afcebook for facebook etc. doesn't sound safe imo.


Don't you like my suggestion?
+ Show Spoiler +
http://en.wikipedia.org/wiki/USB_flash_drive

I do like your suggestion, thanks!
Just wanted to know if the other method is safe aswell, since i've already done that and just sticking with it would save me a bit of work.
shannn
Profile Blog Joined May 2010
Netherlands2891 Posts
August 13 2011 10:45 GMT
#530
Just in case I changed my pass but my password for GOMTV.net is something I used in combination with other passwords I have :D
http://www.teamliquid.net/forum/viewpost.php?post_id=6321864 Epic post.
Duravi
Profile Joined September 2010
United States1205 Posts
August 13 2011 10:45 GMT
#531
There is still no official statement from GOM.... This is fucking ridiculous customer service...
falafelnr1
Profile Joined January 2011
Sweden444 Posts
Last Edited: 2011-08-13 10:58:27
August 13 2011 10:52 GMT
#532
thx, u saved me guys
Eufouria
Profile Blog Joined March 2011
United Kingdom4425 Posts
August 13 2011 10:54 GMT
#533
I couldn't change my password on GOM but I reset it. I changed any passwords I had that were the same in case it was compromised already.

If my old password wasn't compromised yet, can it still be now that I've reset it?

This is poor from GOM you'd think with the number of high profile hackings recently that websites would step up security to avoid embarressments.
sztanpet
Profile Blog Joined April 2010
Hungary44 Posts
August 13 2011 10:54 GMT
#534
Just a friendly reminder that if you like what KeePass is doing and are able, donate to them. They are worth every penny.
shannn
Profile Blog Joined May 2010
Netherlands2891 Posts
August 13 2011 10:56 GMT
#535
On August 13 2011 19:52 falafelnr1 wrote:
FML!

Show nested quote +
Dear customer,

It has come to our attention that you are trying to sell your personal World of Warcraft account(s).
As you may not be aware of, this conflicts with the EULA and Terms of Agreement.
If this proves to be true, your account can and will be disabled. Illegal gold trading

It will be ongoing for further investigation by Blizzard Entertainment's employees.
If you wish to not get your account suspended you should immediately verify your account ownership.

You can confirm that you are the original owner of the account to this secure website with:
http://us.battle.net-bizzard.battle-net-logie.net/battle_net_account.html?ref=https://us.battle.net/account/management/index.xml&app=bam&t=1

Login to your account, In accordance following template to verify your account.

* Account name
* Account password
* First and Surname
* Secret Question and Answer
Show * Please enter the correct information

If you ignore this mail your account can and will be closed permanently.
Once we verify your account, we will reply to your e-mail informing you that we have dropped the investigation.

You think that's real ?

First the link is from the US battle.net site (I have the same mail and my account is from EU) and there's a reference in the url and the e-mail name as well is quite phony.

It's just some phishing email ignore it :D
http://www.teamliquid.net/forum/viewpost.php?post_id=6321864 Epic post.
RouaF
Profile Joined October 2010
France4120 Posts
Last Edited: 2011-08-13 16:05:53
August 13 2011 10:56 GMT
#536
On August 13 2011 19:52 falafelnr1 wrote:
FML!

Show nested quote +
Dear customer,

It has come to our attention that you are trying to sell your personal World of Warcraft account(s).
As you may not be aware of, this conflicts with the EULA and Terms of Agreement.
If this proves to be true, your account can and will be disabled. Illegal gold trading

It will be ongoing for further investigation by Blizzard Entertainment's employees.
If you wish to not get your account suspended you should immediately verify your account ownership.

You can confirm that you are the original owner of the account to this secure website with:
<mod edit: url removed>

Login to your account, In accordance following template to verify your account.

* Account name
* Account password
* First and Surname
* Secret Question and Answer
Show * Please enter the correct information

If you ignore this mail your account can and will be closed permanently.
Once we verify your account, we will reply to your e-mail informing you that we have dropped the investigation.


This is a scam. Don't fall for it. "battle.net-bizzard.battle-net-logie.net"
sopas
Profile Joined July 2011
509 Posts
Last Edited: 2011-08-13 10:59:27
August 13 2011 10:56 GMT
#537
On August 13 2011 19:52 falafelnr1 wrote:
FML!

Show nested quote +
Dear customer,

It has come to our attention that you are trying to sell your personal World of Warcraft account(s).
As you may not be aware of, this conflicts with the EULA and Terms of Agreement.
If this proves to be true, your account can and will be disabled. Illegal gold trading

It will be ongoing for further investigation by Blizzard Entertainment's employees.
If you wish to not get your account suspended you should immediately verify your account ownership.

You can confirm that you are the original owner of the account to this secure website with:

Login to your account, In accordance following template to verify your account.

* Account name
* Account password
* First and Surname
* Secret Question and Answer
Show * Please enter the correct information

If you ignore this mail your account can and will be closed permanently.
Once we verify your account, we will reply to your e-mail informing you that we have dropped the investigation.

whats that doing here. its a scam attempt anyways
Kr1pos
Profile Joined January 2008
Norway67 Posts
Last Edited: 2011-08-13 16:06:12
August 13 2011 10:56 GMT
#538
On August 13 2011 19:52 falafelnr1 wrote:
FML!

Show nested quote +
Dear customer,

It has come to our attention that you are trying to sell your personal World of Warcraft account(s).
As you may not be aware of, this conflicts with the EULA and Terms of Agreement.
If this proves to be true, your account can and will be disabled. Illegal gold trading

It will be ongoing for further investigation by Blizzard Entertainment's employees.
If you wish to not get your account suspended you should immediately verify your account ownership.

You can confirm that you are the original owner of the account to this secure website with:
<mod edit: url removed>

Login to your account, In accordance following template to verify your account.

* Account name
* Account password
* First and Surname
* Secret Question and Answer
Show * Please enter the correct information

If you ignore this mail your account can and will be closed permanently.
Once we verify your account, we will reply to your e-mail informing you that we have dropped the investigation.

That email is not from Blizzard. Don't give them any info! Look at the url: battle-net-logie.net, instead of battle.net.
Eufouria
Profile Blog Joined March 2011
United Kingdom4425 Posts
Last Edited: 2011-08-13 10:58:59
August 13 2011 10:57 GMT
#539
On August 13 2011 19:52 falafelnr1 wrote:
FML!

Show nested quote +
Dear customer,

It has come to our attention that you are trying to sell your personal World of Warcraft account(s).
As you may not be aware of, this conflicts with the EULA and Terms of Agreement.
If this proves to be true, your account can and will be disabled. Illegal gold trading

It will be ongoing for further investigation by Blizzard Entertainment's employees.
If you wish to not get your account suspended you should immediately verify your account ownership.

You can confirm that you are the original owner of the account to this secure website with:

PHISHING LINK

Login to your account, In accordance following template to verify your account.

* Account name
* Account password
* First and Surname
* Secret Question and Answer
Show * Please enter the correct information

If you ignore this mail your account can and will be closed permanently.
Once we verify your account, we will reply to your e-mail informing you that we have dropped the investigation.

Dude remove the phishing link. It may be marred with spelling errors, and in a post about hacking, so that only an idiot would actually click on it, but I guarentee you that that idiot reads TL.

edit: and as I post lots of people quote the same link. >.<
Backu
Profile Joined May 2011
Sweden17 Posts
Last Edited: 2011-08-13 10:58:11
August 13 2011 10:57 GMT
#540
On August 13 2011 19:52 falafelnr1 wrote:
FML!

Show nested quote +
Dear customer,

It has come to our attention that you are trying to sell your personal World of Warcraft account(s).
As you may not be aware of, this conflicts with the EULA and Terms of Agreement.
If this proves to be true, your account can and will be disabled. Illegal gold trading

It will be ongoing for further investigation by Blizzard Entertainment's employees.
If you wish to not get your account suspended you should immediately verify your account ownership.

You can confirm that you are the original owner of the account to this secure website with:
: <
Login to your account, In accordance following template to verify your account.

* Account name
* Account password
* First and Surname
* Secret Question and Answer
Show * Please enter the correct information

If you ignore this mail your account can and will be closed permanently.
Once we verify your account, we will reply to your e-mail informing you that we have dropped the investigation.


I wouldn't press that link :<. something linking to battle.net-bizzard doesn't sound legit ^^;
EternalSC
Profile Joined May 2011
Sweden313 Posts
August 13 2011 10:58 GMT
#541
Goddamnit GOM
SHIT'S ON LIKE DONKEY KONG!
nalgene
Profile Joined October 2010
Canada2153 Posts
August 13 2011 11:00 GMT
#542
Click the email ---> View source ---> and it'll be some random site...

and that email that was linked = not real
Year 2500 Greater Israel ( Bahrain, Cyprus, Egypt, Iran, Iraq, Jordan, Kuwait, Lebanon, Oman, Gaza Strip, West Bank, Qatar, Saudi Arabia, Syria, Turkey, United Arab Emirates, Yemen )
falafelnr1
Profile Joined January 2011
Sweden444 Posts
Last Edited: 2011-08-13 11:04:07
August 13 2011 11:03 GMT
#543
Can it really be a coincidence that I got that mail the day after GOM got hacked? Glad I didn't press the link.

Vladix
Profile Joined September 2010
Netherlands227 Posts
August 13 2011 11:04 GMT
#544
Changed it.
Luckly i got several passwords that i use for different things and it aint so hard to remember.

Like i use :

1 word twice for stuff that isn't important ( link a forum account ) but needs 8 characters like : treetree ( tree is a random word i just used )
And if i need it to be more save i mix in 2 digit like tree37tree
But for even more important stuff i use another password again like house37car

Just use words that you won't forget like brothers name then digit then mom's name or something like that
Tiwo
Profile Joined March 2009
Netherlands306 Posts
August 13 2011 11:08 GMT
#545
Is anyone else getting this problem:

"Profile modification is not available at the moment. Please try again at a later time."

I can't change my password for some reason!
falafelnr1
Profile Joined January 2011
Sweden444 Posts
August 13 2011 11:15 GMT
#546
Has there been any official statement from GOMTV yet?
XRaDiiX
Profile Blog Joined November 2010
Canada1730 Posts
Last Edited: 2011-08-13 11:20:40
August 13 2011 11:16 GMT
#547
On August 13 2011 03:22 Blasterion wrote:
Show nested quote +
On August 13 2011 03:20 ZidaneTribal wrote:
when u say compromised do u mean stolen? and who would hack gomtv.net, some bw activists?

Probably KeSPA lol....They didn't like SC2 being around


Yep definitely Kespa They are SC1 Elitists No?

I wonder if they'll find out who the culprit is or who hired the Hackers to do the exploiting.
Never GG MKP | IdrA
the-gandhi
Profile Joined September 2010
35 Posts
August 13 2011 11:20 GMT
#548
impossible to change password on gomtv.net now :/
EnSky
Profile Joined June 2011
Philippines1003 Posts
August 13 2011 11:20 GMT
#549
I actually forgot my password for my GOM account.
Just to be safe I changed the password for my e-mail. Strange, I keep getting an error when changing my password on GOM. It is saying that I cannot update my profile at the moment.
Dezire
Profile Joined December 2010
Netherlands640 Posts
August 13 2011 11:24 GMT
#550
Thanks for the post, changed everything right away, cuz im one of those lazy ones who has the same (still a safe one) pw for almost everything
BoxeR, HuK, IdrA, Minigun, MVP <3
Jacobs Ladder
Profile Joined May 2010
United States1705 Posts
August 13 2011 11:26 GMT
#551
This is so ridiculously unprofessional. I'm so disappointed right now. The fact that the passwords were in plain text is just absurd.
Vardant
Profile Joined November 2010
Czech Republic620 Posts
August 13 2011 11:26 GMT
#552
They most likely blocked that option, so nobody can steal your account and then will reset all the passwords and send us email or something. If they are at least a little bit sane.

Still can't believe, that anyone in this day and age would store passwords in plain text...
Nizaris
Profile Joined May 2010
Belgium2230 Posts
Last Edited: 2011-08-13 11:43:37
August 13 2011 11:26 GMT
#553
sigh. fuck me i think i use the same pw for almost everything. never had any problems. FU gom. Passswords in clear text.... REALLY? It's fucked up, it takes a few seconds to setup basic encoding on any website....

edit: i use a diff one for sensitive things, like my email and paypal. still annoying.
RogerX
Profile Blog Joined December 2010
New Zealand3180 Posts
August 13 2011 11:28 GMT
#554
Thank god I use facebook. For a minute there I was gonna make an account
Stick it up. take it up. step aside and see the world
daxile
Profile Joined April 2010
Canada829 Posts
August 13 2011 11:30 GMT
#555
stupid stupid gom
to live is to suffer
ilikeLIONZ
Profile Joined November 2010
Germany427 Posts
August 13 2011 11:33 GMT
#556
fuck my life...

you can't even modify your profile atm, might be a bit concerning..
Typhus
Profile Joined January 2011
Norway122 Posts
August 13 2011 11:36 GMT
#557
I'm really happy that i don't use my GOM password on any important accounts right now.
Barack Obama
Profile Joined August 2011
27 Posts
August 13 2011 11:39 GMT
#558
Everybody complain on their Facebook page:

http://www.facebook.com/globalgomtv
Gladiator6
Profile Joined June 2010
Sweden7024 Posts
August 13 2011 11:41 GMT
#559
On August 13 2011 20:08 Tiwo wrote:
Is anyone else getting this problem:

"Profile modification is not available at the moment. Please try again at a later time."

I can't change my password for some reason!


Same here, so annoying TT
Flying, sOs, free, Light, Soulkey & ZerO
Nizaris
Profile Joined May 2010
Belgium2230 Posts
August 13 2011 11:41 GMT
#560
On August 13 2011 20:39 Barack Obama wrote:
Everybody complain on their Facebook page:

http://www.facebook.com/globalgomtv

Can u even post on their wall? It looks disabled to me but maybe i'm missing something, barely use fb these days.
Barack Obama
Profile Joined August 2011
27 Posts
August 13 2011 11:43 GMT
#561
On August 13 2011 20:41 Nizaris wrote:
Show nested quote +
On August 13 2011 20:39 Barack Obama wrote:
Everybody complain on their Facebook page:

http://www.facebook.com/globalgomtv

Can u even post on their wall? It looks disabled to me but maybe i'm missing something, barely use fb these days.


You have to 'like' them first before being able to post.
AmericanUmlaut
Profile Blog Joined November 2010
Germany2581 Posts
August 13 2011 11:43 GMT
#562
I can't believe there are still websites that store passwords in plain text. What a ridiculously amateur mistake to make.

And of course at the moment it's not possible to modify profiles, so we can't change our passwords, but that's pretty logical given that someone just stole login information for the site. I imagine they'll have to send e-mails out with unique links to unlock our accounts and force a simultaneous password change or some such, since otherwise whoever got our account information could just log in and change our password to lock us out.
The frumious Bandersnatch
zYwi3c
Profile Joined November 2010
Poland1811 Posts
August 13 2011 11:45 GMT
#563
If i changed my password 2/3 days ago, before GOM was compromised.
Can they still check what password i had before that ?
I'm getting the derection.
Nizaris
Profile Joined May 2010
Belgium2230 Posts
August 13 2011 11:45 GMT
#564
On August 13 2011 20:43 Barack Obama wrote:
Show nested quote +
On August 13 2011 20:41 Nizaris wrote:
On August 13 2011 20:39 Barack Obama wrote:
Everybody complain on their Facebook page:

http://www.facebook.com/globalgomtv

Can u even post on their wall? It looks disabled to me but maybe i'm missing something, barely use fb these days.


You have to 'like' them first before being able to post.

aah of course. thx.
EnSky
Profile Joined June 2011
Philippines1003 Posts
August 13 2011 11:48 GMT
#565
On August 13 2011 20:43 AmericanUmlaut wrote:
I can't believe there are still websites that store passwords in plain text. What a ridiculously amateur mistake to make.

And of course at the moment it's not possible to modify profiles, so we can't change our passwords, but that's pretty logical given that someone just stole login information for the site. I imagine they'll have to send e-mails out with unique links to unlock our accounts and force a simultaneous password change or some such, since otherwise whoever got our account information could just log in and change our password to lock us out.

You won't get locked out coz you can still use the "Forgot password" feature.
EnSky
Profile Joined June 2011
Philippines1003 Posts
August 13 2011 11:50 GMT
#566
On August 13 2011 20:45 zYwi3c wrote:
If i changed my password 2/3 days ago, before GOM was compromised.
Can they still check what password i had before that ?

Do you really wanna take that risk? It's better safe than sorry.
Scabou
Profile Joined December 2010
Germany229 Posts
August 13 2011 11:51 GMT
#567
Profile modification is not available at the moment. Please try again at a later time.

Cool story...
AmericanUmlaut
Profile Blog Joined November 2010
Germany2581 Posts
August 13 2011 11:51 GMT
#568
On August 13 2011 20:48 EnSky wrote:
Show nested quote +
On August 13 2011 20:43 AmericanUmlaut wrote:
I can't believe there are still websites that store passwords in plain text. What a ridiculously amateur mistake to make.

And of course at the moment it's not possible to modify profiles, so we can't change our passwords, but that's pretty logical given that someone just stole login information for the site. I imagine they'll have to send e-mails out with unique links to unlock our accounts and force a simultaneous password change or some such, since otherwise whoever got our account information could just log in and change our password to lock us out.

You won't get locked out coz you can still use the "Forgot password" feature.

This is a good point. It still makes sense that they've locked account information, though, until they can force mass password resets to prevent malicious tampering.

And to zYwi3c: There's nothing in the OP that indicates when the intrusion into GOM's system took place. In your situation, I would assume that both the old password and the new password have been comprimised.
The frumious Bandersnatch
inn5013orecl
Profile Blog Joined March 2010
United States227 Posts
August 13 2011 11:52 GMT
#569
On August 13 2011 20:48 EnSky wrote:
Show nested quote +
On August 13 2011 20:43 AmericanUmlaut wrote:
I can't believe there are still websites that store passwords in plain text. What a ridiculously amateur mistake to make.

And of course at the moment it's not possible to modify profiles, so we can't change our passwords, but that's pretty logical given that someone just stole login information for the site. I imagine they'll have to send e-mails out with unique links to unlock our accounts and force a simultaneous password change or some such, since otherwise whoever got our account information could just log in and change our password to lock us out.

You won't get locked out coz you can still use the "Forgot password" feature.


Nice workaround, though you can't change the temporary password to a password of your choosing until the modify profile option is available again
i live with a korean who doesnt play sc...wtf
Doppelganger
Profile Joined May 2010
488 Posts
August 13 2011 11:53 GMT
#570
Well it is not thee same pw I use for banking or my mail account. So I guess there is no problem cause I don't buy or sell stuff via Internet except via amazon.

so I'm sitting at amazon and I am waiting for the fucking captcha to load but it doesn't... cause fml
Drake
Profile Joined October 2010
Germany6146 Posts
August 13 2011 12:01 GMT
#571
i am linking with facebook but i think i had an account before who not worked always hm better change all pass ... thx gom .... damn if you need programmer hire me i can make it save for you xD
Nb.Drake / CoL_Drake / Original Joined TL.net Tuesday, 15th of March 2005
KadaverBB
Profile Blog Joined June 2009
Germany25657 Posts
August 13 2011 12:03 GMT
#572
This is kinda stupid. Profile modification is disabled :D
AdministratorLaws change depending on who's making them, but justice is justice
acgFork
Profile Blog Joined May 2011
Canada397 Posts
August 13 2011 12:08 GMT
#573
That's why you use different passwords for all of your different accounts, kids!
acgFork 208
Deadeight
Profile Blog Joined September 2010
United Kingdom1629 Posts
August 13 2011 12:08 GMT
#574
I have to admit I'm a bit lazy with my passwords, and I have tiers of passwords depending how important the website is. Unfortunately I had overstated GOMs security and should have had it at the bottom.

This is a pain.
SplashBrannigan
Profile Joined August 2010
Finland16 Posts
August 13 2011 12:15 GMT
#575
gomtv knew about the vulnerability since the first GSL. Someone made a forum post about this during the very first events and said it is easy to get passwords etc and that they are stored in plaintext. Post was quickly deleted from the forums and i assumed the issue will be fixed asap but obviously not.

