So BundleStars has taken a nice initiative and asked their users to reset their passwords after having been alerted to the fact that some website (not theirs!) with a lot of userbase crossover has likely had their database comprised.

Users that have been using the same login/email and password across multiple sites take note: if any one of the sites has their databases compromised, it is very easy for people with access to that list of login/passwords to then try those logins at related sites and of course, the prize target being financial/banking sites and sites rich with personal information.

A lot of bundlesites look like fly-by-night operations with questionable security practices, and even the biggest companies like Sony, Target, Home Depot, amongst many others have had database breaches in which logins/passwords/personal info has been accessed. No database is 100% safe, so fight this inherent vulnerability with logic and DON'T USE THE SAME PASSWORDS ON YOUR IMPORTANT ACCOUNTS

If you are not already doing so, I highly recommend the use of password management software to make long (20+ characters), random, unique passwords for every single one of your website accounts. If you need to use a password that you can memorize for quick access to some service where use of password management software is either too cumbersome or impractical, then it should be a long, unique password generated by stringing together odd word combinations or somesuch.

Please be vigilant and please be careful with your accounts and computer safety!

8 years ago*

Comment has been collapsed.

Do you use unique passwords for all your sites?

View Results
Yes, always or almost always
Only for sites I really care about
No, I am lazy and I like letting random people access my things
Deleted

This comment was deleted 4 years ago.

8 years ago
Permalink

Comment has been collapsed.

Half-Life 3 confirmed.

P.S: Sorry, had to do it sinceI just just finished the series, AGAIN!

8 years ago
Permalink

Comment has been collapsed.

No, you're wrong. This article clearly says you should use the same password across sites, especially as a business!

8) Try to use one password for everything
It's pretty easy to devise a password eight figures long or more that includes one upper case letter, a number and a symbol. Dream one up and try to use it across every business account

8 years ago*
Permalink

Comment has been collapsed.

digital life, hella uncluttered

i feel liberated

thanks for the link

8 years ago
Permalink

Comment has been collapsed.

what a moron

8 years ago
Permalink

Comment has been collapsed.

worst advice ever xD

8 years ago
Permalink

Comment has been collapsed.

With two factors authentication not a single soul can hack. Unfortunately not all services/portals have it.

I'd suggest password management as well. So far I've been using Last Pass and no complaint. I attach SMS auth for my last pass account, so it's only accessible if the hacker somehow gets a hold of my phone physically.

8 years ago
Permalink

Comment has been collapsed.

If you have a smartphone, I'd advise to switch to Google/MicroSoft authenticator. Faster than the SMS and doesn't leave data stored on your phone to delete when you are bored looking at it.

8 years ago
Permalink

Comment has been collapsed.

Except for the souls that have access (physical or digital) to your phone ;)

8 years ago
Permalink

Comment has been collapsed.

Well I can't do anything against that obviously. xD

8 years ago
Permalink

Comment has been collapsed.

I strongly suggest people use lastpass,
been using this for years now and its the best program choice I've ever had.
Theres also browser plugins to help you manage your stuff.

lastpass.com
lastpass firefox addon

8 years ago
Permalink

Comment has been collapsed.

I'm a long time user and love their program. Makes it so easy to generate unique and longer passwords. Need a password? Select the length, number of digits, special characters, etc. and it generates and then saves the password. I even pay the extra $12/year so I can use the app on my phone.

Many, many years ago when I first entered all of my passwords into the program and ran the security check, I was actually surprised at how many duplicates and weak some of them were. I knew better, but it's so easy to use the same password, especially for those sites that aren't important, like community sites.

8 years ago
Permalink

Comment has been collapsed.

so what happens if someone gets your lastpass password?

8 years ago
Permalink

Comment has been collapsed.

they cash out.

8 years ago
Permalink

Comment has been collapsed.

reminds me of a co-worker, who had a word document that we nicknamed the "Fred Identity Theft Manual". It contained his date of birth, bank number, login and password grouped together for every bank, credit card numbers with expiration date, security code and billing address, you name it.
It was the only item on the desktop of his computer.

Best part: the password for his computer was written in big letters on the whiteboard behind his desk!

8 years ago
Permalink

Comment has been collapsed.

That sounds like a very "special" co-worker.

8 years ago
Permalink

Comment has been collapsed.

very special. He brought in a quarter billion dollars of business his first year.

8 years ago
Permalink

Comment has been collapsed.

I feel compelled to ask:Doing what?

8 years ago
Permalink

Comment has been collapsed.

Actually, I'm wrong. it was $350 million.

$250 million from Longevity Hedging
$100 million for creating a backstop for it.

8 years ago
Permalink

Comment has been collapsed.

It uses two factor authentication so the password alone won't do them much good.
https://lastpass.com/multifactor-authentication/

8 years ago
Permalink

Comment has been collapsed.

