I just received an email saying my email was changed to con02@nm.ru. Did this happen to anyone else ? Was their database somehow compromised or was my password compromised? HB just emailed me back that they are experiencing a high amount of emails sent to them and it might take a few days to email me back -_-.

Well i'm starting to use LastPass from today :D. Thank you for the help, after i tweeted them, they emailed me and asked me for some info. I'm now waiting for response.

Ok i just got back my account and the 4 games that were unredeemed are still there :D. Russians probably hijack HB accounts to download the DRM free versions for pirating... or at least that's my guess. Anyway now i'm using a 100 upper and lower case letters with numbers, so i doubt that will happen again :D.

11 years ago*

Comment has been collapsed.

no clue about that but nothing out of the ordinary here

11 years ago
Permalink

Comment has been collapsed.

your pass probably got stolen/phished/keylogged :> If there was a massive breach we'd be hearing about it already :>

11 years ago
Permalink

Comment has been collapsed.

true :>

11 years ago
Permalink

Comment has been collapsed.

Do you use twitter? If so contact their support account with your problem and the case # you'll find at the end of the auto-reply email you got from them (it's near the end of the email). They are usually faster at replying over there - due to the small team they are and tons of emails they are getting.

They will change the account back and force a password reset for you.

As far as I know their database has not been compromised, but they could make a few changes so that it would not be that "easy" to change the email-adress if you get access to someone elses HB-password.

And as usual. if you use the same password on other sites then go change them asap!

11 years ago
Permalink

Comment has been collapsed.

Thank you i just twitted them with my problem. Their email change system is far too easy... they dont even want confirmation from the email that is being changed -_- ...

11 years ago
Permalink

Comment has been collapsed.

Try not using shit password idek

11 years ago
Permalink

Comment has been collapsed.

Not helpful at all... even if you use 100 digit password if you get key logged it doesn't matter... As far as i know i wasn't key logged and my password isn't something you can just guess (it has 6 letters 5 numbers and lower and upper case letters). I would guess the password was stolen from another site/forum.

11 years ago
Permalink

Comment has been collapsed.

Well then, don't use the same password. That's asking for trouble.

11 years ago
Permalink

Comment has been collapsed.

Yeah i use that pass for sites i don't care if i get my account hijacked and when i was creating my HB account i didn't know if i would ever buy another bundle... and well i never changed it because i'm an idiot :D.

11 years ago
Permalink

Comment has been collapsed.

I know, sorry I was a dick.

11 years ago
Permalink

Comment has been collapsed.

DO NOT USE THE SAME PASSWORD ON MULTIPLE WEBSITES

Look into this

11 years ago
Permalink

Comment has been collapsed.

I prefer Lastpass myself. Been using it for a long time and no issues.

11 years ago
Permalink

Comment has been collapsed.

The main difference between the two is that KeePass stores everything locally where as LastPass sends encrypted passwords to store on their server.

I trust myself more than LastPass.

11 years ago
Permalink

Comment has been collapsed.

And when you need it while away from PC? Lastpass on my android saves me a lot of trouble.

11 years ago
Permalink

Comment has been collapsed.

Then I use the android version of KeePass.

11 years ago
Permalink

Comment has been collapsed.

If your data is stored locally how do you access your stuff from an android?

11 years ago
Permalink

Comment has been collapsed.

I have a backup of my Keepass file stored online, so I can access it everywhere (at least until the point where I made the backup).

Maybe Peroxide does the same.

11 years ago
Permalink

Comment has been collapsed.

It's stored locally so I have the ability to access it? I don't change my passwords daily nor am I signing up to new sites so a simple copy of the database suffices.

Alternatively, you could do as Dopefish states and store it in a Dropbox or something similar. I personally don't as like I said, that's one of the reasons I don't use LastPass. I don't want my encrypted passwords on someone else's server!

11 years ago
Permalink

Comment has been collapsed.

Hell, do you think ur friend pc is clear from spyware/keylogger?

11 years ago
Permalink

Comment has been collapsed.

I just use Notepad, also with no issues. :P

11 years ago
Permalink

Comment has been collapsed.

I use paper or brain HDD(tho things are getting lost there sometimes)

11 years ago
Permalink

Comment has been collapsed.

Unfortunately, remembering 50+ different 20+ character passwords that use letters, numbers and punctuation is a lot easier said than done!

Not that everything needs to be 20+ characters, but when you have the ability to, why not?

11 years ago
Permalink

Comment has been collapsed.

I used to memorize all my passwords, but that was when they were mostly the same password (or variations thereof) and all were 10 characters or less. As for paper, paper is the way of the past.

11 years ago
Permalink

Comment has been collapsed.

I just tell all my passwords to my dog, he will remember them. They are encoded in bark sounds. No one will ever break that code, ha!

10 years ago
Permalink

Comment has been collapsed.

Lol best way dont use same passwords on websites

11 years ago
Permalink

Comment has been collapsed.

you forgot to put the letters ij in the word as it's "hijacked", not "hacked".

11 years ago
Permalink

Comment has been collapsed.

dont blame them, for not knowing the difference.

11 years ago
Permalink

Comment has been collapsed.

Yeah sorry i was searching for the word but couldn't think of it (English is not my first language). Changed it, thanks.

11 years ago
Permalink

Comment has been collapsed.

no prob, glad i could give you a tip ;)

11 years ago
Permalink

Comment has been collapsed.

That sucks. There are a couple of possibilites: 1. you have a keylogger, therefore, somebody got your data through it. 2. You have a simple password and somebody managed to guess it with checker.

11 years ago
Permalink

Comment has been collapsed.

Nah it was my fault for using an old password i have used in forums. And i doubt i have a key logger i use Malwarebytes and from what i know it does protect from them.

11 years ago
Permalink

Comment has been collapsed.

For what it's worth, no one anti-virus or anti-malware program protects from everything.

11 years ago
Permalink

Comment has been collapsed.

After retrieving my account i asked them if they have ever thought of putting at least email confirmation on email changes and password changes. This is what they responded with:

"Hey there,
We are already working on more account security solutions so keep an eye out in the future.

AJ
Support Ninja
Humble Bundle"

This is nice to hear :D.

11 years ago
Permalink

Comment has been collapsed.

I'm glad everything worked out and that you got your account back!

And yes, they are working on a few new things (security and other things) that will see it's light "soonish".

11 years ago
Permalink

Comment has been collapsed.

good to hear.

11 years ago
Permalink

Comment has been collapsed.

Woo!

Now get KeePass or LastPass and never let this happen again! (unless it was self inflicted)

11 years ago
Permalink

Comment has been collapsed.

Dont log on russian pr0n sites with the same email/pass combo.

11 years ago
Permalink

Comment has been collapsed.

Hey man, how long did it take you to get your account back? I'm in the same shit, someone changed my email, now idea how o-o

10 years ago
Permalink

Comment has been collapsed.

" Russians probably hijack HB accounts to download the DRM free versions for pirating"
They're all on tpb or similar sites, what would the point in the extra step be?

10 years ago
Permalink

Comment has been collapsed.

Hahahah so you guys remember how I was being a dick here 2+ months ago? Hahahahah yeah now the same thing happened to me, serves me well lol :(((

10 years ago
Permalink

Comment has been collapsed.

10 years ago
Permalink

Comment has been collapsed.

10 years ago
Permalink

Comment has been collapsed.

Closed 10 years ago by MiFOE.