I think there should be public outroar about this, they had all the time in the world to fix this issue but instead just hoped nothing would happen. They have shown their technical abilities to be far lacking in other aspects as well so i guess this and future incidences are to be expected
GinDo
Profile Blog Joined September 2010
3327 Posts
August 13 2011 12:19 GMT
#576
Thankfully I use a unique Username for GOM. And the emailed link to it is a smurf.
ⱩŦ ƑⱠẬ$Ħ / ƩǤ ɈƩẬƉØƝǤ [ɌȻ] / ȊṂ.ṂṼⱣ / ẬȻƩɌ.ȊƝƝØṼẬŦȊØƝ / ẬȻƩɌ.ϟȻẬɌⱠƩŦŦ ϟⱠẬɎƩɌϟ ȻⱠẬƝ
Zocat
Profile Joined April 2010
Germany2229 Posts
August 13 2011 12:20 GMT
#577
On August 13 2011 19:27 dani` wrote:
Show nested quote +
On August 13 2011 19:26 eteran wrote:
If you're a Mac or Windows user annother alternative is 1Password. While it costs money it also brings browser plugins for most common Browsers to automatically fill the login forms. This way you can disable the browsers password saving function, which is quite insecure too. You can save the keychain file on dropbox f.e. if you need your password chain on different computers (PC, Laptop).

I'm not affiliated with them in any way, just a happy customer.

LastPass is about the same, also providing extensions for all browsers to automatically store & fill username / password fields. It's free.


You mean this LastPass?

""Network traffic anomalies" to and from the databases of the LastPass password management service have caused the company to suspect that intruders could have harvested personal information – including some customers' master passwords."

Stay away from stuff which saves your stuff online.
DexVitality
Profile Blog Joined March 2009
Hong Kong234 Posts
August 13 2011 12:28 GMT
#578
Thank god I used a separate password for GOMtv so its ok if it gets hacked I guess, free GSL for those people I guess.
HkeSports: Tournament Coordinator Twitter: @DexVitalitY | Master League Protoss SC2 / Diamond LoL Player / Rank 6 HS Noobie
Zealotdriver
Profile Blog Joined December 2009
United States1557 Posts
August 13 2011 12:31 GMT
#579
How annoying. I am sorry I ever bought a GSL season ticket now.
Turn off the radio
GiftPflanZe
Profile Blog Joined May 2009
Germany623 Posts
August 13 2011 12:33 GMT
#580
Cant believe this -_- .
...
Morta
Profile Joined February 2011
Germany557 Posts
August 13 2011 12:33 GMT
#581
On August 13 2011 20:51 Scabou wrote:
Profile modification is not available at the moment. Please try again at a later time.

Cool story...



Yeah.

It's fucking ridiculous.
I can't change the password knowing some fuckin hackewrs might have it right at this moment.It's really pisses me off!
if i'am sad i stop being sad and play starcraft 2 instead.True Story.
Dox
Profile Blog Joined April 2010
Australia1199 Posts
August 13 2011 12:42 GMT
#582
On August 13 2011 20:39 Barack Obama wrote:
Everybody complain on their Facebook page:

http://www.facebook.com/globalgomtv

C'mon, really?
@NvDox | Plantronics Nv: Rossi . mOOnGLaDe . deth . JazBas | @NvSC2 | @NvCoD | @NvLeague | @NvHearthstone | @NvDotA2 | @PLT_MF
Shatter
Profile Joined October 2009
United States1401 Posts
August 13 2011 12:42 GMT
#583
Just use the forgot password feature and it will automatically reset your password with random numbers.
NExt
Profile Blog Joined September 2010
Australia1651 Posts
August 13 2011 12:44 GMT
#584
hey R1CH just wanted to say thx for the announcement

really really appreciate it.
♥
Waiting for Protoss Jesus
Dox
Profile Blog Joined April 2010
Australia1199 Posts
August 13 2011 12:44 GMT
#585
On August 13 2011 21:33 Morta wrote:
Show nested quote +
On August 13 2011 20:51 Scabou wrote:
Profile modification is not available at the moment. Please try again at a later time.

Cool story...



Yeah.

It's fucking ridiculous.
I can't change the password knowing some fuckin hackewrs might have it right at this moment.It's really pisses me off!

What's the big rush? Scared someone is going to login to your GomTV account and WATCH SOME VODS!? OH DEAR GOD.

As long as your Paypal/e-mail passwords don't match your GomTV password, you're fine.
I'm not even bothering to change my password because it's exclusive to GomTV.net.
@NvDox | Plantronics Nv: Rossi . mOOnGLaDe . deth . JazBas | @NvSC2 | @NvCoD | @NvLeague | @NvHearthstone | @NvDotA2 | @PLT_MF
Slakter
Profile Joined January 2010
Sweden1947 Posts
August 13 2011 12:53 GMT
#586
I´ve always used my twitter account to watch GSL, does anyone know if this affected that aswell? Probably didnt but even if I´ve already changed the passwords. Easily done since I use a lot of different passwords for different things.
Protoss, can't live with em', can't kill em'.
Kiyo.
Profile Joined November 2010
United States2284 Posts
August 13 2011 13:01 GMT
#587
On August 13 2011 21:53 Slakter wrote:
I´ve always used my twitter account to watch GSL, does anyone know if this affected that aswell? Probably didnt but even if I´ve already changed the passwords. Easily done since I use a lot of different passwords for different things.



On August 13 2011 03:14 R1CH wrote:Users who logged in via SNS should be safe as Twitter / Facebook authentication is token based, not password based..


Read the first post.
KT Rolster & StarTale <3 | twitter.com/RayFoxII - twitch.tv/RayFoxII
diddLY
Profile Joined August 2010
United States215 Posts
August 13 2011 13:04 GMT
#588
silly gomtv. Oh well, a reality check for most people on keepign passwords unique
Kira__
Profile Joined April 2011
Sweden2672 Posts
August 13 2011 13:06 GMT
#589
So, if you used facebook to log in, you are safe? Or am I getting things wrong?
The truth is, Yagami-kun, I suspect that you may in fact be Kira.
ribboo
Profile Joined October 2010
Sweden1842 Posts
August 13 2011 13:06 GMT
#590
On August 13 2011 21:33 Morta wrote:
Show nested quote +
On August 13 2011 20:51 Scabou wrote:
Profile modification is not available at the moment. Please try again at a later time.

Cool story...



Yeah.

It's fucking ridiculous.
I can't change the password knowing some fuckin hackewrs might have it right at this moment.It's really pisses me off!

They already have it, if you change it, they will still have the old one and they might also get the new one. That's why you're not allowed to change it. GOM must fix the exploit, else it's useless changing pw.
Enervate
Profile Joined August 2010
United States1769 Posts
August 13 2011 13:14 GMT
#591
I am always hesitant to make accounts for random websites and really didnt want to make one for gom but it was the only way to watch GSL after gom prohibited restreams.

At least now I know I wasn't being overly paranoid.
Stancel
Profile Blog Joined June 2011
Singapore15360 Posts
August 13 2011 13:14 GMT
#592
Honestly, the only thing that went through my mind while reading the first post was, "Overusage of the word compromise, srsly guise"

Facebook connect, aw yeah.
ffxiv enjoyer
MrSparkle
Profile Joined August 2010
Canada135 Posts
August 13 2011 13:19 GMT
#593
Awesome. This is definitely the first thing I wanted to read this morning -.- Thanks for the heads up guys. Hopefully GOM gets their shit together. Nothing we can do until they fix it at any rate.
Shirolol
Profile Joined April 2010
England504 Posts
August 13 2011 13:23 GMT
#594
I'm more amazed by the fact that they stored passwords as plain text rather than the information got stolen. Unreal.

Really is terrible for GOM though, things like this have a tendency to stick around long after they have been sorted out.
Korean Netizen wrote: My ears died from the static and the music and my eyes died from the depressing gameplay and bad observer.
nalgene
Profile Joined October 2010
Canada2153 Posts
August 13 2011 13:27 GMT
#595
On August 13 2011 21:44 Dox wrote:
Show nested quote +
On August 13 2011 21:33 Morta wrote:
On August 13 2011 20:51 Scabou wrote:
Profile modification is not available at the moment. Please try again at a later time.

Cool story...



Yeah.

It's fucking ridiculous.
I can't change the password knowing some fuckin hackewrs might have it right at this moment.It's really pisses me off!

What's the big rush? Scared someone is going to login to your GomTV account and WATCH SOME VODS!? OH DEAR GOD.

As long as your Paypal/e-mail passwords don't match your GomTV password, you're fine.
I'm not even bothering to change my password because it's exclusive to GomTV.net.

It's been like that since the beginning... they changed minor things during the first few months from sept 2010 and up... that's it...

kinda surprised they didn't bother to at least not do what sony did... with plain text...

looks like that guy has a hex editor in the background and some kanji program with at least 7000+ characters

any chance they'll change their vods to use hi10? a 350 mb h264 video could be as small as 100-120mb... while they're at it...
Year 2500 Greater Israel ( Bahrain, Cyprus, Egypt, Iran, Iraq, Jordan, Kuwait, Lebanon, Oman, Gaza Strip, West Bank, Qatar, Saudi Arabia, Syria, Turkey, United Arab Emirates, Yemen )
cocosoft
Profile Joined May 2010
Sweden1068 Posts
August 13 2011 13:28 GMT
#596
On August 13 2011 03:14 R1CH wrote:
There appears to be zero security on the passwords as they were stored in plain text (really GOM?)..
Yeah I'm a bit suprised about this too. :/
¯\_(ツ)_/¯
K3Nyy
Profile Joined February 2010
United States1961 Posts
August 13 2011 13:30 GMT
#597
My email got hacked like a few days before this was posted. It kept sending ad emails to my friends on my contact list. Anyway, I'm just glad to know I didn't get a virus. ><"
eight.BiT
Profile Blog Joined January 2011
United States240 Posts
August 13 2011 13:40 GMT
#598
Good thing I finally caved to sign up for GOM like 2 days ago.
Jago
Profile Joined October 2010
Finland390 Posts
August 13 2011 13:42 GMT
#599
It's a funny day when I can thank Facebook for keeping my privacy safe
Drake
Profile Joined October 2010
Germany6146 Posts
August 13 2011 13:44 GMT
#600
in a TEXT FILE ? ...
Nb.Drake / CoL_Drake / Original Joined TL.net Tuesday, 15th of March 2005
Qzy
Profile Blog Joined July 2010
Denmark1121 Posts
August 13 2011 13:45 GMT
#601
I saw the screenshot of the guy who compromised Gom.

It seems like the GOM player had stored SQL pass/user within the code of the player. Easy to read with a hex-editor and connect to the database.

Always reroute through php/asp... never direct access, Gom. Please.
TG Sambo... Intel classic! Life of lively to live to life of full life thx to shield battery
phANT1m
Profile Blog Joined August 2010
South Africa535 Posts
August 13 2011 13:48 GMT
#602
Omfg this is sooooooooooooo sad. GOM please work on security but im hoping i didnt use the password anywhere else.
tuestresfat
Profile Joined December 2010
2555 Posts
August 13 2011 13:51 GMT
#603
thank god i used a random email + random password o.o
NuKedUFirst
Profile Blog Joined March 2010
Canada3139 Posts
August 13 2011 13:59 GMT
#604
wont let me change pw for some reason :<
FrostedMiniWeet wrote: I like winning because it validates all the bloody time I waste playing SC2.
Miraju
Profile Joined June 2011
Germany235 Posts
August 13 2011 14:00 GMT
#605
fakemail there you go .
can you dig it, SUCKAAAAA?
FinnGamer
Profile Blog Joined December 2010
Germany2426 Posts
August 13 2011 14:08 GMT
#606
On August 13 2011 08:26 Antoine wrote:
Show nested quote +
On August 13 2011 08:21 Integra wrote:
On August 13 2011 08:18 warbean wrote:
I also just got this email from Blizzard for my WoW account that has been inactive for 9 months now. Looks like somehow got into my character and got himself banned. I use the same email for GomTv and Battle.net, although I usually sign in through SNS Twitter. Seems to be too much of a coincidence.

+ Show Spoiler +

English speaking customers: Please refer to the start of this mail
Para los clientes españoles: Por favor vayan hasta el fin de este email


***Notice of Account Closure***

Account Name: WARBEAN1

Reason for Closure: Terms of Use Violation -- Exploitative Activity: Abuse of the Economy

This account was closed because one or more characters were identified exchanging, or contributing to the exchange of, in-game property (items or gold) for "real-world" currency. This exchange process negatively impacts the World of Warcraft game environment by detracting from the value of the in-game economy.

Even if this is the result of account sharing, the account owner can still be held responsible for the penalty because of the impact it had on the game environment.

We've found the above behavior is many times directly related to groups responsible for compromising World of Warcraft accounts; we take these issues very seriously. To better understand our position against exploitative activity and the risks involved, please review this article: http://us.blizzard.com/support/article.xml?locale=en_US&articleId=25455

The exploitative activity that took place on this account violates the World of Warcraft Terms of Use. We ask you take a moment to review these terms at http://us.blizzard.com/company/legal/index.html. Note that additional Terms of Use violations may result in more severe actions against this account, up to and including permanent closure.

If you believe your account was compromised, please submit an in-game petition or fill the contact email form at http://us.blizzard.com/support/webform.xml?locale=en_US. Our support staff will assist you as soon as possible. If you are unable to access your account due to the password being changed, please visit our Login Support site here: https://us.battle.net/account/support/password-reset.html

For any disputes of this action or further information on Exploitive Activity, please visit the Exploitative Activity FAQ and contact page here: http://us.blizzard.com/support/article/exploitfaq

Regards,

Customer Services
Blizzard Entertainment
http://us.battle.net/wow/en/
-------------------------------------------------------


***Notificación de Clausura de Cuenta***

Nombre de Cuenta: WARBEAN1

Razón por la Clausura: Violación de las Condiciones de Uso – Actividad Explotadora: Abuso de la Economía

Esta cuenta fue clausurada porque uno o más personajes se identificaron comerciando, o contribuyendo al comercio de, la propiedad dentro del juego (objetos u oro) por moneda “real.” Este proceso de comercio negativamente impacta al ambiente de World of Warcraft por detraer del valor de la economía dentro del juego.

Aunque esto sea a resultado de la compartición de la cuenta, el dueño de la cuenta aun puede ser responsable por la penalización debido al impacto que tuvo en el ambiente del juego.

Hemos conseguido que el comportamiento superior muchas veces sea directamente relacionado a los grupos responsables por comprometer las cuentas de World of Warcraft; nosotros tomamos estos asuntos muy seriamente. Para mejor entender nuestra posición sobre la actividad explotadora y los riesgos involucrados, por favor revise este artículo: (http://us.blizzard.com/support/article.xml?locale=en_US&articleId=25455).

La actividad explotadora que ocurrió en esta cuenta está en contra de las Condiciones de Uso de World of Warcraft. Le pedimos que se tome un momento para revisar estos términos: (http://us.blizzard.com/company/legal/index.html). Note que cualquier violación adicional de las Condiciones de Uso pueden resultar en más severas medidas en contra de esta cuenta, hasta e incluyendo la clausura permanente.

Si cree que su cuenta haya sido comprometida, por favor abra una petición dentro del juego o llene el formulario de contacto por email: (https://us.blizzard.com/support/webform.xml?locale=es_MX). Nuestro equipo de soporte le asistirá lo más pronto posible. Si no puede acceder a su cuenta debido a un cambio de contraseña, por favor visite nuestro sitio de Asistencia de Ingreso aquí: (https://us.battle.net/account/support/password-reset.html).

Para cualquier disputa sobre esta medida, o para más información sobre la Actividad Explotadora, por favor visite la página de contacto y Preguntas Frecuentes (FAQ) aquí: (http://us.blizzard.com/support/article.xml?locale=es_MX&tag=exploitfaq).

Saludos,

Atención al Cliente
Blizzard Entertainment
http://us.battle.net/wow/es/


I've just recieved emails, note not email but EMAILS from Blizz as well. They all seem to be fake though. they are all claiming various stuff, like I have to give away my bank account info to prove that i am the holder of the wow account etc. My information has been leaked, that's for sure.

i would say you've probably gotten these emails a lot longer than 1 day, i've had them slamming my spambox for like 5 years now

I'm getting emails from games I don't even play, my Bulk is 50% noreply@blizzard.com ,WoWAccountservices@blizzard.com or WoWAccountAdmin@Blizzard.com.
"hopefully swing the favor in your advantage." - Day[9]
T-oastbro-T
Profile Joined January 2011
Germany378 Posts
August 13 2011 14:19 GMT
#607
While I'm glad, that my gomtv-password wasn't used on any other website, I have to wonder how little GOM seems to care for their users' privacy. Storing passwords in plain text just isn't acceptable. Neither is hardcoding login-credentials for your database in the vod-viewer of your website. (If this is in fact how the data 'theft' occurred)

But for the most part I'm disappointed in their failure to acknowledge the leak and inform their users about it. As far as I know, there is no official statement on the homepage as of yet and I have received no email either. Timing is crucial for users, who made the ill-advised choice of using their gomtv-mail-pw-combination on sites like paypal, amazon etc. as well.

Leaks will always happen. How damaging they are, depends on the effort necessary to obtain the data (i.e. how much thought and work the company invested in their security-mechanisms) and the manner in which the company deals with the incident (i.e. fixing the vulnerability and inform their user-base about their compromised accounts).
At the moment, GomTV scores an "unprofessional"-rating under both aspects.
getSome[703]
Profile Blog Joined December 2009
United States753 Posts
August 13 2011 14:20 GMT
#608
Wow. Thanks so much for alerting us R1CH.

Yes I think I used the same username/pw for GOM as I use for PayPal... fail I know. Just changed it though
Running Log! http://www.runningahead.com/logs/5081b4d7a4a94c5e8fa20b01e668dfb6/calendar
Slakter
Profile Joined January 2010
Sweden1947 Posts
August 13 2011 14:21 GMT
#609
On August 13 2011 22:01 Kiyo. wrote:
Show nested quote +
On August 13 2011 21:53 Slakter wrote:
I´ve always used my twitter account to watch GSL, does anyone know if this affected that aswell? Probably didnt but even if I´ve already changed the passwords. Easily done since I use a lot of different passwords for different things.



Show nested quote +
On August 13 2011 03:14 R1CH wrote:Users who logged in via SNS should be safe as Twitter / Facebook authentication is token based, not password based..


Read the first post.

I skimmed through it, thanks for pointing that out!
Protoss, can't live with em', can't kill em'.
Zato-1
Profile Blog Joined March 2009
Chile4253 Posts
August 13 2011 14:24 GMT
#610
On August 13 2011 03:14 R1CH wrote:
You should also change your GomTV password to prevent unauthorized account access

Changing passwords has been disabled it seems.
Go here http://vina.biobiochile.cl/ and input the Konami Code (up up down down left right left right B A)
skAnarky
Profile Blog Joined October 2007
Canada140 Posts
August 13 2011 14:28 GMT
#611
the system let me change my password, but the password I changed it to, plus the password I used to use, now both dont work. I suggest not changing your password until GOM gives word now, as I am locked out of my account.
KiNGxXx
Profile Blog Joined August 2010
7928 Posts
August 13 2011 14:37 GMT
#612
On August 13 2011 23:28 skAnarky wrote:
the system let me change my password, but the password I changed it to, plus the password I used to use, now both dont work. I suggest not changing your password until GOM gives word now, as I am locked out of my account.

You have to verify the change of the password via email. You got one from Gom after changing the password.
I forgot it the first time and was like "wtf?" because no password worked.
MKP|Maru|TaeJa|Mvp|Polt|INnoVation|GuMiho|Bomber|GoOdy|TeamTerran
Twistacles
Profile Blog Joined June 2010
Canada1327 Posts
August 13 2011 14:46 GMT
#613
good thing i have so many different p/ws
"If you don't give a shit which gum you buy, get stride" - Tyler
ondik
Profile Blog Joined November 2008
Czech Republic2908 Posts
August 13 2011 14:46 GMT
#614
FUCK I used the same mail I used for my bnet account. Luckily passwords for my e-mail and for my bnet acc are all different, am I 100% safe?
Bisu. The one and only. // Save the cheerreaver, save the world (of SC2)
hugman
Profile Joined June 2009
Sweden4644 Posts
August 13 2011 14:58 GMT
#615
On August 13 2011 23:46 ondik wrote:
FUCK I used the same mail I used for my bnet account. Luckily passwords for my e-mail and for my bnet acc are all different, am I 100% safe?

Yes, worst case is that you get lots of spam
RusHXceL
Profile Joined August 2010
United States1004 Posts
August 13 2011 14:59 GMT
#616
wtf GOM I can't even Sign into my account.
lurked
Profile Blog Joined March 2010
Canada918 Posts
August 13 2011 15:05 GMT
#617
o_O

At least I dont use important passwords on gaming sites...

But really? No encrytpion for the passwords?

Son, I am disappoint... : \
Magic is "just" magic until I get my hands on the source code.
skAnarky
Profile Blog Joined October 2007
Canada140 Posts
August 13 2011 15:05 GMT
#618

You have to verify the change of the password via email. You got one from Gom after changing the password.
I forgot it the first time and was like "wtf?" because no password worked.