A good technique is password phrases. For instance, if my password was: Password3

I could instead alter it for bundlestars or google to be: Password3_Bundlestars or Password3_google

edit: password manager is best though.

8 years ago
Permalink

Comment has been collapsed.

just so you know, automatic password crackers and hackers know people do this and its pretty much the second option they use.

8 years ago
Permalink

Comment has been collapsed.

True true. I honestly hadn't though of that. derp.

Still, it will take that much longer to crack your initial password, which will render your other passwords safer. Dictionary attacks usually only scope out the easiest targets.

8 years ago
Permalink

Comment has been collapsed.

DON'T USE THE SAME PASSWORDS ON YOUR IMPORTANT ACCOUNTS

these people make me sad (╯︵╰,)

8 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 5 years ago.

8 years ago
Permalink

Comment has been collapsed.

I use LastPass but I had a problem with their Firefox addon: it made my Firefox terribly slow - after uninstalling it, my Firefox came back to its true speed. So, I just use their website for managing my password and use their password generator

Firefox's Save Logins is also excellent and minimalist addon and consumes very minimal resources. But remember, don't use it if you share your PC...

I think it's easy for Bundle Stars to resolve the problem - use IP check like implemented by those Indie Gala and Humble Bundle. And of course that would sacrifice ease of login if your IP address keep resetting.

8 years ago
Permalink

Comment has been collapsed.

BUMP for exposure. There are some good recommendations for password managers and other computer security thoughts in this thread. 22% of the current pollsters who voted "lazy", please consider at least exploring the use of a password manager because it will only be a matter of time before you learn this the hard way.

8 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 8 years ago.

8 years ago
Permalink

Comment has been collapsed.

No. Other site was probably compromised and the attackers were using the emails and passwords obtained somewhere else trying to access BundleStars accounts.

8 years ago
Permalink

Comment has been collapsed.

Wait, I totally misread the opening post. Ignore me.

8 years ago
Permalink

Comment has been collapsed.

EDIT: I saw your edit but will leave this post in case others are looking for some clarification

I started this because of the BundleStars warning -- I highly respect them for their efforts to combat poor security habits of their users. It's not really a BundleStars problem and they didn't have to publicize in this way, but it does help get people to practice better security habits. I also want people to realize this isn't just a BundleStars issue -- if you are using the same password issue it will affect all the sites you use the same login at.

I don't know which gaming site(s) were compromised, and I don't think there is any way of knowing. Likely many smaller bundle/store sites and gaming communities or gaming news sites are fairly susceptible to attack vectors and easy database mining, and many probably don't even have the tools or experience to know if their database has been compromised. Whether they are worth the effort to hack is another story, but the more people use unique passwords the less rewarding the effort to hack becomes.

8 years ago
Permalink

Comment has been collapsed.

Yeah it's interesting that a multi-million user entity like Steam tried to hush their breach up and a tiny little bundle site sent everyone an email. Ah, business ethics.

8 years ago
Permalink

Comment has been collapsed.

Christ I really wish storing passwords in plaintext were a felony.

8 years ago*
Permalink

Comment has been collapsed.

This doesn't necessarily mean the compromised site stored passwords in plaintext. If you root a server rather than just find a SQL injection, you can just add a few lines to login.php or whatever to collect cleartext passwords surreptitiously until the breach is uncovered.

8 years ago
Permalink

Comment has been collapsed.

True, but a significant part of the problem still probably stems from storing plaintext passwords which is absolutely inexcusable. Anyone can be a victim of a 0day attack, but storing passwords safely has such a completely effective, standard and widespread solution that anyone not using it really deserves to have their ass thrown in prison for putting others at risk.
<\rant>

8 years ago*
Permalink

Comment has been collapsed.

For sure. I couldn't be happier if more sites started using bcrypt or scrypt for password hashes.

Non-crypto hashes still seem to he the norm though and, salted or not, they are still very weak.

8 years ago
Permalink

Comment has been collapsed.

Not sure what sites had the weak security and started the leak, but I know that RockStar social club was almost certainly one site they either used the passwords on or got them from.

8 years ago
Permalink

Comment has been collapsed.

For those who don't want to use password management software, acrostic phrases tend to make easy passwords. For example:

This is my 3rd password for google's email - Tim3pfge

But I hate having to take money out of the bank - BIhhtmootb

(bonus points if you're multi-lingual)

8 years ago
Permalink

Comment has been collapsed.

I use Keepass myself. Great manager! What it lacks in the convenience of a web browser plugin it makes up by being able to store your encrypted database on your cloud storage of choice (Google Drive, Dropbox, MS OneDrive) so that you can access it on any computer or phone where you can log into that service.

http://keepass.info/

8 years ago
Permalink

Comment has been collapsed.

8 years ago
Permalink

Comment has been collapsed.

Sign in through Steam to add a comment.