d2jsp
Log InRegister
d2jsp Forums > Other Games > Browser Games > Elethor > Alert: Passwords May Be Compromised
Add Reply New Trade New Price Check New Topic New Poll
Member
Posts: 92
Joined: Apr 10 2016
Gold: 575.00
Aug 8 2021 11:37pm
Edit: announcements from Dev:

I will be performing a rollback of roughly 1 day but will be taking Elethor down for a short while to determine what is going on and how the problems have come up.

I'll keep everyone updated!

All passwords are salted and hashed on my servers and it doesn't appear that any servers have been compromised. They are all highly secured with several layers of 2FA and nothing has been triggered.

There are no plain text passwords stored anywhere.

However to be safe, if you reuse passwords anywhere, I would highly recommend changing them.

This post was edited by AcheronGloom on Aug 9 2021 09:10am
Member
Posts: 1,059
Joined: Aug 21 2018
Gold: 1,470.70
Aug 9 2021 03:53am
pro tip: change your password but use something new and random, on the off chance they can still scrape/get the new password, I suggest using a password store such as LastPass or similar.
Member
Posts: 20,253
Joined: Apr 30 2008
Gold: 5,267.97
Aug 9 2021 05:50am
Another protip: don't use the same password on multiple different websites.
Member
Posts: 13,004
Joined: Jan 31 2009
Gold: 7,330.00
Aug 9 2021 05:53am
Quote (Leevee @ 9 Aug 2021 13:50)
Another protip: don't use the same password on multiple different websites.


I've used a unique password for elethor (20 random letters/symbols etc) so this is way more likely to be a sessionID Hijack than a password issue

(I lost over 2b gold)

This post was edited by Shadirra on Aug 9 2021 05:54am
Member
Posts: 20,253
Joined: Apr 30 2008
Gold: 5,267.97
Aug 9 2021 05:55am
Quote (Shadirra @ Aug 9 2021 01:53pm)
I've used a unique password for elethor (20 random letters/symbols etc) so this is way more likely to be a sessionID Hijack than a password issue

(I lost over 2b gold)


My protip is more about the possibility of actual passwords being stolen from the DB (like OP mentioned). If that happens and you use the same password everywhere, all your accounts everywhere will be at risk.
Member
Posts: 13,004
Joined: Jan 31 2009
Gold: 7,330.00
Aug 9 2021 05:56am
Quote (Leevee @ 9 Aug 2021 13:55)
My protip is more about the possibility of actual passwords being stolen from the DB (like OP mentioned). If that happens and you use the same password everywhere, all your accounts everywhere will be at risk.


totally agree , just don't think that this hack was people with qwertyuiop passwords :P
Member
Posts: 16,846
Joined: Sep 13 2018
Gold: 15,325.65
Aug 9 2021 06:56am
so youre telling me, that i shouldnt be using PassWordJSP or PassWordEle or PassWordQues ?
Member
Posts: 668
Joined: Aug 10 2007
Gold: 142,193.00
Aug 9 2021 03:33pm
Quote (Light_Prince @ Aug 9 2021 08:56am)
so youre telling me, that i shouldnt be using PassWordJSP or PassWordEle or PassWordQues ?


nah you have some letters capitalized.. pretty stong passwords
Go Back To Elethor Topic List
Add Reply New Trade New Price Check New Topic New Poll