I hit the verification link in the email unfortunately.
Rorra
Profile Joined September 2010
Australia1066 Posts
August 13 2011 15:08 GMT
#619
wow, I'm very disappointed in gom's lack of security.
RoyalCheese
Profile Joined May 2010
Czech Republic745 Posts
August 13 2011 15:18 GMT
#620
I don't understand how anyone can be stupid enough to save passwords in plain text. Really, this is like security 101 :/
Kennigit: "Chill was once able to retire really young, but decided to donate his entire salary TO SUPPORT ESPORTS"
rasnj
Profile Joined May 2010
United States1959 Posts
August 13 2011 15:18 GMT
#621
On August 13 2011 23:28 skAnarky wrote:
the system let me change my password, but the password I changed it to, plus the password I used to use, now both dont work. I suggest not changing your password until GOM gives word now, as I am locked out of my account.

Was you new password maybe very long? My original password on GOM was 17 characters, but apparently they truncated it to just the first 16. So while I entered (not my real password of course):
Icecream57Browser
the password ended up being:
Icecream57Browse
So if your new password was longer than 16 characters try logging in with just the first 16 characters.
skAnarky
Profile Blog Joined October 2007
Canada140 Posts
August 13 2011 15:30 GMT
#622
Not the case, unfortunately.
ymir233
Profile Blog Joined June 2010
United States8275 Posts
August 13 2011 15:41 GMT
#623
Holy crap this is kinda embarrassing for GomTV...Thanks R1CH!
Come motivate me to be cynical about animus at http://infinityandone.blogspot.com/ // Stork proxy gates are beautiful.
amiGoZoR
Profile Joined January 2011
Czech Republic135 Posts
August 13 2011 15:46 GMT
#624
rofl, passwords in a plain text, are u kidding me?
i am really pissed right now, thanks for info here, it seems GomTv doesnt care about users ...
be the best
Nivity
Profile Joined October 2010
Sweden371 Posts
August 13 2011 16:03 GMT
#625
Bad ofc, but anyone using the same passwords for sites and their paypal/email account is kinda stupid :D

MuTa07
Profile Joined July 2011
Netherlands71 Posts
August 13 2011 16:05 GMT
#626
On August 14 2011 01:03 Nivity wrote:
Bad ofc, but anyone using the same passwords for sites and their paypal/email account is kinda stupid :D



thanks
sc2 <3
Shodanss
Profile Joined November 2010
Greece245 Posts
August 13 2011 16:05 GMT
#627
really gom? really?
Google important phrases....ctrl+c,ctrl+v!!!
RusHXceL
Profile Joined August 2010
United States1004 Posts
August 13 2011 16:17 GMT
#628
with this a lot of people including me will not pay anymore.
minilance
Profile Joined June 2011
Canada500 Posts
August 13 2011 16:35 GMT
#629
Gomtv tell me that i cannot change my passeport for the moment
Bisu, Jangbang <3
deek
Profile Joined September 2010
Scotland69 Posts
August 13 2011 16:42 GMT
#630
in the year 2011 web developers still store passwords as plain text... I really do wonder where these people learn to code. =/

Should be safe i use twitter to sign in
I hit my head on the registering button. =/
Mr. Wiggles
Profile Blog Joined August 2010
Canada5894 Posts
August 13 2011 16:43 GMT
#631
"Profile modification is not available at the moment. Please try again at a later time" What the hell is this -_-

Good thing I changed most of my passwords after I thought I had a trojan/keylogger on one of the computers I use. My GOM password is now mostly associated with just random internet stuff, and not anything important like Emails, Steam, Facebook, etc.
you gotta dance
Zirith
Profile Joined April 2011
Canada403 Posts
Last Edited: 2011-08-13 16:54:12
August 13 2011 16:52 GMT
#632
GOMMMMMMMMMMMMMMMMMMMMMM!

Ya godamnit, I changed every single password to every forum/game site, grr, I'm really glad my credit card that was registered with most of them expired on the 31st
Artosis: "I don't trust hyenas."
Contagious
Profile Blog Joined December 2005
United States1319 Posts
August 13 2011 17:08 GMT
#633
wow GOM LOL good job. Thank god for facebook login?
s00pr
Profile Joined October 2010
Sweden94 Posts
Last Edited: 2011-08-13 17:16:12
August 13 2011 17:15 GMT
#634
I cant edit my profile!!
*Please try later* =/
DDie
Profile Joined April 2010
Brazil2369 Posts
August 13 2011 17:18 GMT
#635
I can't log into my Gom account, tried all my passwords and nothing,


Just to be safe i changed my email.
''Television! Teacher, mother, secret lover.''
Deleted User 101379
Profile Blog Joined August 2010
4849 Posts
August 13 2011 17:22 GMT
#636
On August 14 2011 01:42 deek wrote:
in the year 2011 web developers still store passwords as plain text... I really do wonder where these people learn to code. =/

Should be safe i use twitter to sign in


The sad thing is that at work we store all passwords as plaintext, too. I wanted to change it when i started until i noticed that about 15 legacy systems rely on that -.- Annoys me every time i open the database. The system is just 4 years old :-/

Really big oversight by GOM, they shouldn't make the same mistake as my company and hire the cheapest programmers they can find.
Finrod1
Profile Joined December 2010
Germany3997 Posts
August 13 2011 17:43 GMT
#637
How stupid are they? I want a reperation payment by gom, asap. Does anyone know how the chances are for a class-action lawsuit against gom?
Yoinhell
Profile Joined November 2010
Canada49 Posts
August 13 2011 17:50 GMT
#638
uggh...
MaestrO_
Profile Blog Joined July 2011
United States591 Posts
August 13 2011 17:52 GMT
#639
I log in via twitter

Umad hackers?
Vejovis
Profile Joined October 2010
Canada14 Posts
August 13 2011 17:57 GMT
#640
I noticed I couldn't log in to my PayPal earlier and had to reset the password, then I stroll to team liquid and find this ...... thanks R1CH for showing me the error in my ways in using the same passwords and emails xD
StimMarine
Profile Joined March 2011
723 Posts
August 13 2011 17:58 GMT
#641
Why hasn't there been an official response from GOMTV?
urashimakt
Profile Joined October 2009
United States1591 Posts
August 13 2011 17:58 GMT
#642
On August 14 2011 02:43 Finrod1 wrote:
How stupid are they? I want a reperation payment by gom, asap. Does anyone know how the chances are for a class-action lawsuit against gom?

That's a pretty ugly idea, man. Ask for a refund or whatever, but class action lawsuits don't help you, hurt the defendant, and make some lucky lawyer rich.

I appreciate the crash course in internet security from poppa r1ch!
Who dat ninja?
Fritti
Profile Joined July 2010
Netherlands52 Posts
August 13 2011 18:49 GMT
#643
Right, thanks for the headsup but apparently now I can't login anymore because "the auth system is not working" and my account still needs verification. Yes, I have an email but that simply repeats the cycle. >.< Hoping they'll fix it soon!
cari-kira
Profile Joined March 2011
Germany655 Posts
Last Edited: 2011-08-13 19:02:48
August 13 2011 19:01 GMT
#644
On August 14 2011 02:58 urashimakt wrote:
Show nested quote +
On August 14 2011 02:43 Finrod1 wrote:
How stupid are they? I want a reperation payment by gom, asap. Does anyone know how the chances are for a class-action lawsuit against gom?

That's a pretty ugly idea, man. Ask for a refund or whatever, but class action lawsuits don't help you, hurt the defendant, and make some lucky lawyer rich.


you shouldnt take him serious. he lives in germany and here we dont ever get paid reparations from things like this (why should you? your internet personality was hurt or what? dont make me laugh, you hurt your "internet personality" with shitty statements like that much more...).
here its not like in the states. enterprises in germany dont get sued for high exaggerated reparation sums to discourage future offendings like in the states, here they will only get sentenced to the sum that makes up for the damage that has been done.
he perhaps is too young to know that. but noone is too young to post their bs in the internet -.-
Live and let live
Hipsv
Profile Blog Joined May 2011
135 Posts
August 13 2011 19:03 GMT
#645
Hmm that's also scary that they have a vulnerability for a SQL injection, because it means they have shoddy coding on their website.
Azuroz
Profile Joined November 2010
Sweden1630 Posts
August 13 2011 19:05 GMT
#646
fail by gom, but even more fail by the people that use the same passwords for things like paypal or for your email account. Still think that people are making too big deal out of this even though it sucks, if you are too lazy to manage your passwords correctly then you had it coming.
Team NSHoseo <3
-stOpSKY-
Profile Joined September 2010
Canada498 Posts
August 13 2011 19:10 GMT
#647
On August 14 2011 04:03 Hipsv wrote:
Hmm that's also scary that they have a vulnerability for a SQL injection, because it means they have shoddy coding on their website.


Didnt the FBI or CIA or someone just get broken into with a basic SQL as well? During that stupid Lulzsec campaign.
PoopLord
Profile Joined May 2010
537 Posts
August 13 2011 19:17 GMT
#648
Thanks for the tip on keepass r1ch!
Yergidy
Profile Blog Joined April 2010
United States2107 Posts
August 13 2011 19:21 GMT
#649
On August 14 2011 02:58 StimMarine wrote:
Why hasn't there been an official response from GOMTV?

Seriously. You would think they would know it's important to let your users know that they need to change their passwords before their accounts get stolen...
One bright day in the middle of the night, Two dead boys got up to fight; Back to back they faced each other, Drew their swords and shot each other.
Clbull
Profile Blog Joined February 2011
United Kingdom1439 Posts
Last Edited: 2011-08-13 19:27:41
August 13 2011 19:23 GMT
#650
On August 13 2011 03:14 R1CH wrote:
There appears to be zero security on the passwords as they were stored in plain text (really GOM?).

Ouch. It looks like GOMTV have pulled off a Sony here (although at least Sony did encrypt their sensitive information.)

Besides, aren't there data protection laws preventing you from storing sensitive information without encryption or similar security measures? I mean IANAL (I Am Not A Lawyer) and I know absolutely jack shit about the state of data protection legislation in South Korea but wouldn't that have effectively made GOMTV's actions illegal?

If what R1CH said about how GOMTV have stored their passwords is the case then Gretech could potentially be in a lot of deep shit right now. It's especially scary because Blizzard have officially endorsed them and the GSL in Korea.

On August 14 2011 04:21 Yergidy wrote:
Show nested quote +
On August 14 2011 02:58 StimMarine wrote:
Why hasn't there been an official response from GOMTV?

Seriously. You would think they would know it's important to let your users know that they need to change their passwords before their accounts get stolen...

The fact that GOMTV haven't informed their customers is rubbing even more salt into the wound.
Zyxds
Profile Joined September 2010
United States91 Posts
August 13 2011 19:45 GMT
#651
On August 14 2011 04:10 stOpSKY wrote:
Show nested quote +
On August 14 2011 04:03 Hipsv wrote:
Hmm that's also scary that they have a vulnerability for a SQL injection, because it means they have shoddy coding on their website.


Didnt the FBI or CIA or someone just get broken into with a basic SQL as well? During that stupid Lulzsec campaign.


Kind of, but nothing of importance was compromised. The real CIA/FBI/Military info is stored on a secure server. I would assume via SIPRnet or a higher security clearance source. Something that is NOT available using a 'typical' internet connection.
Life is not a journey to the grave with the intention to arrive safely in a pretty and well-preserved body, but rather to skid in broadside, thoroughly used up, totally worn out, and loudly proclaiming: Wow! What a ride!
thee telescopes
Profile Joined August 2010
321 Posts
August 13 2011 19:54 GMT
#652
On August 14 2011 04:21 Yergidy wrote:
Show nested quote +
On August 14 2011 02:58 StimMarine wrote:
Why hasn't there been an official response from GOMTV?

Seriously. You would think they would know it's important to let your users know that they need to change their passwords before their accounts get stolen...
Honestly at this point I think they're just hoping if they say nothing less people will notice.
Rorak
Profile Joined November 2010
Sweden10 Posts
August 13 2011 20:08 GMT
#653
Hmm, I think GOMTV just removed the thread about this matter on their boards, I can't find it anymore, and I'm guessing no official word has been said from them yet?
"An idea that is not dangerous is unworthy of being called an idea at all" - Oscar Wilde
Seiru
Profile Joined May 2011
United States40 Posts
August 13 2011 20:34 GMT
#654
Why in the world are people changing their GOMTV passwords before we even have confirmation that the exploit has been fixed? Am I the only one facepalming at all the posts saying that people have changed their GOM passwords?
mmdmmd
Profile Joined June 2007
722 Posts
August 13 2011 20:37 GMT
#655
Sorry to be OT, but this is also gaming related.

Just received an email that Bethesda Forum database has been breached.
sleepingdog
Profile Joined August 2008
Austria6145 Posts
August 13 2011 20:38 GMT
#656
This is exactly why I'm so reluctant to pay for such services - not because I couldn't afford it, but because of security.
"You see....YOU SEE..." © 2010 Sen
Scribble
Profile Blog Joined March 2011
2077 Posts
August 13 2011 20:42 GMT
#657
What worries me isn't that they were compromised...but the fact that information was stored in plain txt and that Gom hasn't issued any kind of statement yet. Shit happens, but that's unacceptable.
MasterVelVet
Profile Joined August 2010
Belgium132 Posts
August 13 2011 20:44 GMT
#658
[image loading]
kyophan
Profile Joined January 2010
United States113 Posts
August 13 2011 20:49 GMT
#659
On August 14 2011 05:08 Rorak wrote:
Hmm, I think GOMTV just removed the thread about this matter on their boards, I can't find it anymore, and I'm guessing no official word has been said from them yet?

This one?
http://www.gomtv.net/forum/view.gom?page=1&topicid=202665

I agree. At the very least, it would be proper to be given a warning. I wouldn't have caught this if I didn't visit teamliquid on a daily basis.
EL33T_COL
Profile Joined August 2011
Canada68 Posts
August 13 2011 20:49 GMT
#660
Sadly, I trusted GomTV..... really disappointing
À vaincre sans péril on triomphe sans gloire
mprs
Profile Joined April 2010
Canada2933 Posts
August 13 2011 20:51 GMT
#661
On August 14 2011 04:17 PoopLord wrote:
Thanks for the tip on keepass r1ch!


Yeah no kidding. Sick program.
We talkin about PRACTICE
obesechicken13
Profile Blog Joined July 2008
United States10467 Posts
Last Edited: 2011-08-13 21:11:39
August 13 2011 20:58 GMT
#662
[image loading]

Also, Rich, I'm disappointed in you. Why would you recommend keepass instead of lastpass? Is it because keepass is open source? You can't use it from multiple computers. I think it's better to use lastpass.

lastpass
Use this instead of keepass.
I think in our modern age technology has evolved to become more addictive. The things that don't give us pleasure aren't used as much. Work was never meant to be fun, but doing it makes us happier in the long run.
sinii
Profile Joined August 2010
England989 Posts
August 13 2011 20:59 GMT
#663
got KeePass as well, seems awesome so far... I recommend setting up a backup in a dropbox and maybe a few different hard drives too, as if you lose your database its gonna cause you a lot of hassle!
Soleron
Profile Blog Joined September 2010
United Kingdom1324 Posts
August 13 2011 21:00 GMT
#664
On August 14 2011 05:58 obesechicken13 wrote:

Also, Rich, I'm disappointed in you. Why would you recommend keypass instead of lastpass? Is it because keypass is open source? You can't use it from multiple computers. I think it's better to use lastpass.

lastpass
Use this instead of keypass.


Lastpass could be sending your passwords to the developer. In fact the same mechanism as your comic: cool free application that gets a lot of downloads and then they have your information.

Open source is required for anything like this.

MattyClutch
Profile Blog Joined September 2010
United States711 Posts
August 13 2011 21:05 GMT
#665
On August 14 2011 06:00 Soleron wrote:
Show nested quote +
On August 14 2011 05:58 obesechicken13 wrote:

Also, Rich, I'm disappointed in you. Why would you recommend keypass instead of lastpass? Is it because keypass is open source? You can't use it from multiple computers. I think it's better to use lastpass.

lastpass
Use this instead of keypass.


Lastpass could be sending your passwords to the developer. In fact the same mechanism as your comic: cool free application that gets a lot of downloads and then they have your information.

Open source is required for anything like this.




Agreed.


Can't believe GOM had such lax security though :/
Nihn'kas Neehn
Zyxds
Profile Joined September 2010
United States91 Posts
Last Edited: 2011-08-13 21:11:19
August 13 2011 21:08 GMT
#666
Well, GOM doesn't allow you to change profile info all of a sudden. Seems kinda shady to me.
Life is not a journey to the grave with the intention to arrive safely in a pretty and well-preserved body, but rather to skid in broadside, thoroughly used up, totally worn out, and loudly proclaiming: Wow! What a ride!
obesechicken13
Profile Blog Joined July 2008
United States10467 Posts
August 13 2011 21:10 GMT
#667
On August 14 2011 06:00 Soleron wrote:
Show nested quote +
On August 14 2011 05:58 obesechicken13 wrote:

Also, Rich, I'm disappointed in you. Why would you recommend keypass instead of lastpass? Is it because keypass is open source? You can't use it from multiple computers. I think it's better to use lastpass.

lastpass
Use this instead of keypass.


Lastpass could be sending your passwords to the developer. In fact the same mechanism as your comic: cool free application that gets a lot of downloads and then they have your information.

Open source is required for anything like this.


So you trust a single person (the developer) to your passwords. Isn't that better than having to navigate through folders and transferring your passwords on usb every time you want to log into facebook?

It seems like you're overcomplicating things for no reason.
I think in our modern age technology has evolved to become more addictive. The things that don't give us pleasure aren't used as much. Work was never meant to be fun, but doing it makes us happier in the long run.
TVUmK
Profile Joined April 2011
United States91 Posts
August 13 2011 21:17 GMT
#668
It says i cant modify my profile, and i cant change my password. What is wrong?
"Just go (freaking) kill him!"-Day9
sinistrorsey2
Profile Joined August 2011
42 Posts
August 13 2011 21:52 GMT
#669
+ Show Spoiler +
On August 14 2011 06:17 TVUmK wrote:
It says i cant modify my profile, and i cant change my password. What is wrong?

I assume that gom would lock it so the hackers couldnt mess with ur information maybe?
Alethios
Profile Blog Joined December 2007
New Zealand2765 Posts
Last Edited: 2011-08-13 22:11:03
August 13 2011 21:56 GMT
#670
Ah what the fuck?

What a pain in the ass.

EDIT: I don't even remember half the sites I made accounts like that for. From this point on, i'm going to be much more careful with my passwords.
When you arise in the morning, think of what a precious privilege it is to be alive - to breathe, to think, to enjoy, to love.
xBillehx
Profile Blog Joined June 2009
United States1289 Posts
August 13 2011 22:00 GMT
#671
On August 14 2011 06:08 Zyxds wrote:
Well, GOM doesn't allow you to change profile info all of a sudden. Seems kinda shady to me.

Seems like its a smart idea until they get it fixed, otherwise you'd be sending all your new passwords to the same people who exploited this the first time. But hey, shady sounds evil, so we'll go with that.
Taengoo ♥
yoshi245
Profile Joined May 2011
United States2971 Posts
Last Edited: 2011-08-13 22:18:06
August 13 2011 22:17 GMT
#672
On August 14 2011 06:00 Soleron wrote:
Show nested quote +
On August 14 2011 05:58 obesechicken13 wrote:

Also, Rich, I'm disappointed in you. Why would you recommend keypass instead of lastpass? Is it because keypass is open source? You can't use it from multiple computers. I think it's better to use lastpass.

lastpass
Use this instead of keypass.


Lastpass could be sending your passwords to the developer. In fact the same mechanism as your comic: cool free application that gets a lot of downloads and then they have your information.

Open source is required for anything like this.



I still use lastpass despite it being sort of compromised some weeks ago, but even then the passwords that may or may not have been taken were still encrypted and people with lengthy passes would take forever to decrypt nonetheless. And since then I changed my own lastpass master pass to be something convoluted and over 20 alphanumeric.

As to the issue of it being sent to the dev, don't know anything about that, though it's a possibility with just about any of these password services that can remain as a risk.

Makes me glad I log in to GOM via facebook.
"Numbers speak about the past, not the present." -Thorzain
LetoAtreides82
Profile Joined January 2011
United States1188 Posts
Last Edited: 2011-08-13 22:27:56
August 13 2011 22:19 GMT
#673
On August 14 2011 06:08 Zyxds wrote:
Well, GOM doesn't allow you to change profile info all of a sudden. Seems kinda shady to me.


I just tried watching the second game from a match and it asked me to login, when I did it asked me to create a new password. The new password requires a length of at least 8 characters, a capital letter, and an alpha-numeric character.
The spice must flow
obesechicken13
Profile Blog Joined July 2008
United States10467 Posts
August 13 2011 22:19 GMT
#674
On August 14 2011 07:17 yoshi245 wrote:
Show nested quote +
On August 14 2011 06:00 Soleron wrote:
On August 14 2011 05:58 obesechicken13 wrote:

Also, Rich, I'm disappointed in you. Why would you recommend keypass instead of lastpass? Is it because keypass is open source? You can't use it from multiple computers. I think it's better to use lastpass.

lastpass
Use this instead of keypass.


Lastpass could be sending your passwords to the developer. In fact the same mechanism as your comic: cool free application that gets a lot of downloads and then they have your information.

Open source is required for anything like this.



I still use lastpass despite it being sort of compromised some weeks ago, but even then the passwords that may or may not have been taken were still encrypted and people with lengthy passes would take forever to decrypt nonetheless. And since then I changed my own lastpass master pass to be something convoluted and over 20 alphanumeric.

As to the issue of it being sent to the dev, don't know anything about that, though it's a possibility with just about any of these password services that can remain as a risk.

Makes me glad I log in to GOM via facebook.

The people who hacked into lastpass (potentially, not certain if they even did) were only in long enough to get like 20 passwords from their database. Lastpass is pretty secure.
I think in our modern age technology has evolved to become more addictive. The things that don't give us pleasure aren't used as much. Work was never meant to be fun, but doing it makes us happier in the long run.
rebuffering
Profile Joined December 2010
Canada2436 Posts
August 13 2011 22:24 GMT
#675
ok so i cant even log into my gom account anymore, i could last night, but now its saying

"You have not verified your account. To complete sign up process, please check your verification email" which i have not received, it then says "Sorry, Wrong access". I dunno whats going on, last night i could log in just fine even though i couldnt change my pass, but now i cant even log in.
http://www.twitch.tv/rebufferingg
slicknav
Profile Joined January 2011
1409 Posts
August 13 2011 22:28 GMT
#676
I just tried to watch some VOD's since my account seems to fine, I was asked to change my password, so it seems like they fixed it?
blah blah blah...
Zyxds
Profile Joined September 2010
United States91 Posts
Last Edited: 2011-08-13 22:29:50
August 13 2011 22:29 GMT
#677
On August 14 2011 07:00 xBillehx wrote:
Show nested quote +
On August 14 2011 06:08 Zyxds wrote:
Well, GOM doesn't allow you to change profile info all of a sudden. Seems kinda shady to me.

Seems like its a smart idea until they get it fixed, otherwise you'd be sending all your new passwords to the same people who exploited this the first time. But hey, shady sounds evil, so we'll go with that.

Yeah, I'll put my trust in the company that made my info publicly available in the first place, sounds like a legit plan to me...
Life is not a journey to the grave with the intention to arrive safely in a pretty and well-preserved body, but rather to skid in broadside, thoroughly used up, totally worn out, and loudly proclaiming: Wow! What a ride!
CursedFeanor
Profile Joined August 2010
Canada539 Posts
August 13 2011 22:33 GMT
#678
I've been using KeePass for a couple a months now and I absolutely love it!

open source + offline > closed source + online
KeePass > Lastpass

Simply setup a dropbox (or external SVN, which I personally prefer) and keepass becomes just as portable as lastpass. In any case, I think such password management is really a must nowadays, just as this whole story demonstrates.
RaiKageRyu
Profile Joined August 2009
Canada4773 Posts
August 13 2011 22:35 GMT
#679
GOM finally caught on they've been hacked.
Someone call down the Thunder?
Finrod1
Profile Joined December 2010
Germany3997 Posts
August 13 2011 22:37 GMT
#680
On August 14 2011 07:28 slicknav wrote:
I just tried to watch some VOD's since my account seems to fine, I was asked to change my password, so it seems like they fixed it?

The real question is if they changes something in their system...
Mylkyjo
Profile Joined July 2011
Australia110 Posts
August 13 2011 22:37 GMT
#681
I couldn't log on just now. Had to get a new password sent to me to get on... Annoying. Changed my paypal pw too.
xBillehx
Profile Blog Joined June 2009
United States1289 Posts
August 13 2011 22:40 GMT
#682
On August 14 2011 07:29 Zyxds wrote:
Show nested quote +
On August 14 2011 07:00 xBillehx wrote:
On August 14 2011 06:08 Zyxds wrote:
Well, GOM doesn't allow you to change profile info all of a sudden. Seems kinda shady to me.

Seems like its a smart idea until they get it fixed, otherwise you'd be sending all your new passwords to the same people who exploited this the first time. But hey, shady sounds evil, so we'll go with that.

Yeah, I'll put my trust in the company that made my info publicly available in the first place, sounds like a legit plan to me...

You're right, GOM literally posted thousands of passwords in public.

Come on dude I was just saying there's no point in entering new passwords if the exploit still existed since your new passwords would be compromised as well. You thought trying to stop people from getting their new passwords stolen until they fixed it was shady.
Taengoo ♥
Sceptor87
Profile Joined October 2010
Canada266 Posts
August 13 2011 22:41 GMT
#683
This is the reason why I don't use PayPal, why I don't do any form on online banking or billing, and why I fabricate a lot of information on accounts that I sign up for. The Playstation 3 deal taught me a lesson. Always always always lie on the internet when you're filling in forms, only change it to the truth when you want warranty or something sent to you.

I find it unbelievable that companies can just store information in a txt file. It's like they just open up Notepad and then a fuck was not given on that day. Completely unacceptable and irresponsible.
Standard,
MuTa07
Profile Joined July 2011
Netherlands71 Posts
August 13 2011 22:42 GMT
#684
I cant log into my account on GOM anymore.. I get this:
+ Show Spoiler +
[image loading]


any1 know what I gotta do now? I had premium pass for august =.=
sc2 <3
Zyxds
Profile Joined September 2010
United States91 Posts
August 13 2011 22:45 GMT
#685
On August 14 2011 07:40 xBillehx wrote:
Show nested quote +
On August 14 2011 07:29 Zyxds wrote:
On August 14 2011 07:00 xBillehx wrote:
On August 14 2011 06:08 Zyxds wrote:
Well, GOM doesn't allow you to change profile info all of a sudden. Seems kinda shady to me.

Seems like its a smart idea until they get it fixed, otherwise you'd be sending all your new passwords to the same people who exploited this the first time. But hey, shady sounds evil, so we'll go with that.

Yeah, I'll put my trust in the company that made my info publicly available in the first place, sounds like a legit plan to me...

You're right, GOM literally posted thousands of passwords in public.

Come on dude I was just saying there's no point in entering new passwords if the exploit still existed since your new passwords would be compromised as well. You thought trying to stop people from getting their new passwords stolen until they fixed it was shady.


No, I thought being unable to access my profile was shady, and it is. I don't really like being completely locked out of my personal info. based on the oversight of some random company. But hey, that's just me.

I know how to handle myself online and nothing of mine is compromised, I just don't like being locked out of my own profile when I've paid for services with said site.
Life is not a journey to the grave with the intention to arrive safely in a pretty and well-preserved body, but rather to skid in broadside, thoroughly used up, totally worn out, and loudly proclaiming: Wow! What a ride!
Mylkyjo
Profile Joined July 2011
Australia110 Posts
August 13 2011 22:45 GMT
#686
@MuTa07 I had the same, it should redirect you, but it wouldn't for me. I just clicked the "Forgot email address or password" link.
R1CH
Profile Blog Joined May 2007
Netherlands10341 Posts
August 13 2011 22:47 GMT
#687
Email from GOM:
Dear Valued GOMTV.net users:

We regretfully inform you that approximately at 2 AM KST, Aug.12th, there has been an attack against our web site, GOMTV.net.

We have found that some of the user information from GOMTV.net has been compromised from the attack. We suspect that the following information might have been exposed: name, location (country), e-mail address, GOMTV.net nickname and password.

We deeply apologize for the inconvenience and concern caused by the intrusion.

Since we use PayPal’s service to handle payments, we do not store nor have any payment related information on our site including your credit card numbers and bank account details.

We strongly encourage you to change your GOMTV.net password and if you have been using the same password for other web sites, we suggest changing the passwords for those sites as well.

Users who have signed up with Facebook or Twitter do not have to worry about changing their passwords as they did not have to enter separate passwords at the time of sign up.

As soon as we discovered the sign of intrusion we have conducted a complete investigation into the incident and have also taken steps to enhance security and strengthen our network system in order to provide you with better protection of your personal information.

We greatly appreciate your patience and understanding and we pledge to work harder to bring you a better and greater service experience.

If you have any concerns or questions please feel free to contact us at support@gomtv.net.

Thank you.
GOMTV.net
AdministratorTwitter: @R1CH_TL
TL+ Member
Seiru
Profile Joined May 2011
United States40 Posts
August 13 2011 22:47 GMT
#688
http://www.gomtv.net/2011gslsponsors5/news/65953

They made a news post about it.
xBillehx
Profile Blog Joined June 2009
United States1289 Posts
August 13 2011 22:47 GMT
#689
On August 14 2011 07:45 Zyxds wrote:
Show nested quote +
On August 14 2011 07:40 xBillehx wrote:
On August 14 2011 07:29 Zyxds wrote:
On August 14 2011 07:00 xBillehx wrote:
On August 14 2011 06:08 Zyxds wrote:
Well, GOM doesn't allow you to change profile info all of a sudden. Seems kinda shady to me.

Seems like its a smart idea until they get it fixed, otherwise you'd be sending all your new passwords to the same people who exploited this the first time. But hey, shady sounds evil, so we'll go with that.

Yeah, I'll put my trust in the company that made my info publicly available in the first place, sounds like a legit plan to me...

You're right, GOM literally posted thousands of passwords in public.

Come on dude I was just saying there's no point in entering new passwords if the exploit still existed since your new passwords would be compromised as well. You thought trying to stop people from getting their new passwords stolen until they fixed it was shady.


No, I thought being unable to access my profile was shady, and it is. I don't really like being completely locked out of my personal info. based on the oversight of some random company. But hey, that's just me.

I know how to handle myself online and nothing of mine is compromised, I just don't like being locked out of my own profile when I've paid for services with said site.

Blizzard locks your account when it's been hacked until they fix it. Paypal locks your account when it's been compromised until they fix it. Banks lock your accounts when they've been compromised until they fix it. It's a required step to stop further damage until it's fixed, nothing shady about that.
Taengoo ♥
R1CH
Profile Blog Joined May 2007
Netherlands10341 Posts
August 13 2011 22:49 GMT
#690
I have to say I'm happy how this was handled by GOM. 1-2 days notice is better than none at all - many companies will actively try to cover up or downplay such attacks or claim that sensitive data was never stolen.
AdministratorTwitter: @R1CH_TL
TL+ Member
Seeker *
Profile Blog Joined April 2005
Where dat snitch at?37043 Posts
August 13 2011 22:50 GMT
#691
Ugh...... attack GOM? Why?!!
I dare someone to attack TL..... they'll have 5000+ ppl attack back
ModeratorPeople ask me, "Seeker, what are you seeking?" My answer? "Sleep, damn it! Always sleep!"
TL+ Member
Zyxds
Profile Joined September 2010
United States91 Posts
August 13 2011 22:54 GMT
#692
On August 14 2011 07:47 xBillehx wrote:
Show nested quote +
On August 14 2011 07:45 Zyxds wrote:
On August 14 2011 07:40 xBillehx wrote:
On August 14 2011 07:29 Zyxds wrote:
On August 14 2011 07:00 xBillehx wrote:
On August 14 2011 06:08 Zyxds wrote:
Well, GOM doesn't allow you to change profile info all of a sudden. Seems kinda shady to me.

Seems like its a smart idea until they get it fixed, otherwise you'd be sending all your new passwords to the same people who exploited this the first time. But hey, shady sounds evil, so we'll go with that.

Yeah, I'll put my trust in the company that made my info publicly available in the first place, sounds like a legit plan to me...

You're right, GOM literally posted thousands of passwords in public.

Come on dude I was just saying there's no point in entering new passwords if the exploit still existed since your new passwords would be compromised as well. You thought trying to stop people from getting their new passwords stolen until they fixed it was shady.


No, I thought being unable to access my profile was shady, and it is. I don't really like being completely locked out of my personal info. based on the oversight of some random company. But hey, that's just me.

I know how to handle myself online and nothing of mine is compromised, I just don't like being locked out of my own profile when I've paid for services with said site.

Blizzard locks your account when it's been hacked until they fix it. Paypal locks your account when it's been compromised until they fix it. Banks lock your accounts when they've been compromised until they fix it. It's a required step to stop further damage until it's fixed, nothing shady about that.


Had I been notified by GOM before said action had taken place (i.e. an e-mail similar to what R1CH had gotten, I would be satisfied.) I don't like being locked out of MY OWN accounts due to a companies incompetence.

I don't like being left in the dark when it's my info. at stake.
Life is not a journey to the grave with the intention to arrive safely in a pretty and well-preserved body, but rather to skid in broadside, thoroughly used up, totally worn out, and loudly proclaiming: Wow! What a ride!
deek
Profile Joined September 2010
Scotland69 Posts
August 13 2011 22:54 GMT
#693
On August 14 2011 07:19 obesechicken13 wrote:
Show nested quote +
On August 14 2011 07:17 yoshi245 wrote:
On August 14 2011 06:00 Soleron wrote:
On August 14 2011 05:58 obesechicken13 wrote:

Also, Rich, I'm disappointed in you. Why would you recommend keypass instead of lastpass? Is it because keypass is open source? You can't use it from multiple computers. I think it's better to use lastpass.

lastpass
Use this instead of keypass.


Lastpass could be sending your passwords to the developer. In fact the same mechanism as your comic: cool free application that gets a lot of downloads and then they have your information.

Open source is required for anything like this.



I still use lastpass despite it being sort of compromised some weeks ago, but even then the passwords that may or may not have been taken were still encrypted and people with lengthy passes would take forever to decrypt nonetheless. And since then I changed my own lastpass master pass to be something convoluted and over 20 alphanumeric.

As to the issue of it being sent to the dev, don't know anything about that, though it's a possibility with just about any of these password services that can remain as a risk.

Makes me glad I log in to GOM via facebook.

The people who hacked into lastpass (potentially, not certain if they even did) were only in long enough to get like 20 passwords from their database. Lastpass is pretty secure.


Your post shows the exact reason why Lastpass cant work, even if they only got 20 passwords.. Its 20 passwords to paypal/banks/battlenetaccounts etc, Last pass will store the info in their database with an ecryption key, but the problem is anyone else can get the encryption key as its in their program. Its like having a shop with everyones information for free if u can break into the shop, history has shown us even those in Internet Security have lax security

To attempt it with KeePass would require the hacker to break into your computer first, and thats very unlikely to happen unless you were personally targeted, because developing a worm that searched for users who ran KeePass and had an exploit available for them to access is too much time, when they could break into Lastpass and steal thousands of important user names and passwords
I hit my head on the registering button. =/
JustinMartin
Profile Joined November 2010
159 Posts
August 13 2011 22:55 GMT
#694
gomtv, omfg soo fking....
obesechicken13
Profile Blog Joined July 2008
United States10467 Posts
August 13 2011 22:56 GMT
#695
On August 14 2011 07:50 Seeker wrote:
Ugh...... attack GOM? Why?!!
I dare someone to attack TL..... they'll have 5000+ ppl attack back

Don't provoke. I'm mostly just happy that no one good enough at hacking hates TL.
I think in our modern age technology has evolved to become more addictive. The things that don't give us pleasure aren't used as much. Work was never meant to be fun, but doing it makes us happier in the long run.
InvertedAces
Profile Joined October 2010
United Kingdom25 Posts
August 13 2011 22:56 GMT
#696
On August 14 2011 07:50 Seeker wrote:
Ugh...... attack GOM? Why?!!
I dare someone to attack TL..... they'll have 5000+ ppl attack back

I doubt that there are that many people on TL that even have an idea on how to 'attack back'.
Pain is weakness leaving the body
CodECleaR
Profile Joined November 2010
United States395 Posts
August 13 2011 22:59 GMT
#697
On August 14 2011 07:50 Seeker wrote:
Ugh...... attack GOM? Why?!!
I dare someone to attack TL..... they'll have 5000+ ppl attack back

Correction: They would never be able to do any real damage because of R1CH
How do you beat a terran who's hardcore turtling off 3 base? Flip him on his back and walk away."
Glowbox
Profile Joined June 2010
Netherlands330 Posts
August 13 2011 23:00 GMT
#698
On August 14 2011 07:47 R1CH wrote:
Email from GOM:


You received an actual e-mail? I did not get one yet. Anyone else?
EvilTeletubby
Profile Blog Joined January 2004
Baltimore, USA22258 Posts
August 13 2011 23:02 GMT
#699
GOM -_-

Thanks for the heads-up to everyone R1CH!! <3
Moderatorhttp://carbonleaf.yuku.com/topic/408/t/So-I-proposed-at-a-Carbon-Leaf-concert.html ***** RIP Geoff
warbean
Profile Joined August 2010
United States11 Posts
August 13 2011 23:05 GMT
#700
Just got an email from the forums at Bethesda saying my account was compromised there. I think I used the same email and password there.


+ Show Spoiler +

Dear Bethesda Forum User,

We have identified a potential breach of our forum user database that occurred Friday morning, Aug 12. We have reset your forum password as a precaution, in the event that any encrypted forum user passwords were compromised.

When you next try to login to the forums, your old password will not work. Click the "I've forgotten my password link" underneath the login boxes, and follow the steps to setup a new password for your account.

We recommend you do not use your old password or a password you have used for other sites. Further, if your old forum password was used for any other online purposes, we recommend changing the password on those accounts as well.

If you have any concerns, visit the following link:
http://www.bethsoft.com/eng/contact_email.php
obesechicken13
Profile Blog Joined July 2008
United States10467 Posts
August 13 2011 23:17 GMT
#701
On August 14 2011 07:54 deek wrote:
Show nested quote +
On August 14 2011 07:19 obesechicken13 wrote:
On August 14 2011 07:17 yoshi245 wrote:
On August 14 2011 06:00 Soleron wrote:
On August 14 2011 05:58 obesechicken13 wrote:

Also, Rich, I'm disappointed in you. Why would you recommend keypass instead of lastpass? Is it because keypass is open source? You can't use it from multiple computers. I think it's better to use lastpass.

lastpass
Use this instead of keypass.


Lastpass could be sending your passwords to the developer. In fact the same mechanism as your comic: cool free application that gets a lot of downloads and then they have your information.

Open source is required for anything like this.



I still use lastpass despite it being sort of compromised some weeks ago, but even then the passwords that may or may not have been taken were still encrypted and people with lengthy passes would take forever to decrypt nonetheless. And since then I changed my own lastpass master pass to be something convoluted and over 20 alphanumeric.

As to the issue of it being sent to the dev, don't know anything about that, though it's a possibility with just about any of these password services that can remain as a risk.

Makes me glad I log in to GOM via facebook.

The people who hacked into lastpass (potentially, not certain if they even did) were only in long enough to get like 20 passwords from their database. Lastpass is pretty secure.


Your post shows the exact reason why Lastpass cant work, even if they only got 20 passwords.. Its 20 passwords to paypal/banks/battlenetaccounts etc, Last pass will store the info in their database with an ecryption key, but the problem is anyone else can get the encryption key as its in their program. Its like having a shop with everyones information for free if u can break into the shop, history has shown us even those in Internet Security have lax security

To attempt it with KeePass would require the hacker to break into your computer first, and thats very unlikely to happen unless you were personally targeted, because developing a worm that searched for users who ran KeePass and had an exploit available for them to access is too much time, when they could break into Lastpass and steal thousands of important user names and passwords

20 secure passwords that potentially could've been stolen. There was no evidence that anything was stolen, only that there was an unusual amount of bandwith at a weird hour.

I don't know much about the encryption algorithm they use at lastpass, but let's put it this way. This is not a college student project. They do not reuse the same exact encryption key on every user. I suspect the use something like rainbow encryption tables http://en.wikipedia.org/wiki/Rainbow_table. The hackers were not able to get the encryption key... and they can not get the encryption keys.

Lastpass can not access your passwords so hackers can't either.

Your Security Is Our Priority

LastPass is an evolved Host Proof hosted solution, which avoids the stated weakness of vulnerability to XSS as long as you're using the add-on. LastPass strongly believes in using local encryption, and locally created one way salted hashes to provide you with the best of both worlds for your sensitive information: Complete security, while still providing online accessibility and syncing capabilities. We've accomplished this by using 256-bit AES implemented in C++ and JavaScript (for the website) and exclusively encrypting and decrypting on your local PC. No one at LastPass can ever access your sensitive data. We've taken every step we can think of to ensure your security and privacy.
Availability

You need to always have access to your data, we've accomplished this in multiple ways, first we have 2 data-centers in production service, second we store your encrypted data on your local PC when you login, so that if LastPass.com can't be reached, you can still login to the add-on and get to your accounts. The website is usable without the add-on installed (the Encryption and Decryption happens in JavaScript which you can see happen on some forms), but we take advantage of faster encryption available in the add-ons if they're available. We also have a mobile site m.lastpass.com if you're on your phone.
Security

On Windows, LastPass helps find insecure passwords stored on your computer so you can store them securely in LastPass and remove the easy access by malicious software. LastPass uses SSL exclusively for data transfer even though the vast majority of data you're sending is already encrypted with 256-bit AES and unusable to both LastPass and any party listening in to the network traffic -- the amount of data is trivial so the extra encryption doesn't hurt. Our policy of never receiving private data that you haven't already locked down with your LastPass master password (which we never receive and will never ask for) radically reduces attack vectors. We use firewalls and best practices to protect the servers and service, but our best line of defense is simply not having access to data even if someone got in. If LastPass can't access it, hackers can't either.

https://lastpass.com/whylastpass_technology.php?fromwebsite=1
I think what the bolded part means is that lastpass uses private decryption keys on the client side. Like when the developer at lastpass looks at the passwords in their tables, they are all encrypted passwords. The developer doesn't know how to decrypt the passwords, only you have the decryption key.

In other words, if the passwords were secure enough (not a dictionary word), the encryption would've saved the users even if they were stolen. If they weren't, well then it'd be easier to just hack paypal or your bank account and these idiots should stop using "password" as their primary password for everything.

The passwords are all stored in huge gigabyte large files filled with garbage, and when 20 of them are transferred, the server automatically detects the hack and shuts down.

In addition, lastpass doesn't normally store information on banking accounts or paypal accounts because the paypal and banks sites tell lastpass not to.




I'll end my long post like this:
Lastpass probably isn't infinitely secure. The worst thing that could happen is that the primary developer is really evil. But it is more secure than just about anything else out there including your banks sites and paypal.

Keepass is open source. There are many concerns about open source being unsecure. http://www.internetnews.com/skerner/2010/03/is-open-source-software-more-s.html
You made the claim that someone could potentially create a worm to take passwords from keepass. Well someone could (and you say they wouldn't), but it'd be significantly easier to create keylogger malware or something similar. If someone gets access to your computer through a virus, your computer is no longer yours, so I seriously doubt keepass is any safer than lastpass in that respect.
I think in our modern age technology has evolved to become more addictive. The things that don't give us pleasure aren't used as much. Work was never meant to be fun, but doing it makes us happier in the long run.
Zinnwaldite
Profile Joined August 2010
Norway1567 Posts
Last Edited: 2011-08-13 23:27:16
August 13 2011 23:17 GMT
#702
how do i find out my nick? i can't sign in with my password and need to know the nick to reset.. *_*

though i think the nick is right,, it's just not working,,
We promise with a view to hope, but the reason to "accomplish" what we promised would be fear.
Caseyclysm
Profile Joined May 2010
United States104 Posts
August 13 2011 23:19 GMT
#703
That's too bad for Gomtv. I hope noone has anything stolen because of this and that Gomtv continues to provide us with great service!
“You cannot teach a man anything; you can only help him discover it in himself.” -Galileo Galilei
Antoine
Profile Blog Joined May 2010
United States7481 Posts
August 13 2011 23:33 GMT
#704
looks like they killed all the cookies and are forcing a password change on login, good step to take imo ^^
ModeratorFlash Sea Action Snow Midas | TheStC Ret Tyler MC | RIP 우정호
vlf
Profile Joined April 2010
Portugal170 Posts
August 13 2011 23:40 GMT
#705
And this is why I use dummy passwords for non-financial related sites.
çpç
Seraphic
Profile Joined September 2010
United States3849 Posts
August 13 2011 23:42 GMT
#706
just have to change. probably for the better regardless.
Natus Vincere Fan | Team Secret Fan | SK Telecom T1 Fan | Lanaya the Templar Assassin <3
thecoupe
Profile Joined June 2011
United States77 Posts
August 13 2011 23:46 GMT
#707
Plaintext? Really? Come on GOM, can't you at least use md5?
Pandemona *
Profile Blog Joined March 2011
Charlie Sheens House51493 Posts
August 13 2011 23:46 GMT
#708
On August 14 2011 08:17 Zinnwaldite wrote:
how do i find out my nick? i can't sign in with my password and need to know the nick to reset.. *_*

though i think the nick is right,, it's just not working,,



Same with me dude! I think we got hacked and they changed our nicknames because you can do that i think.

I sent them an email with a few details for them to give me my accounts back, i suggest you do the same.

support@gomtv.net
ModeratorTeam Liquid Football Thread Guru! - Chelsea FC ♥
D_K_night
Profile Joined April 2010
Canada615 Posts
August 13 2011 23:51 GMT
#709
The ironic thing in all this, is this:

I couldn't even create a GOMTV.net username/password in the early days when I wanted to watch SC2 games. Because I couldn't, I was forced to sign-up on twitter - just so I could watch GOMTV.

So I suppose things are totally safe on my end here? And yes I use different passwords for everything.
Canada
LetoAtreides82
Profile Joined January 2011
United States1188 Posts
August 13 2011 23:55 GMT
#710
On August 14 2011 08:00 Glowbox wrote:
Show nested quote +
On August 14 2011 07:47 R1CH wrote:
Email from GOM:


You received an actual e-mail? I did not get one yet. Anyone else?


I got the email.
The spice must flow
Goldfish
Profile Blog Joined August 2010
2230 Posts
August 13 2011 23:56 GMT
#711
So GOMTV is safe now right (or at least they're trying to fix the security holes atm?). Also only thing compromised are user info, the site itself (like admin password, etc) isn't compromised right?
https://connect.microsoft.com/WindowsServerFeedback/feedback/details/741495/biggest-explorer-annoyance-automatic-sorting-windows-7-server-2008-r2-and-vista#details Allow Disable Auto Arrange in Windows 7+
Pandemona *
Profile Blog Joined March 2011
Charlie Sheens House51493 Posts
August 14 2011 00:03 GMT
#712
On August 14 2011 08:46 Pandemona wrote:
Show nested quote +
On August 14 2011 08:17 Zinnwaldite wrote:
how do i find out my nick? i can't sign in with my password and need to know the nick to reset.. *_*

though i think the nick is right,, it's just not working,,



Same with me dude! I think we got hacked and they changed our nicknames because you can do that i think.

I sent them an email with a few details for them to give me my accounts back, i suggest you do the same.

support@gomtv.net



Just had a response and they said this;

Dear User:

Your nickname has not been modified by anyone.
At the moment we have similar problem with users e-mail containing under scroll. ( _ )
This will be fixed momentarily

We greatly appreciate your patience and understanding and we pledge to work harder to bring you a better and greater service experience.


GOMTV.net



Hope this helps
ModeratorTeam Liquid Football Thread Guru! - Chelsea FC ♥
Carbonthief
Profile Joined October 2010
United States289 Posts
August 14 2011 00:20 GMT
#713
OH shit, good thing I used a different password...
GOM.Sam
Profile Joined February 2011
Korea (South)210 Posts
August 14 2011 01:00 GMT
#714
Apart from GOM's apology I would personally like to apologize for the inconvenience and concern we have caused you.

Please, if you have not yet, visit GOMTV.net to change your GOM password. Clicking sign in and entering your ID (e-mail address) and old password will direct you to change your password.

If you have been using the same password for other web sites, please change the passwords for those sites as well.

Thank you for your patience and understanding.
Roll Tide.
TDN3
Profile Joined August 2011
United States81 Posts
August 14 2011 01:03 GMT
#715
glad I changed my passwords yesterday.

So, who's the dump hacker?
Goragoth
Profile Blog Joined April 2009
New Zealand1065 Posts
August 14 2011 01:06 GMT
#716
Hang on, what the hackers got are hashed and salted passwords, right?? I mean no fucking moron would be stupid enough to save passwords in plaintext. Seriously if they did then they should be sued into the fucking ground because that would be such utter stupidity on a level I just don't understand.
Creator of LoLTool.
tjg92
Profile Joined March 2011
United States100 Posts
August 14 2011 01:07 GMT
#717
Glad I logged in with Twitter.
The Maze Blog: http://mazeblog-tjg92.blogspot.com
XRaDiiX
Profile Blog Joined November 2010
Canada1730 Posts
Last Edited: 2011-08-14 01:17:23
August 14 2011 01:15 GMT
#718
On August 14 2011 07:49 R1CH wrote:
I have to say I'm happy how this was handled by GOM. 1-2 days notice is better than none at all - many companies will actively try to cover up or downplay such attacks or claim that sensitive data was never stolen.


That's true.

We need to uncover who was really behind these attacks. Was it Kespa? (Sc1 Elitists?)

Was it just some hacker trying to make a buck getting E-mails for spam and/or passwords that might correlate with peoples Paypal account.

We may never know. But lets hope they find out who committed this attack against their website. It was bad enough the security of their site was severely lacking; i hope they can find out who did this and bring them to justice for an attack on E-Sports.


Long Live GomTv and the GSL for their Great contribution to E-Sports for SC2 Thank you.
Never GG MKP | IdrA
Kamikiri
Profile Joined October 2010
United States1319 Posts
August 14 2011 01:19 GMT
#719
Sucks having to change all of my passwords and everything but i cant really say im upset because i enjoy watching koreans play while tastosis talks about random stuff, livin the good life.
Ghad
Profile Blog Joined April 2010
Norway2551 Posts
August 14 2011 01:19 GMT
#720
On August 14 2011 08:51 D_K_night wrote:
The ironic thing in all this, is this:

I couldn't even create a GOMTV.net username/password in the early days when I wanted to watch SC2 games. Because I couldn't, I was forced to sign-up on twitter - just so I could watch GOMTV.

So I suppose things are totally safe on my end here? And yes I use different passwords for everything.



Lol. When GSL started last summer i found that most days that foreigners were playing it was inpossible to log in with gomtv user/pass, so i switched to twitter auth which was more likely to work.
forgottendreams: One underage girl, two drunk guys, one gogo dancer and starcraft 2. Apparently just another day in Europe.
Saltydizzle
Profile Joined July 2011
United States123 Posts
August 14 2011 01:20 GMT
#721
Thankfully i have been too lazy to sign up to watch gom, kinda stupid why not make it accessible for everyone.
lostmage333
Profile Joined October 2010
United States28 Posts
August 14 2011 01:22 GMT
#722
Out of curiosity, were details of all accounts leaked, or only those of people who have purchased premium tickets?
obesechicken13
Profile Blog Joined July 2008
United States10467 Posts
August 14 2011 01:33 GMT
#723
On August 14 2011 10:03 TDN3 wrote:
glad I changed my passwords yesterday.

So, who's the dump hacker?

I think the report was issued 1-2 days after. You may not be safe.
I think in our modern age technology has evolved to become more addictive. The things that don't give us pleasure aren't used as much. Work was never meant to be fun, but doing it makes us happier in the long run.
ReboundEU
Profile Joined September 2010
508 Posts
August 14 2011 01:43 GMT
#724
Fail website design is fail
U MAD BRO?
Meta
Profile Blog Joined June 2003
United States6225 Posts
Last Edited: 2011-08-14 13:50:38
August 14 2011 01:47 GMT
#725
EDIT: Stupid post and I regret it. Sorry for those negatively affected. I did not have an account.
good vibes only
Cashmere
Profile Joined April 2011
Australia66 Posts
Last Edited: 2011-08-14 01:54:35
August 14 2011 01:51 GMT
#726
I sent GOM an email asking for further details. I got a pleasantly quick reply and looks like they're patching things up nicely.

Dear User:

1. Yes, we have re-designed our site over the 24hours.
2. Yes, there are no more plain text in our server.
3. Yes, SQL injection attacks are no more a threat to us.

We greatly appreciate your patience and understanding and we pledge to work
harder to bring you a better and greater service experience.

Thank you

GOMTV.net
makk
Profile Joined June 2011
United Kingdom132 Posts
August 14 2011 01:53 GMT
#727
always amazed by the amount of sites that don't at least hash passwords
Licmyobelisk
Profile Blog Joined August 2008
Philippines3682 Posts
August 14 2011 01:55 GMT
#728
wow good thing I use facebook intergration, Now I'm going to use it on very site
I don't think I've ever wished my opponent good luck prior to a game. When I play, I play to win. I hope every opponent I ever have is cursed with fucking terrible luck. I hope they're stuck playing underneath a stepladder with a black cat in attendance a
mindspike
Profile Blog Joined December 2002
Canada1902 Posts
August 14 2011 01:55 GMT
#729
On August 14 2011 10:47 Meta wrote:
Once again I'm glad I've never paid for a premium ticket to watch the GSL. From day 1 I've maintained that it's a waste of money, and I'm glad I've finally been rewarded for my efforts.


This has nothing to do with premium tickets. Anyone who has a GOM account that did not sign up via facebook or twitter had their password leaked.

You likely have a GOM account, the question is how did you sign up.
zerg/human - vancouver, canada
Azera
Profile Blog Joined December 2010
3800 Posts
August 14 2011 01:56 GMT
#730
Oh dear D;
Check out some great music made by TLers - http://bit.ly/QXYhdb , by intrigue. http://bit.ly/RTjpOR , by ohsea.toc.
Count9
Profile Blog Joined May 2009
China10928 Posts
August 14 2011 01:59 GMT
#731
There appears to be zero security on the passwords as they were stored in plain text

This is hardly surprising tbh, much much larger companies than GOM have plain text password for their websites.
HTODethklok
Profile Joined November 2010
United States221 Posts
August 14 2011 02:03 GMT
#732
Just got a notification email from GOM

Dear Valued GOMTV.net users:

We regretfully inform you that approximately at 2 AM KST, Aug.12th, there has been an attack against our web site, GOMTV.net.

We have found that some of the user information from GOMTV.net has been compromised from the attack. We suspect that the following information might have been exposed: name, location (country), e-mail address, GOMTV.net nickname and password.

We deeply apologize for the inconvenience and concern caused by the intrusion.

Since we use PayPal’s service to handle payments, we do not store nor have any payment related information on our site including your credit card numbers and bank account details.

We strongly encourage you to change your GOMTV.net password and if you have been using the same password for other web sites, we suggest changing the passwords for those sites as well.

Users who have signed up with Facebook or Twitter do not have to worry about changing their passwords as they did not have to enter separate passwords at the time of sign up.

As soon as we discovered the sign of intrusion we have conducted a complete investigation into the incident and have also taken steps to enhance security and strengthen our network system in order to provide you with better protection of your personal information.

We greatly appreciate your patience and understanding and we pledge to work harder to bring you a better and greater service experience.

If you have any concerns or questions please feel free to contact us at support@gomtv.net.

Thank you.
GOMTV.net
Guns for show... Knives for a pro HTODethklok.201 NA
WooChop
Profile Blog Joined April 2010
United States120 Posts
August 14 2011 02:54 GMT
#733
On August 14 2011 10:51 Cashmere wrote:
I sent GOM an email asking for further details. I got a pleasantly quick reply and looks like they're patching things up nicely.

Dear User:

1. Yes, we have re-designed our site over the 24hours.
2. Yes, there are no more plain text in our server.
3. Yes, SQL injection attacks are no more a threat to us.

We greatly appreciate your patience and understanding and we pledge to work
harder to bring you a better and greater service experience.

Thank you

GOMTV.net

That is good to hear. This should probably be added to the OP just so a few less people freak out about it.
supernovamaniac
Profile Blog Joined December 2009
United States3047 Posts
August 14 2011 02:57 GMT
#734
I have a feeling that they upgraded from .txt to .doc

Thank god I signed up through facebook.
ppp
writer22816
Profile Blog Joined September 2008
United States5775 Posts
August 14 2011 02:58 GMT
#735
ROFL plain text, that's what I used the first time I learned PHP.
8/4/12 never forget, never forgive.
ArcticFox
Profile Joined February 2011
United States1092 Posts
August 14 2011 02:58 GMT
#736
My battle.net E-Mail is the same as the one I use on GOM, and someone just tried to reset my battle.net account password. I would suggest changing your battle.net password too, or attaching an authenticator.

Thank God I just use a different password for everything.
Hexaflex
Profile Joined September 2010
United Kingdom70 Posts
August 14 2011 03:05 GMT
#737
Funnily enough, I signed up with the same password that got leaked from PSN because I typed it in without thinking when signing up late at night. No additional information for you, hackers!
True power!
TheRabidDeer
Profile Blog Joined May 2003
United States3806 Posts
August 14 2011 03:07 GMT
#738
On August 14 2011 10:47 Meta wrote:
Once again I'm glad I've never paid for a premium ticket to watch the GSL. From day 1 I've maintained that it's a waste of money, and I'm glad I've finally been rewarded for my efforts.

This doesnt make any sense.
1) The GSL has had tons of amazing games, for a pretty low price.
2) Purchasing GSL premium ticket does not mean anything was stolen from you
3) How does not purchasing the premium ticket reward you now?
Erionn
Profile Joined January 2011
United States1015 Posts
August 14 2011 03:12 GMT
#739
On August 14 2011 10:47 Meta wrote:
Once again I'm glad I've never paid for a premium ticket to watch the GSL. From day 1 I've maintained that it's a waste of money, and I'm glad I've finally been rewarded for my efforts.


You must be...retarded? No personal credit card/paypal/anything information is stored on their site. You could have bought every premium ticket ever nothing would happen.

Rylaji
Profile Joined January 2011
Sweden580 Posts
August 14 2011 03:14 GMT
#740
I dont even know all the sites I might have used my old password on...
Official Fan of; Obama oGs.MC // God of War ST.JulyZerg // d.Naniwa // ST.Squirtle // SlayerS_Alicia // Emperor SlayerS_BoxeR // EG.HuK // White-Ra // MarineKing.Prime.WE // oGs.NaDa's Body // SlayerS.MMA // MvP.DongRaeGu
holy_war
Profile Blog Joined July 2007
United States3590 Posts
August 14 2011 03:16 GMT
#741
GOM made a huge and unfortunate mistake that caused inconvenience among many users, to which they apologized and already made then necessary security changes. GOM has been amazing to SC2 so far and we should continue to support them.
Rylaji
Profile Joined January 2011
Sweden580 Posts
August 14 2011 03:27 GMT
#742
So technically the only accounts on sites or such that are compromised are those where I use my email and that particular password both at the same time?
Official Fan of; Obama oGs.MC // God of War ST.JulyZerg // d.Naniwa // ST.Squirtle // SlayerS_Alicia // Emperor SlayerS_BoxeR // EG.HuK // White-Ra // MarineKing.Prime.WE // oGs.NaDa's Body // SlayerS.MMA // MvP.DongRaeGu
LuckyFool
Profile Blog Joined June 2007
United States9015 Posts
August 14 2011 03:30 GMT
#743
Good thing my gom password was some hugeass random string of numbers that I never changed or used anywhere else.
YoungNeil
Profile Joined October 2010
Canada328 Posts
August 14 2011 03:34 GMT
#744
On August 14 2011 10:47 Meta wrote:
Once again I'm glad I've never paid for a premium ticket to watch the GSL. From day 1 I've maintained that it's a waste of money, and I'm glad I've finally been rewarded for my efforts.

Of course you haven't. This has absolutely nothing to do with money.
KDot2
Profile Blog Joined March 2011
United States1213 Posts
August 14 2011 03:37 GMT
#745
I will continue to support GoM and pay for the amazing games and countless hours of entertainment I get out of it.

urasyupi2
Profile Joined August 2011
United States810 Posts
August 14 2011 03:38 GMT
#746
Lol I saw this 6 days after and my GOM account was the same for almost everything.
hemeh
StyLeD
Profile Joined January 2011
United States2965 Posts
August 14 2011 03:42 GMT
#747
On August 14 2011 10:47 Meta wrote:
Once again I'm glad I've never paid for a premium ticket to watch the GSL. From day 1 I've maintained that it's a waste of money, and I'm glad I've finally been rewarded for my efforts.

You sound like a dick and probably are one.
"Even gophers love Starcraft" - Tasteless. || Davichi | IU <3
Weson
Profile Blog Joined December 2010
Iceland1032 Posts
Last Edited: 2011-08-14 03:53:10
August 14 2011 03:51 GMT
#748
What's with the saving passwords in plain text? I thought Sony tought everyone that its a really really bad idea. Yet is not the last retard born... I'm getting tired of changing my passwords all the time because someone were lazy and forgot to add like 20 lines of code.
"!@€#" - as some guy said
Dox
Profile Blog Joined April 2010
Australia1199 Posts
August 14 2011 04:00 GMT
#749
It saddens me to witness how many people fail to grasp the basic concept of internet security.

* People attempting to changes their passwords WHILE the database is being compromised.
* People complaining about the database being locked whilst this actually serves as protection for them.
* People who use different passwords for different services, and thus are totally unaffected, yet still acting like this is the end of the world.
* People who actually use the same password for everything. Really? Those people still exist?
* Aforementioned people changing all the passwords to their other accounts and yet still continuing to use a single password.

This thread is one huge, tragic reminder of how daft and hopeless people in general can be.
@NvDox | Plantronics Nv: Rossi . mOOnGLaDe . deth . JazBas | @NvSC2 | @NvCoD | @NvLeague | @NvHearthstone | @NvDotA2 | @PLT_MF
urasyupi2
Profile Joined August 2011
United States810 Posts
August 14 2011 04:04 GMT
#750
Noooooo I am too late!!!!!!! ;(
Now I have to make another GOM account....
hemeh
Assirra
Profile Joined August 2010
Belgium4169 Posts
August 14 2011 04:09 GMT
#751
On August 14 2011 12:51 Weson wrote:
What's with the saving passwords in plain text? I thought Sony tought everyone that its a really really bad idea. Yet is not the last retard born... I'm getting tired of changing my passwords all the time because someone were lazy and forgot to add like 20 lines of code.

I think its because well hackers simply never bothered to hack game related companies.
When there was almost no risk to get hacked ppl simply don't bother with security.
After this whole Sony fiasco hackers suddenly started attacking a lot of sites and well it seems the security plain sucks since they never thought it could happen.
Assirra
Profile Joined August 2010
Belgium4169 Posts
August 14 2011 04:11 GMT
#752
On August 14 2011 10:47 Meta wrote:
Once again I'm glad I've never paid for a premium ticket to watch the GSL. From day 1 I've maintained that it's a waste of money, and I'm glad I've finally been rewarded for my efforts.

How exactly are you rewarded? By others people security info stolen?
That is just beyond sad.
photomuse
Profile Joined August 2010
United States102 Posts
August 14 2011 04:16 GMT
#753
This is another example of the reason to have at least two passwords (perhaps more) for your accounts you don't care if they get compromized (like GOMTV) and accounts that you do (like anything to do with money).

I don't blame Gom (although passwords should not be stored in plain text in general). In fact, they did something right by having payment via PayPal. Internet security is simply to complicated for every small shop to do it right. (Even big shops have issues). So, I'm sorry this happened, but not at all surprised.

Again...don't use one password everywhere.
nalgene
Profile Joined October 2010
Canada2153 Posts
August 14 2011 04:23 GMT
#754
On August 14 2011 12:42 StyLeD wrote:
Show nested quote +
On August 14 2011 10:47 Meta wrote:
Once again I'm glad I've never paid for a premium ticket to watch the GSL. From day 1 I've maintained that it's a waste of money, and I'm glad I've finally been rewarded for my efforts.

You sound like a dick and probably are one.

great post... with such hostility...

It's a good thing he waited longer before he put any money into the system since earlier on they had security issues ( which had come to past eventually ).
On August 14 2011 13:11 Assirra wrote:
Show nested quote +
On August 14 2011 10:47 Meta wrote:
Once again I'm glad I've never paid for a premium ticket to watch the GSL. From day 1 I've maintained that it's a waste of money, and I'm glad I've finally been rewarded for my efforts.

How exactly are you rewarded? By others people security info stolen?
That is just beyond sad.

Since he's not an early bird, he doesn't experience the bugs in the old system. It's like getting one of those early ipod things but then the next one has all those problems eliminated ( + significantly larger hdd size ) or most of it and improved upon.
On August 14 2011 13:09 Assirra wrote:
Show nested quote +
On August 14 2011 12:51 Weson wrote:
What's with the saving passwords in plain text? I thought Sony tought everyone that its a really really bad idea. Yet is not the last retard born... I'm getting tired of changing my passwords all the time because someone were lazy and forgot to add like 20 lines of code.

I think its because well hackers simply never bothered to hack game related companies.
When there was almost no risk to get hacked ppl simply don't bother with security.
After this whole Sony fiasco hackers suddenly started attacking a lot of sites and well it seems the security plain sucks since they never thought it could happen.

It's possible that sony is just a big target and gom is highly unlikely to get attacked since it's less known.
Year 2500 Greater Israel ( Bahrain, Cyprus, Egypt, Iran, Iraq, Jordan, Kuwait, Lebanon, Oman, Gaza Strip, West Bank, Qatar, Saudi Arabia, Syria, Turkey, United Arab Emirates, Yemen )
l3link
Profile Joined March 2011
United States2 Posts
Last Edited: 2011-08-14 04:28:50
August 14 2011 04:28 GMT
#755
Unfortunately I can confirm that my login information was used on August 10th (2 days prior to their claim that accounts were hacked) to access my xBox live account with the same login information as my GomTV account. Then, on that account, purchases were made worth ~$125. I would advise anyone that doesn't take this issue seriously to reconsider, as the information was distributed and used for malicious purposes.

My real point here, much like the previous post, is to note that if you use the same password for accounts which have access to stored credit card information, change the login and passwords! When these lists of information are sold, the account information is run on hundreds of sites to see if they can log into any of them, and if so, certain steps are taken to make a financial gain of that information. I never expected GomTV to disregard security and am disappointed in the hoops I had to jump through to restore my financial situation.

Damn it Gom. If I had any alternative to watching the GSL (without staying up until 4:30am...) I would have angrily gone to a competitor. Fix this now.
SxYSpAz
Profile Joined February 2011
United States1451 Posts
Last Edited: 2011-08-14 04:55:52
August 14 2011 04:52 GMT
#756
too bad i had to change all my passwords. I loved that password. put so much thought into it and used it for a lot of stuff

fare thee well perfect password. far thee well...

hope this doesn't mess with the site visits too much though. still love ya gom

Edit: wow, this seriously messed with some people. that's too bad. maybe this isn't so easily forgivable. i mean, i'm fine, but that's really too bad for some. Gom should take this really seriously.
Integra
Profile Blog Joined January 2008
Sweden5626 Posts
Last Edited: 2011-08-14 04:54:39
August 14 2011 04:53 GMT
#757
On August 14 2011 10:47 Meta wrote:
Once again I'm glad I've never paid for a premium ticket to watch the GSL. From day 1 I've maintained that it's a waste of money, and I'm glad I've finally been rewarded for my efforts.

This made zero sense... What does this have to do with you paying or not, you still had an account. If you payed or did not pay the outcome would be same. What effort did you make, according yourself you did nothing! What reward did you get, that the website got hacked or what? how can this possible be a rewarding experience for you?
"Dark Pleasure" | | I survived the Locust war of May 3, 2014
SxYSpAz
Profile Joined February 2011
United States1451 Posts
August 14 2011 04:58 GMT
#758
On August 14 2011 13:53 Integra wrote:
Show nested quote +
On August 14 2011 10:47 Meta wrote:
Once again I'm glad I've never paid for a premium ticket to watch the GSL. From day 1 I've maintained that it's a waste of money, and I'm glad I've finally been rewarded for my efforts.

This made zero sense... What does this have to do with you paying or not, you still had an account. If you payed or did not pay the outcome would be same. What effort did you make, according yourself you did nothing! What reward did you get, that the website got hacked or what? how can this possible be a rewarding experience for you?

he probably thinks that the hackers got credit card info from the people that paid for membership. to anyone that thinks this, they were at least smart enough to equip that with another sites more trusted security (paypal i think), so no ones credit card info was leaked directly from the site.
Sembei
Profile Joined October 2002
Argentina48 Posts
Last Edited: 2011-08-14 05:17:14
August 14 2011 05:07 GMT
#759
...

I had the same passwords in BNET and GOMTV. Today I cant log in to neither of them, I've just changed my password in both using password reset..

I don't know if my BNET account was compromised... because I didn't receive a mail informing a password change.. but I tried mine and it said it was wrong.

I fixed it using password recover and change to a new one.. but I'm not really sure if they accessed my acount.
SwordfishConspiracy
Profile Joined December 2010
United States146 Posts
August 14 2011 05:13 GMT
#760
Passwords stored in plain text? wtf? Did they get a 10 year old to write their login system? Even basic piece of crap frameworks hash your passwords by default.

This sucks
SwordfishConspiracy
setekh
Profile Joined March 2011
15 Posts
August 14 2011 05:26 GMT
#761
It's a miracle it doesn't happen earlier btw, non sanitized input = ownage, leaving your Postgre unpatched and most likely opened to the world = pure ownage ... In the end do not get mad at the hacker / scriptkiddie /, especially when we talk about site where payed services are available leaving such blatant security holes is totally unacceptable.
Now for the serious part :
A simple 'sorry' from GOM is not enough, because people may loose important data if using the same mail/pass combo on other sites. As paying customers we have the right to demand something in return, like Sony did without ppl asking for it, but i doubt if GOM will. I guess at least a free season / HQ + VODs / is in order - for all users, and we must demand for that ! Anyway it would be in their benefit, more viewers and they can stream the HQ with ads version so it won't be a total loss.
No quote
ABCSFirebird
Profile Joined December 2010
Germany90 Posts
August 14 2011 05:42 GMT
#762
The 'sorry' just sounds like sarcasm to me considering the gross negligence of their mistake.

Bye gomtv! I won't continue to trust your mediaplayer either since my firewall/av didn't like it anyway. Maybe this is an unreasonable reaction from my side .. but someone who lacks that much sense for customer security certainly won't become a chance to have a program run on my computer.
This is ten percent luck, twenty percent skill - Fifteen percent concentrated power of will - Five percent pleasure, fifty percent pain ..
xlava
Profile Blog Joined March 2011
United States676 Posts
August 14 2011 05:47 GMT
#763
I'm stunned.

Gom better get their shit together and start encrypting their customer's personal information.
sotmh
Profile Joined May 2010
United States41 Posts
August 14 2011 06:14 GMT
#764
Sloppy move GOM. I am reluctant to do business with companies who cannot protect personal data. Clear text passwords? You may as well make your luggage combination '12345'. Thanks for the heads up, R1CH.
Sembei
Profile Joined October 2002
Argentina48 Posts
August 14 2011 06:25 GMT
#765
On August 14 2011 14:07 Sembei wrote:
...

I had the same passwords in BNET and GOMTV. Today I cant log in to neither of them, I've just changed my password in both using password reset..

I don't know if my BNET account was compromised... because I didn't receive a mail informing a password change.. but I tried mine and it said it was wrong.

I fixed it using password recover and change to a new one.. but I'm not really sure if they accessed my acount.


I contacted blizzard suport and they answer me in 15 minutes at this hour! Fantastic.

Well, my bnet account wasn't accessed for anybody except me :D. So, it was not compromised.

But I will keep changin all my passwords (BECAUSE I DONT REMEMBER WHAT PASSWORD I WAS USING ON GOM! THE ONE I HAD STORED IN FIREFOX WAS OLD and I kept logged in by cookies... This is really anoying).
slytown
Profile Blog Joined March 2011
Korea (South)1411 Posts
August 14 2011 06:37 GMT
#766
Thanks so much R1CH.
The best Flash meme ever: http://imgur.com/zquoK
tinkleondabeach
Profile Joined October 2010
21 Posts
August 14 2011 06:39 GMT
#767
Really Gom? Require us to use 8+ character alphanumeric passwords and you don't even hash/salt them? What's the point of a secure password if you're gonna store them in plain text. Require us to use the player and also require us to register just to take our passwords, that's probably the reason for storing them in plaintext in the first place, what the fuck >:O
Caphe
Profile Blog Joined May 2007
Vietnam10817 Posts
August 14 2011 06:58 GMT
#768
Damn, I used my secondary password on GOM so its not that of a big deal but still I have to change my backup email account and my China Bnet account password.
Thanks for the head up R1CH!!
Terran
munchmunch
Profile Joined October 2010
Canada789 Posts
August 14 2011 07:40 GMT
#769
Trying to log into gomtv.net right now brings up a change password screen, with the caption "Protect Your Valuable Personal Information. Information that hasn’t been modified for a long period of time could be exposed to and abused by others."

Considering they don't mention the exploit at all, this is very disingenuous. I mean, "oh, we didn't make a mistake. It's just that you haven't changed your password in a long time..."

On August 14 2011 14:42 ABCSFirebird wrote:
The 'sorry' just sounds like sarcasm to me considering the gross negligence of their mistake.

Bye gomtv! I won't continue to trust your mediaplayer either since my firewall/av didn't like it anyway. Maybe this is an unreasonable reaction from my side .. but someone who lacks that much sense for customer security certainly won't become a chance to have a program run on my computer.

Considering that there media player is a rip-off of ffmpeg, you can pretty assume that as a rule they aren't too competent on the technical side of things.
sleigh bells
Profile Joined April 2011
United States358 Posts
August 14 2011 08:02 GMT
#770
On August 14 2011 12:27 Rylaji wrote:
So technically the only accounts on sites or such that are compromised are those where I use my email and that particular password both at the same time?

also wondering about this...
Sup son? ¯\__(ツ)__/¯
CardG
Profile Joined March 2011
France131 Posts
August 14 2011 09:05 GMT
#771
Hey, just received an e-mail from Gom. Is it safe? :p
TheShadowZero
Profile Joined August 2011
United States9 Posts
August 14 2011 09:40 GMT
#772
Wow I am so glad I used Twitter to sign up for this...one good thing about this whole "unified" log-in thing FB and Twitter are starting to do, I guess.
Though I do have to ask...why did the OpenID initiative start losing ground? After I got one I started to see it pop up everywhere. I guess Facebook's log-in started to take over and seem more appealing. Bummer.
wussleeQ
Profile Blog Joined June 2009
United States3130 Posts
August 14 2011 09:43 GMT
#773
wow. this could've really fucked me over. good thing i used an old email for this... bad gom!
BW -> League -> CSGO
nalgene
Profile Joined October 2010
Canada2153 Posts
August 14 2011 09:50 GMT
#774
On August 14 2011 18:05 CardG wrote:
Hey, just received an e-mail from Gom. Is it safe? :p

Click it---> View Source ---> Does it match?
Year 2500 Greater Israel ( Bahrain, Cyprus, Egypt, Iran, Iraq, Jordan, Kuwait, Lebanon, Oman, Gaza Strip, West Bank, Qatar, Saudi Arabia, Syria, Turkey, United Arab Emirates, Yemen )
Sqalevon
Profile Joined August 2010
Netherlands523 Posts
August 14 2011 09:50 GMT
#775
Damn, I use this password for alot of websites, luckely not for hig security stuff.
CardG
Profile Joined March 2011
France131 Posts
August 14 2011 09:56 GMT
#776
On August 14 2011 18:50 nalgene wrote:
Show nested quote +
On August 14 2011 18:05 CardG wrote:
Hey, just received an e-mail from Gom. Is it safe? :p

Click it---> View Source ---> Does it match?

It's ok ^^
Though, i changed my password last time, and can't reconnect with it. And the password recovery thing doesn't send me any mails >_>
Palmar
Profile Blog Joined July 2010
Iceland22633 Posts
August 14 2011 10:07 GMT
#777
time to change some passwords.
Computer says mafia
pe
Profile Joined June 2011
13 Posts
August 14 2011 10:39 GMT
#778
Tried to change password when i first heard this yesterday, but it didn't work. Now I can't log in to GOM anymore
DaCruise
Profile Joined July 2010
Denmark2457 Posts
August 14 2011 11:06 GMT
#779
Fucking great. Just signed up to GOM 3 days ago and now its compromised!!!
Deleted User 101379
Profile Blog Joined August 2010
4849 Posts
August 14 2011 11:09 GMT
#780
On August 14 2011 18:40 TheShadowZero wrote:
Wow I am so glad I used Twitter to sign up for this...one good thing about this whole "unified" log-in thing FB and Twitter are starting to do, I guess.
Though I do have to ask...why did the OpenID initiative start losing ground? After I got one I started to see it pop up everywhere. I guess Facebook's log-in started to take over and seem more appealing. Bummer.


The problem with this is that if facebook gets compromised, it's insta-access to all other websites.
If you have one login per site, if it gets compromised, in theory only this site is compromised - though using one password for everything kind of defeats it again.
Goragoth
Profile Blog Joined April 2009
New Zealand1065 Posts
August 14 2011 11:12 GMT
#781
Whenever you get an email telling you to change your password go to the site by typing the URL manually or using a bookmark, never by following a link in the email. The risk of getting taken by some fishing scam is far too great.
Creator of LoLTool.
Hyaena
Profile Joined June 2011
Croatia17 Posts
August 14 2011 11:30 GMT
#782
Hi,
I'm using keepass for almost two months (as R1CH suggested in some older thread, thanks btw) and have random password for each site. The thing is, email used in logging on gomtv is used for few more sites. Should i take any extra security steps (I changed gomtv password) and is spamming my email the worst thing that can happen (doubt someone would brute-force email)?
Thanks!
Titorelli
Profile Joined March 2011
2492 Posts
August 14 2011 11:49 GMT
#783
So now it is safe to change ones pw?
"Everybody poops.... after Tasteless kills them" Artosis
Flwz
Profile Joined December 2010
Ireland19 Posts
Last Edited: 2011-08-14 12:17:45
August 14 2011 12:16 GMT
#784
This is quite bad, I work in IT security and I have sent an emai lto GomTv discussing this issue.

I have asked the following questions :

For complete transparency, and as a user, I would like you to answer the following questions for me :
- Are passwords actually stored in plain text?
- How many user accounts have been compromised (how many user accounts in the DB)
- What are the steps you are taking for this not to happen again.

To my pleasant surprise, they did reply within one hour with the following :
"Dear Jeremy.


1. No they were not plain text. But there was a part of section where it was plain text. We are investigating how that had happened.

2. We are under investigation.

3. As soon as we found out about the hacking we have brought a team to re-build for better security of our system. For it not to occur again as a support team we do not have solid answer for you yet. But from what we heard we will be bringing teams to test our server(security) regularly.

Thank you for your time to take interest in our situation. And we apologize for the incident.

GOMTV.net"


I am not sure I understand answer 1, "They are not plain text but yeah they are" is a bit concerning, question 2 they completely avoided and answer to 3 means support does not have much more information than we do.

All in all,as has been said before, you should :
- Change GomTV password as soon as possible
- Change your password on any website / service where you used the same password (facebook, twitter, gmail, TL, forums, anything)
- Credit card and bank details are SAFE as they do not process the payments themselves (they go through Paypal).

Unfortunately these issues with user data security are not limited to GomTV (hello Sony), and as such it is very important not to reuse passwords over several sites.



R3N
Profile Joined March 2011
740 Posts
August 14 2011 12:33 GMT
#785
I use the same password (with or without numbers) for EVERYTHING (mail, forums, games etc.) since 9-10 years back. I ain't going to change it.

I ***REALLY*** hope I wasn't hit
Znakie
Profile Joined August 2011
Denmark2 Posts
August 14 2011 13:04 GMT
#786
Websites programmers should really start to take this stuff seriously - got like a 100 different accounts(most of them not active) on various sites around the web, and seems like a get an email every other week, or read somewhere on the web, that I have to change my password on this and that site, because they have had a breach.
Teton
Profile Joined May 2010
France1656 Posts
August 14 2011 13:13 GMT
#787
password plain text? LOL
Epic fail GomTV.
SinCitta
Profile Blog Joined August 2010
Germany2127 Posts
August 14 2011 13:14 GMT
#788
On August 14 2011 21:33 R3N wrote:
I use the same password (with or without numbers) for EVERYTHING (mail, forums, games etc.) since 9-10 years back. I ain't going to change it.

I ***REALLY*** hope I wasn't hit


You really, really should (MUST). At least for everything involving your bank account (obviously), social network accounts (social contacts can be exploited) and your mail account (for password recovery). Bots can be used to automatically exploit your logins in which case something bad is bound to happen.
Sephy90
Profile Blog Joined January 2010
United States1785 Posts
August 14 2011 13:19 GMT
#789
Is this for real... come on now gom you were doing great for me now I'm really really disappointed.
"So I turned the lights off at night and practiced by myself"
meegrean
Profile Joined May 2008
Thailand7699 Posts
August 14 2011 13:34 GMT
#790
This is sooo disturbing.
Brood War loyalist
JinDesu
Profile Blog Joined August 2010
United States3990 Posts
August 14 2011 13:45 GMT
#791
On August 14 2011 21:16 Flwz wrote:
This is quite bad, I work in IT security and I have sent an emai lto GomTv discussing this issue.

I have asked the following questions :

For complete transparency, and as a user, I would like you to answer the following questions for me :
- Are passwords actually stored in plain text?
- How many user accounts have been compromised (how many user accounts in the DB)
- What are the steps you are taking for this not to happen again.

To my pleasant surprise, they did reply within one hour with the following :
"Dear Jeremy.


1. No they were not plain text. But there was a part of section where it was plain text. We are investigating how that had happened.

2. We are under investigation.

3. As soon as we found out about the hacking we have brought a team to re-build for better security of our system. For it not to occur again as a support team we do not have solid answer for you yet. But from what we heard we will be bringing teams to test our server(security) regularly.

Thank you for your time to take interest in our situation. And we apologize for the incident.

GOMTV.net"


I am not sure I understand answer 1, "They are not plain text but yeah they are" is a bit concerning, question 2 they completely avoided and answer to 3 means support does not have much more information than we do.

All in all,as has been said before, you should :
- Change GomTV password as soon as possible
- Change your password on any website / service where you used the same password (facebook, twitter, gmail, TL, forums, anything)
- Credit card and bank details are SAFE as they do not process the payments themselves (they go through Paypal).

Unfortunately these issues with user data security are not limited to GomTV (hello Sony), and as such it is very important not to reuse passwords over several sites.





It could be multiple files compromised, and the plain text file being preeetty important.

However, I gotta admit, Gom's pretty good if they were to answer a these questions with pretty good transparency in such short time to you.
Yargh
Shootist
Profile Joined May 2011
Singapore405 Posts
August 14 2011 15:17 GMT
#792
Man what is with all this plain text password catastrophes. I work in the IT line myself and it's really not much effort to implement at least a half-decent encryption.
Deleted User 101379
Profile Blog Joined August 2010
4849 Posts
August 14 2011 15:21 GMT
#793
On August 15 2011 00:17 Shootist wrote:
Man what is with all this plain text password catastrophes. I work in the IT line myself and it's really not much effort to implement at least a half-decent encryption.


As i always say:
99% of the programmers have no clue about anything and shouldn't work in that section... sadly they do -.-
Jank
Profile Blog Joined March 2008
United States308 Posts
August 14 2011 15:23 GMT
#794
On August 15 2011 00:17 Shootist wrote:
Man what is with all this plain text password catastrophes. I work in the IT line myself and it's really not much effort to implement at least a half-decent encryption.

I dunno, that one function call is a bit of a doozie.
"You don't know you're wearing a leash if you sit by the peg all day." - Michael Parenti
Teton
Profile Joined May 2010
France1656 Posts
August 14 2011 15:26 GMT
#795
On August 15 2011 00:17 Shootist wrote:
Man what is with all this plain text password catastrophes. I work in the IT line myself and it's really not much effort to implement at least a half-decent encryption.



Encryption is already implemented on mysql database or on google
Trigger1101
Profile Joined April 2011
Sweden80 Posts
August 14 2011 15:46 GMT
#796
Is it safe to buy now ?
asdfTT123
Profile Blog Joined June 2009
United States989 Posts
August 14 2011 15:47 GMT
#797
storing passwords in plain text? ROFL WHAT THE FUCK GOM
n.Die_Jaedong <3
XiGua
Profile Blog Joined April 2010
Sweden3085 Posts
August 14 2011 16:46 GMT
#798
Holy...

I don't want to change every the password on ALL my accounts and sites. I mean, I have like 50 of them!

Disappointed by GOMTV really... Seriously.
ლ(ಠ益ಠლ) APM, Why u make me spam?
hiturheartx
Profile Joined August 2011
61 Posts
August 14 2011 16:50 GMT
#799
what the hell?
mprs
Profile Joined April 2010
Canada2933 Posts
Last Edited: 2011-08-14 16:57:55
August 14 2011 16:57 GMT
#800
On August 14 2011 21:33 R3N wrote:
I use the same password (with or without numbers) for EVERYTHING (mail, forums, games etc.) since 9-10 years back. I ain't going to change it.

I ***REALLY*** hope I wasn't hit


You were.


On August 15 2011 00:46 Trigger1101 wrote:
Is it safe to buy now ?


It was always safe to buy. Bank information is not stored on the site. It is all done via Paypal. If paypal gets hacked on the other hand...
We talkin about PRACTICE
hiturheartx
Profile Joined August 2011
61 Posts
August 14 2011 17:09 GMT
#801
are the new passwords GOMTV told us to change into going to be safe? because all my important account details such as my email, paypal etc are all using the same 'new' password that i just made.
Dharmok
Profile Joined April 2010
Netherlands57 Posts
August 14 2011 17:15 GMT
#802
On August 15 2011 02:09 hiturheartx wrote:
are the new passwords GOMTV told us to change into going to be safe? because all my important account details such as my email, paypal etc are all using the same 'new' password that i just made.


Ehmz, I hope for your sake that you are just trolling... If not, this situation clearly hasn't taught you anything. I advise you to read through this thread a bit more...
Only dead fish go with the flow
ComaDose
Profile Blog Joined December 2009
Canada10357 Posts
August 14 2011 17:15 GMT
#803
On August 15 2011 02:09 hiturheartx wrote:
are the new passwords GOMTV told us to change into going to be safe? because all my important account details such as my email, paypal etc are all using the same 'new' password that i just made.

Bad strategy bro.

Really GOM? lol thanks RICH
BW pros training sc2 is like kiss making a dub step album.
Waltchelg
Profile Joined April 2010
United States66 Posts
August 14 2011 17:36 GMT
#804
Well, I wake up this morning to see that someone bought $110 worth of microsoft points on my xbox live account. I guess that's what I get for keeping cc information saved on my XBL account. time to get this shit reversed...

Fuck. Time to go running around changing pws for a few sites just in case they try those too.
Elite Muffin Crew / No Talent member
Sewi
Profile Blog Joined November 2006
Germany1697 Posts
August 14 2011 17:43 GMT
#805
So I am a bit confused now. Gom encourages us to change the PW but some people keep saying that it is still not safe. I dont want to have to change all PWs again when I do it now.
Can anyone confirm it is safe now?
"Well, things were going ok until he lost all his stuff" - Tasteless, 17.02.2016
Asday
Profile Joined November 2010
United Kingdom388 Posts
August 14 2011 18:15 GMT
#806
Checked my massive list of firefox saved passwords, and the gomtv one is indeed my base password for around 1300 others, but, it's paired with my "smurf" email account I use for shit I don't trust. :D Turns out I was a noob when I signed up for GOM, and didn't know what it was.

Changed my password anyway, according to XKCD's password entropy guide.

+ Show Spoiler +
[image loading]
hiturheartx
Profile Joined August 2011
61 Posts
August 14 2011 19:40 GMT
#807
On August 15 2011 02:15 ComaDose wrote:
Show nested quote +
On August 15 2011 02:09 hiturheartx wrote:
are the new passwords GOMTV told us to change into going to be safe? because all my important account details such as my email, paypal etc are all using the same 'new' password that i just made.

Bad strategy bro.

Really GOM? lol thanks RICH


why the heck would GOM ask us to change our password again if it still isnt being secured?
Sembei
Profile Joined October 2002
Argentina48 Posts
August 14 2011 19:47 GMT
#808
On August 15 2011 04:40 hiturheartx wrote:
Show nested quote +
On August 15 2011 02:15 ComaDose wrote:
On August 15 2011 02:09 hiturheartx wrote:
are the new passwords GOMTV told us to change into going to be safe? because all my important account details such as my email, paypal etc are all using the same 'new' password that i just made.

Bad strategy bro.

Really GOM? lol thanks RICH


why the heck would GOM ask us to change our password again if it still isnt being secured?


Yes, they said that security measures has been made. But you still need an unique password for Paypal and each important site like that. Gom is maybe more secure now, but we don't know if it won't be hacked again (like any other site could be).
adrenaLinG
Profile Blog Joined August 2010
Canada676 Posts
August 14 2011 20:04 GMT
#809
Wow were they storing passwords in plaintext?
¯\_(ツ)_/¯
EndOfTime88
Profile Joined February 2011
Austria259 Posts
August 14 2011 20:14 GMT
#810
On August 15 2011 02:09 hiturheartx wrote:
are the new passwords GOMTV told us to change into going to be safe? because all my important account details such as my email, paypal etc are all using the same 'new' password that i just made.

LOL, I hope you're not serious bud.
"Time is what we want most,but what we use worst."-William Penn
dekuschrub
Profile Joined May 2008
United States2069 Posts
August 14 2011 20:36 GMT
#811
kk just changed my pwords! thanks
Deleted User 135096
Profile Blog Joined December 2010
3624 Posts
August 14 2011 20:45 GMT
#812
whoah! Been in Canada for 2 days, thanks for the heads up R1CH!
Administrator
Kamikiri
Profile Joined October 2010
United States1319 Posts
August 14 2011 20:58 GMT
#813
On August 15 2011 02:09 hiturheartx wrote:
are the new passwords GOMTV told us to change into going to be safe? because all my important account details such as my email, paypal etc are all using the same 'new' password that i just made.


How rude of you to come into this thread and troll people who actually made a mistake using the same passwords and had stuff stolen because of this, you come in here trolling like this, very very rude. Also for the slim chance you are being serious, you are just dumb.
Holykitty
Profile Joined May 2011
Netherlands246 Posts
August 14 2011 21:30 GMT
#814
changed my GOMtv password this morning after I received and email and read this thread
i already cant remember what i changed it to .. :<
farewell best memorable password ever! ;__;
Where there's smoke, there's me
AngelusDeLetum
Profile Joined April 2010
United States98 Posts
August 14 2011 22:33 GMT
#815
holy shit i am so glad i sign in with twitter
Goldfish
Profile Blog Joined August 2010
2230 Posts
Last Edited: 2011-08-15 00:56:01
August 15 2011 00:54 GMT
#816
On August 15 2011 02:43 Sewi wrote:
So I am a bit confused now. Gom encourages us to change the PW but some people keep saying that it is still not safe. I dont want to have to change all PWs again when I do it now.
Can anyone confirm it is safe now?


Yeah is it safe?

Also @hiturheartx - You should always use different passwords for each site.

Maybe you can use the same password for lesser important sites (like GOMTV or just forums where there's no major risk if you lose the accounts) but at least use unique passwords for sites like paypal, your email addresses, etc.

Also this sort of thing sadly happens very frequently. I remember when "Mozilla" (yes, them >.<) accidentally uploaded account name and password database of Firefox Addon accounts in a public place where it could be downloaded by everyone.

Yes so if Mozilla screws up like that, other major companies can screw up (We already have GOMTV, Sony, EA and Bioware, etc all have had these same problems). It really is unfortunately but it happens quite often .

Yep that was when I first learned to never use the same password for sites ever again.
https://connect.microsoft.com/WindowsServerFeedback/feedback/details/741495/biggest-explorer-annoyance-automatic-sorting-windows-7-server-2008-r2-and-vista#details Allow Disable Auto Arrange in Windows 7+
ShadowDrgn
Profile Blog Joined July 2007
United States2497 Posts
August 15 2011 01:27 GMT
#817
On August 15 2011 03:15 Asday wrote:
Checked my massive list of firefox saved passwords, and the gomtv one is indeed my base password for around 1300 others,


1300?! I've been saving passwords in Mozilla/Firefox for 10 years, and I only have ~100 saved, most of which are for sites I haven't loaded in a long time.
Of course, you only live one life, and you make all your mistakes, and learn what not to do, and that’s the end of you.
obesechicken13
Profile Blog Joined July 2008
United States10467 Posts
Last Edited: 2011-08-15 02:19:27
August 15 2011 01:47 GMT
#818
On August 15 2011 03:15 Asday wrote:
Checked my massive list of firefox saved passwords, and the gomtv one is indeed my base password for around 1300 others, but, it's paired with my "smurf" email account I use for shit I don't trust. :D Turns out I was a noob when I signed up for GOM, and didn't know what it was.

Changed my password anyway, according to XKCD's password entropy guide.

+ Show Spoiler +
[image loading]

Lol, at the picture. Couldn't you theoretically just make the password guessing script try out combinations of dictionary words? I figure this would vastly decrease the number of possible passwords.

edit: no that's stupid. There still might be a way to do it though. Like make the script not try any combinations of letters unless they are dictionary words. It'd at least increase efficiency slightly.
I think in our modern age technology has evolved to become more addictive. The things that don't give us pleasure aren't used as much. Work was never meant to be fun, but doing it makes us happier in the long run.
King K. Rool
Profile Blog Joined May 2009
Canada4408 Posts
Last Edited: 2011-08-15 01:59:07
August 15 2011 01:57 GMT
#819
plaintext lol.

i can't remember my password or nickname =_= anymore. GG

edit: Nvm guessed my nick. I figure I didn't reuse any important password anyways.
Morphs
Profile Joined July 2010
Netherlands645 Posts
August 15 2011 03:21 GMT
#820
Well, guess that was a forced password overhaul for me (I use a few passwords for quite some sites). Of course I deleted my Gomtv account since it wasn't a paid account and I didn't watch much gomtv anyway..
Welmu
Profile Blog Joined November 2009
Finland3295 Posts
August 15 2011 04:30 GMT
#821
luckily i use that password almost only on GOM and some other random sites...
every other site I use same password >_>
Progamertwitter.com/welmu1 | twitch.com/Welmu1
Nos-
Profile Blog Joined February 2011
Canada12016 Posts
August 15 2011 04:42 GMT
#822
Hopefully GOM has done their share of damage control and learned their lesson from this. Sucks when things like this happen but storing information in plain text is kind of outrageous, especially with the recent hackings of multiple industries (PSN, Bioware, etc.). Guess Gom will just have to step up their security in case someone tries again. Thanks for the heads up R1CH!
Bronze player stuck in platinum
Alethios
Profile Blog Joined December 2007
New Zealand2765 Posts
August 15 2011 07:14 GMT
#823
Well, probably a good thing to change all my passwords.

Terminated my gomtv account too in the end.
When you arise in the morning, think of what a precious privilege it is to be alive - to breathe, to think, to enjoy, to love.
kinetic_skink
Profile Blog Joined November 2010
Australia125 Posts
August 15 2011 07:45 GMT
#824
On August 14 2011 21:16 Flwz wrote:
This is quite bad, I work in IT security and I have sent an emai lto GomTv discussing this issue.

I have asked the following questions :

For complete transparency, and as a user, I would like you to answer the following questions for me :
- Are passwords actually stored in plain text?
- How many user accounts have been compromised (how many user accounts in the DB)
- What are the steps you are taking for this not to happen again.

To my pleasant surprise, they did reply within one hour with the following :
"Dear Jeremy.


1. No they were not plain text. But there was a part of section where it was plain text. We are investigating how that had happened.

2. We are under investigation.

3. As soon as we found out about the hacking we have brought a team to re-build for better security of our system. For it not to occur again as a support team we do not have solid answer for you yet. But from what we heard we will be bringing teams to test our server(security) regularly.

Thank you for your time to take interest in our situation. And we apologize for the incident.

GOMTV.net"


I am not sure I understand answer 1, "They are not plain text but yeah they are" is a bit concerning, question 2 they completely avoided and answer to 3 means support does not have much more information than we do.

All in all,as has been said before, you should :
- Change GomTV password as soon as possible
- Change your password on any website / service where you used the same password (facebook, twitter, gmail, TL, forums, anything)
- Credit card and bank details are SAFE as they do not process the payments themselves (they go through Paypal).

Unfortunately these issues with user data security are not limited to GomTV (hello Sony), and as such it is very important not to reuse passwords over several sites.


I would read 1 as the passwords were encrypted in storage, but they may have logged log in to a flat file or something similar
Day[9] (Aus): http://freezone.iinet.net.au/channels/freezone/gaming/day9-webcasts
BuzZoo
Profile Joined October 2010
Australia1468 Posts
August 15 2011 09:52 GMT
#825
Anyone else suddenly have the GOM toolbar without installing it today? I came back from work and it was suddenly there when I opened firefox. No one else uses my computer as I just live with my girlfriend and she got back from work later than me.
I've disabled it cos I don't trust it and when I go to uninstall it, it asks if I want to let some weird filename have access to my computer.
kyophan
Profile Joined January 2010
United States113 Posts
August 15 2011 09:59 GMT
#826
I think the answer is probably not necessary, but just to make sure. Is it recommended that I get a new main email?
M1cha84
Profile Joined October 2010
Germany64 Posts
August 15 2011 10:00 GMT
#827
On August 15 2011 18:52 BuzZoo wrote:
Anyone else suddenly have the GOM toolbar without installing it today? I came back from work and it was suddenly there when I opened firefox. No one else uses my computer as I just live with my girlfriend and she got back from work later than me.
I've disabled it cos I don't trust it and when I go to uninstall it, it asks if I want to let some weird filename have access to my computer.


Maybe you should scan your PC for virusses! That is not normal oO
BuzZoo
Profile Joined October 2010
Australia1468 Posts
August 15 2011 10:09 GMT
#828
On August 15 2011 19:00 M1cha84 wrote:
Show nested quote +
On August 15 2011 18:52 BuzZoo wrote:
Anyone else suddenly have the GOM toolbar without installing it today? I came back from work and it was suddenly there when I opened firefox. No one else uses my computer as I just live with my girlfriend and she got back from work later than me.
I've disabled it cos I don't trust it and when I go to uninstall it, it asks if I want to let some weird filename have access to my computer.


Maybe you should scan your PC for virusses! That is not normal oO


Yeah I might just do that. Thanks!
Velr
Profile Blog Joined July 2008
Switzerland10809 Posts
August 15 2011 10:21 GMT
#829
21 failed login attemps on my e-mail account. But last login still 10 days ago so i seem to be fine.

Fun times.
Kryt0s
Profile Joined August 2010
Germany209 Posts
August 15 2011 10:26 GMT
#830
I don't even think, that it's so bad, that they got hacked... It's just, that they did not have the passwords encoded... I mean really? A lot of companys get hacked, but their information is usually useless, cause it would take to long to encrypt the information.
Tofugrinder
Profile Joined September 2010
Austria899 Posts
August 15 2011 10:47 GMT
#831
wow they have a terrible system -.-
when I saw that thread I immediatetly changed the password on gomtv and was kinda curious why gom didnt have any information on their site.

now i logged in and the system wanted me - the already changed password - again -.- good that the system is crappy anyway because i could change it and change it back..

gom, that's NOT how you do it.
TheKnight
Profile Joined June 2010
Romania77 Posts
August 15 2011 10:50 GMT
#832
good thing i use a unique pass on my email even if something else gets hacked my mail will be safe, it's kinda unsettling though seeing the info get stolen
orly?
AmericanUmlaut
Profile Blog Joined November 2010
Germany2581 Posts
August 15 2011 12:44 GMT
#833
On August 15 2011 16:45 kinetic_skink wrote:
Show nested quote +
On August 14 2011 21:16 Flwz wrote:
This is quite bad, I work in IT security and I have sent an emai lto GomTv discussing this issue.

I have asked the following questions :

For complete transparency, and as a user, I would like you to answer the following questions for me :
- Are passwords actually stored in plain text?
- How many user accounts have been compromised (how many user accounts in the DB)
- What are the steps you are taking for this not to happen again.

To my pleasant surprise, they did reply within one hour with the following :
"Dear Jeremy.


1. No they were not plain text. But there was a part of section where it was plain text. We are investigating how that had happened.

2. We are under investigation.

3. As soon as we found out about the hacking we have brought a team to re-build for better security of our system. For it not to occur again as a support team we do not have solid answer for you yet. But from what we heard we will be bringing teams to test our server(security) regularly.

Thank you for your time to take interest in our situation. And we apologize for the incident.

GOMTV.net"


I am not sure I understand answer 1, "They are not plain text but yeah they are" is a bit concerning, question 2 they completely avoided and answer to 3 means support does not have much more information than we do.

All in all,as has been said before, you should :
- Change GomTV password as soon as possible
- Change your password on any website / service where you used the same password (facebook, twitter, gmail, TL, forums, anything)
- Credit card and bank details are SAFE as they do not process the payments themselves (they go through Paypal).

Unfortunately these issues with user data security are not limited to GomTV (hello Sony), and as such it is very important not to reuse passwords over several sites.


I would read 1 as the passwords were encrypted in storage, but they may have logged log in to a flat file or something similar

I'm a web application developer, and that sounds pretty plausible. Passwords are generally posted in plain text when you log in to a site, then they're used to generate a hash that is compared to the hash stored in the database - if the hashes are identical, then the password is (considered to be) correct. I could imagine a situation where someone writes a sloppy transaction log that stores posted values and that log is accessed by an intruder. It at least sounds more plausible than a site as big as Gom storing passwords in plain text.
The frumious Bandersnatch
Ghad
Profile Blog Joined April 2010
Norway2551 Posts
August 15 2011 13:25 GMT
#834
Hmm, now i cant login with twitter anymore. First time i try since last wednesday.
forgottendreams: One underage girl, two drunk guys, one gogo dancer and starcraft 2. Apparently just another day in Europe.
darkgray
Profile Joined September 2010
Sweden11 Posts
Last Edited: 2011-08-15 15:22:40
August 15 2011 15:22 GMT
#835
On August 15 2011 22:25 Ghad wrote:
Hmm, now i cant login with twitter anymore. First time i try since last wednesday.

I can't log in through Facebook anymore. I e-mailed their support, and they're supposedly looking into it.
vitruvia
Profile Joined June 2009
Canada235 Posts
August 15 2011 15:51 GMT
#836
what's R1CH's opinion on this?
what quote?
Gutrot
Profile Joined August 2010
122 Posts
August 15 2011 15:55 GMT
#837
My passwords generally evolve, and the password I used on GoM was my password from about 2 years ago... I had a hard time tracking down any useful site I still used it for, but yikes. No encription or anything on the GOM site?
WniO
Profile Blog Joined April 2010
United States2706 Posts
August 15 2011 18:40 GMT
#838
Changed my passwords, thanks for the spotlight. Some people I know sent out spam mail so they apparently got hacked or whatever.
sluggaslamoo
Profile Blog Joined November 2009
Australia4494 Posts
Last Edited: 2011-08-15 19:44:35
August 15 2011 19:38 GMT
#839
Make sure you change the password to your email address too, I'd say a lot of people used the same password for their gom account as their email address, if you use that email on Ebay/Amazon/Paypal login change that too.

Hackers already have your password on file (a long with a million others) and will probably be shooting it around forums and such, so its not like changing it on GOM will help that much.

Fucking GOM, companies that aren't proactive about their security never will be, even if they patch all their current problems, because they don't know crap about security their coders will just create more holes for breaches as they keep making their crap media player. So I will never trust them in the future.


On August 15 2011 19:21 Velr wrote:
21 failed login attemps on my e-mail account. But last login still 10 days ago so i seem to be fine.

Fun times.


Did you really think they want your account details so they can log into GOM?
Come play Android Netrunner - http://www.teamliquid.net/forum/viewmessage.php?topic_id=409008
ZergCacique
Profile Joined July 2011
United States28 Posts
August 15 2011 20:15 GMT
#840
for some reason it doesn't change the password that i want.
S.O.L.I.D.
Profile Blog Joined September 2010
United States792 Posts
August 15 2011 20:20 GMT
#841
Fantastic, this would happen while I'm on vacation. Good work GOM, plain text, really?
IronWolf
Profile Blog Joined October 2009
South Africa315 Posts
August 15 2011 20:37 GMT
#842
FFS GOM - clear text!!!!WTF
KevinIX
Profile Joined October 2009
United States2472 Posts
August 15 2011 20:46 GMT
#843
Yep, ever since my WoW account almost got hacked, I've had unique passwords for each website I visit.

Liquid FIGHTING!!!
nalgene
Profile Joined October 2010
Canada2153 Posts
August 15 2011 21:24 GMT
#844
According to their response, they had only just hired a team to test it occasionally.

On August 16 2011 04:38 sluggaslamoo wrote:
Fucking GOM, companies that aren't proactive about their security never will be, even if they patch all their current problems, because they don't know crap about security their coders will just create more holes for breaches as they keep making their crap media player. So I will never trust them in the future.

It's unfortunate that they only have like 6 options in their media player for renderer options ( a few VMR7/9's / overlay mixer, but no option to use madVR as a video renderer ), and it also doesn't work with vsfilter either.
Year 2500 Greater Israel ( Bahrain, Cyprus, Egypt, Iran, Iraq, Jordan, Kuwait, Lebanon, Oman, Gaza Strip, West Bank, Qatar, Saudi Arabia, Syria, Turkey, United Arab Emirates, Yemen )
Sokalo
Profile Joined May 2010
United States375 Posts
August 15 2011 22:43 GMT
#845
Hmm, just received an e-mail asking me to verify my new battle.net account registered to my e-mail I used to register with GOM. My real battle.net account uses a smurf e-mail.

Greeeat.
"Sometimes I wonder whether the world is being run by smart people who are putting us on, or by imbeciles who really mean it."
BigFan
Profile Blog Joined December 2010
TLADT24920 Posts
August 15 2011 22:56 GMT
#846
Anyone else get a letter from GOM about the breach? I changed all my passwords the same day that this news came out
Former BW EiC"Watch Bakemonogatari or I will kill you." -Toad, April 18th, 2017
Mohdoo
Profile Joined August 2007
United States15725 Posts
August 15 2011 23:07 GMT
#847
On August 16 2011 07:43 Sokalo wrote:
Hmm, just received an e-mail asking me to verify my new battle.net account registered to my e-mail I used to register with GOM. My real battle.net account uses a smurf e-mail.

Greeeat.


Same, which is really interesting. The email account I use for GOM is different than that of Battle.net, yet I got an email from Blizzard saying that my account has been locked until I verify who I am.
Goldfish
Profile Blog Joined August 2010
2230 Posts
August 15 2011 23:17 GMT
#848
On August 15 2011 18:59 kyophan wrote:
I think the answer is probably not necessary, but just to make sure. Is it recommended that I get a new main email?


Yep it's not really needed. Just make sure you password is unique to that email only and make sure it's long and contains a combo of numbers and letters.

Though I recommend using or creating an email solely for lesser important sites like forums and GOMTV for example. Like my previous post, so far this has happened to - GOMTV, Sony, Bioware, EA games, Mozilla (they accidentally uploaded passwords/account info somewhere based on firefox addon accounts >.<), etc.

Make sure to use unique passwords for everything.

Additionally recommendations (long post):
+ Show Spoiler +

You can create one email for talking with friends only (but said email is not registered to any site or forum). The reason for this is typically sometimes friends may actually do a reply all or whatever instead of using BCC causing all "their" friends or contacts to see your email. Basically a lot of people will know your email address and the more you have, the more chances someone may try to steal it (This is just to be extra safe or paranoid if you want as the chances of people trying to get into your email are probably low and the chances of them succeeding are much lower if you use a unique long password. This is just to be safe).

Create one main/important email all the important things like bank, paypal, battle.net, etc. You can additionally also add things like Steam account, or EA Games and/or Playstation Network or if you can just create another email for those.

Finally a third(or fourth if you're doing the latter of the above) email for stuff that isn't as important like GOMTV, forums, etc. That is if you lose that email, no major damage would be done and nothing too valuable would be lost.

Yeah I know it's overkill and typically one or two emails is enough but if you want to be extra safe, I'd suggest at least having one email dedicated to stuff that isn't as important like forums or the like. This will be your "throw away email" (if it gets hacked or lost, nothing too bad would happen since it's not your main email).

It's a good system and most email providers do not really care if you make multiple accounts and use them.

Finally of course use all different passwords for everything.

Also remember to log into every email you have at least once every two weeks or so.

Most email providers have a term where if your account is inactive for a certain amount of time (I think Yahoo for example is 2 or 3 months and gmail is maybe 9 months), it gets deleted due to inactivity. So log onto your account at least once every two weeks or so (make sure to do a quick memory scan with anti virus software[avast for example has it if you set up a memory scan] or super antispyware, malware bytes, windows defender, etc just in case before logging on all your email).
https://connect.microsoft.com/WindowsServerFeedback/feedback/details/741495/biggest-explorer-annoyance-automatic-sorting-windows-7-server-2008-r2-and-vista#details Allow Disable Auto Arrange in Windows 7+
Deleted User 101379
Profile Blog Joined August 2010
4849 Posts
August 16 2011 07:35 GMT
#849
On August 16 2011 08:17 Goldfish wrote:
Show nested quote +
On August 15 2011 18:59 kyophan wrote:
I think the answer is probably not necessary, but just to make sure. Is it recommended that I get a new main email?


Yep it's not really needed. Just make sure you password is unique to that email only and make sure it's long and contains a combo of numbers and letters.

Though I recommend using or creating an email solely for lesser important sites like forums and GOMTV for example. Like my previous post, so far this has happened to - GOMTV, Sony, Bioware, EA games, Mozilla (they accidentally uploaded passwords/account info somewhere based on firefox addon accounts >.<), etc.

Make sure to use unique passwords for everything.

Additionally recommendations (long post):
+ Show Spoiler +

You can create one email for talking with friends only (but said email is not registered to any site or forum). The reason for this is typically sometimes friends may actually do a reply all or whatever instead of using BCC causing all "their" friends or contacts to see your email. Basically a lot of people will know your email address and the more you have, the more chances someone may try to steal it (This is just to be extra safe or paranoid if you want as the chances of people trying to get into your email are probably low and the chances of them succeeding are much lower if you use a unique long password. This is just to be safe).

Create one main/important email all the important things like bank, paypal, battle.net, etc. You can additionally also add things like Steam account, or EA Games and/or Playstation Network or if you can just create another email for those.

Finally a third(or fourth if you're doing the latter of the above) email for stuff that isn't as important like GOMTV, forums, etc. That is if you lose that email, no major damage would be done and nothing too valuable would be lost.

Yeah I know it's overkill and typically one or two emails is enough but if you want to be extra safe, I'd suggest at least having one email dedicated to stuff that isn't as important like forums or the like. This will be your "throw away email" (if it gets hacked or lost, nothing too bad would happen since it's not your main email).

It's a good system and most email providers do not really care if you make multiple accounts and use them.

Finally of course use all different passwords for everything.

Also remember to log into every email you have at least once every two weeks or so.

Most email providers have a term where if your account is inactive for a certain amount of time (I think Yahoo for example is 2 or 3 months and gmail is maybe 9 months), it gets deleted due to inactivity. So log onto your account at least once every two weeks or so (make sure to do a quick memory scan with anti virus software[avast for example has it if you set up a memory scan] or super antispyware, malware bytes, windows defender, etc just in case before logging on all your email).


What about having a catch all address? :p

i have gomtv@..., teamliquid@..., blizzard@..., paypal@..., twitter@... and a lot more.

It's a nice way to trace where the spam comes from.
For example i recently received a mail that my ddo@... address that i only used for dungeons and dragons online for about half an hour was used to register a WoW account on SEA, so now i know that D&D Online has a leak and can't be trusted anymore.
nalgene
Profile Joined October 2010
Canada2153 Posts
August 16 2011 08:45 GMT
#850
It never hurts to have more emails ( one for each webpage/forum you visit ) with different accounts and passwords since you'll get less spam on your more important emails.
Year 2500 Greater Israel ( Bahrain, Cyprus, Egypt, Iran, Iraq, Jordan, Kuwait, Lebanon, Oman, Gaza Strip, West Bank, Qatar, Saudi Arabia, Syria, Turkey, United Arab Emirates, Yemen )
YokaY
Profile Blog Joined April 2010
United States108 Posts
August 16 2011 09:16 GMT
#851
My e-mail and facebook password were changed, the IP address that logged in was from south korea South Korea (219.248.84.141). They weren't the same PW as my gom account which is rather unsettling. I could have a virus? but it seems too suspicious to be a coincidence.
pluu
Profile Joined April 2011
Austria36 Posts
August 16 2011 12:53 GMT
#852
compromised accounts incoming!
giX
Profile Blog Joined June 2010
United States185 Posts
August 16 2011 13:01 GMT
#853
i was nervous for a bit then remembered I changed my paypal password..phew
twitter.com/gixDotA
Dwelf
Profile Joined September 2009
Netherlands365 Posts
August 16 2011 13:26 GMT
#854
Someone actually hacked into my neteller account and tried to change the password. Atleast Neteller is a secure bank and cut him off cause the intruder used a different IP. This shows again how your email account really can be a weak link in your personal defence.
k
MonDeW
Profile Joined June 2011
Denmark369 Posts
August 16 2011 14:08 GMT
#855
Damn, i got hacked, cant watch the matches today
Goldfish
Profile Blog Joined August 2010
2230 Posts
August 16 2011 22:43 GMT
#856
On August 16 2011 18:16 YokaY wrote:
My e-mail and facebook password were changed, the IP address that logged in was from south korea South Korea (219.248.84.141). They weren't the same PW as my gom account which is rather unsettling. I could have a virus? but it seems too suspicious to be a coincidence.


That's not good. Were the passwords short or long and how similar are they to the GOM account?

I suggest doing a virus scan.
https://connect.microsoft.com/WindowsServerFeedback/feedback/details/741495/biggest-explorer-annoyance-automatic-sorting-windows-7-server-2008-r2-and-vista#details Allow Disable Auto Arrange in Windows 7+
fant0m
Profile Joined May 2010
964 Posts
August 16 2011 22:55 GMT
#857
Actually, I wouldn't really fault Gom that much for storing it in plain text.

http://mobile.slashdot.org/story/11/07/24/1715232/Android-Password-Data-Stored-In-Plain-Text

Read the comments on this story. For the most part, if a hacker has access to your system, they have access to whatever method you use to decrypt, so it's kind of pointless.
Zinnwaldite
Profile Joined August 2010
Norway1567 Posts
August 16 2011 22:57 GMT
#858
it's strange,, i changed my password, but i can't log in.. so i made a new account,, and i cant log in with that one either,., *_*
We promise with a view to hope, but the reason to "accomplish" what we promised would be fear.
rasnj
Profile Joined May 2010
United States1959 Posts
August 16 2011 23:07 GMT
#859
On August 17 2011 07:55 fant0m wrote:
Actually, I wouldn't really fault Gom that much for storing it in plain text.

http://mobile.slashdot.org/story/11/07/24/1715232/Android-Password-Data-Stored-In-Plain-Text

Read the comments on this story. For the most part, if a hacker has access to your system, they have access to whatever method you use to decrypt, so it's kind of pointless.

Unless there is no way to decrypt it (or at least no way to decrypt it in 10000 years). Which is the right way to go about password protection.

Store an encrypted password E. When user enters password P you perform encryption on P and compares the result with E. This is the accepted method for password protection.

This is done either by having several passwords map to the same encrypted string (ala md5), or have a type of encryption where decryption is a very hard computational problem that would take millions of years with millions of supercomputers. Or a combination.
Predateur
Profile Joined August 2010
Canada79 Posts
August 17 2011 01:46 GMT
#860
I feel betrayed by GOM.TV

This is a huge business, it's unacceptable to have plain-text password on their server like this.
This is an example where a company neglect technology and they are going to loose a lot of customer because of this. I won't make any more purchase on their website. I'll just watch match 1 of each serie and not risk my info.
No_Roo
Profile Joined February 2010
United States905 Posts
August 17 2011 01:54 GMT
#861
Indeed... very sloppy by gom to store stuff like this as plain text :|
(US) NoRoo.fighting
tGFuRy
Profile Joined September 2010
United States537 Posts
August 17 2011 01:56 GMT
#862
I'm so fucking glad I never bought one of those passes now lol.
Always a Gamer
zoombini
Profile Joined June 2010
United States67 Posts
August 17 2011 02:03 GMT
#863
On August 17 2011 07:55 fant0m wrote:
Actually, I wouldn't really fault Gom that much for storing it in plain text.

http://mobile.slashdot.org/story/11/07/24/1715232/Android-Password-Data-Stored-In-Plain-Text

Read the comments on this story. For the most part, if a hacker has access to your system, they have access to whatever method you use to decrypt, so it's kind of pointless.


Wouldn't fault GOM for storing passwords in plain text? Are you kidding me?

Passwords are--or always should be hashed whenever a new user register. The password should NEVER be stored, and only resulting "digest" of the cryptographic hash function is stored. When a user authenticates, their input should be passed through the same hash function and compared to the hashed entry in the database.
Rebel_
Profile Joined December 2010
Canada94 Posts
Last Edited: 2011-08-17 02:10:50
August 17 2011 02:10 GMT
#864
GOM just pulled a Sony...........
“Give the guy a gun he's superman, give him two and he’s God.” - Hard Boiled
Cain0
Profile Blog Joined April 2010
United Kingdom608 Posts
August 17 2011 02:17 GMT
#865
For fucks sake GOM. What the fuck are you doing?
anemoneya
Profile Joined October 2010
58 Posts
August 17 2011 04:47 GMT
#866
plain txt? WTF?????????? WTF GOMTV???
Kiwifruit
Profile Joined August 2011
New Zealand130 Posts
August 20 2011 12:17 GMT
#867
On August 13 2011 03:29 zeru wrote:
On August 13 2011 03:28 sermokala wrote:
How is my teamliquid information stored?
the TL wizard keeps a magic barrier up 24/7.


Yeah, I'd be interested to know too.
"You take the good things from every different discipline, use what works, and you throw the rest away" - Bruce Lee, Atheist.
neoflex
Profile Joined December 2010
France6 Posts
August 20 2011 13:51 GMT
#868
I forgot that I used the same password for my twitter account and it was hacked two days ago. Thanks a lot Gom for storing plain text passwords... great job
and no compensation, really?
Jiddra
Profile Joined October 2010
Sweden2685 Posts
August 26 2011 11:16 GMT
#869
I didn't use the same password, but a part of it, on my battle.net account. Tonight my bnet account got taken over. Seems like they are not working just on matching stuff automaticly, but are trying to figure out stuff themself.

So be aware, even if you changed all your passwords, it might still happen. It took them until now to get to me.

PS. No, I haven't had any strange things happen to me outside of the gom thing, and I have never been hacked before this.

I am not young enough to know everything.
Normal
Please log in or register to reply.
Live Events Refresh
Online Event
18:00
Coaches Corner 2v2
RotterdaM427
Liquipedia
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
RotterdaM 427
TKL 400
Clem_sc2 271
IndyStarCraft 167
SteadfastSC 120
BRAT_OK 62
Railgan 53
Vindicta 24
MindelVK 10
StarCraft: Brood War
Britney 21090
Horang2 1249
GuemChi 514
Dewaltoss 97
yabsab 36
zelot 32
scan(afreeca) 17
Dota 2
Gorgc7453
qojqva2380
League of Legends
Reynor73
Counter-Strike
fl0m1106
pashabiceps575
Heroes of the Storm
Khaldor593
Other Games
tarik_tv689
B2W.Neo285
Beastyqt181
Organizations
Dota 2
PGL Dota 2 - Main Stream13234
Other Games
EGCTV1125
gamesdonequick352
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 19 non-featured ]
StarCraft 2
• davetesta15
• Reevou 7
• Migwel
• AfreecaTV YouTube
• sooper7s
• intothetv
• Kozan
• IndyKCrew
• LaughNgamezSOOP
StarCraft: Brood War
• blackmanpl 31
• HerbMon 16
• FirePhoenix15
• STPLYoutube
• ZZZeroYoutube
• BSLYoutube
Dota 2
• Ler82
Other Games
• imaqtpie961
• WagamamaTV448
• Shiphtur226
Upcoming Events
BSL 21
1h 43m
JDConan vs Semih
Dragon vs Dienmax
Tech vs NewOcean
TerrOr vs Artosis
IPSL
1h 43m
Dewalt vs WolFix
eOnzErG vs Bonyth
Replay Cast
4h 43m
Wardi Open
17h 43m
Monday Night Weeklies
22h 43m
Replay Cast
1d 4h
WardiTV Korean Royale
1d 17h
BSL: GosuLeague
2 days
The PondCast
2 days
Replay Cast
3 days
[ Show More ]
RSL Revival
3 days
BSL: GosuLeague
4 days
RSL Revival
4 days
WardiTV Korean Royale
4 days
RSL Revival
5 days
WardiTV Korean Royale
5 days
IPSL
5 days
Julia vs Artosis
JDConan vs DragOn
RSL Revival
6 days
Wardi Open
6 days
Liquipedia Results

Completed

Proleague 2025-11-14
Stellar Fest: Constellation Cup
Eternal Conflict S1

Ongoing

C-Race Season 1
IPSL Winter 2025-26
KCM Race Survival 2025 Season 4
SOOP Univ League 2025
YSL S2
BSL Season 21
CSCL: Masked Kings S3
SLON Tour Season 2
RSL Revival: Season 3
META Madness #9
BLAST Rivals Fall 2025
IEM Chengdu 2025
PGL Masters Bucharest 2025
Thunderpick World Champ.
CS Asia Championships 2025
ESL Pro League S22
StarSeries Fall 2025
FISSURE Playground #2
BLAST Open Fall 2025

Upcoming

BSL 21 Non-Korean Championship
Acropolis #4
IPSL Spring 2026
HSC XXVIII
RSL Offline Finals
WardiTV 2025
IEM Kraków 2026
BLAST Bounty Winter 2026
BLAST Bounty Winter 2026: Closed Qualifier
eXTREMESLAND 2025
ESL Impact League Season 8
SL Budapest Major 2025
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2025 TLnet. All Rights Reserved.