Data Security Update 1/4/2019

Announcements made here about the game and the company.

Re: Data Security Update 1/4/2019

Postby ChubbyMooshroom9 » Sat Jan 05, 2019 9:00 am

I’d probably do some sort of in-game verification, like screenshots or DMs in game to a mod
Image

Hall of Fame
Spoiler:
Shino Thomson
Image
Federico Decandia
Image
Clayton (Briah)
Image
Gebura Briah
User avatar
ChubbyMooshroom9
FM Awards: Town
FM Awards: Town
 
Posts: 1376
Joined: Wed Jun 10, 2015 2:31 pm
Location: Ethiopia

Re: Data Security Update 1/4/2019

Postby Alicitzen » Sat Jan 05, 2019 12:17 pm

Malfoydragon wrote:Has the malware, the hackers, and all traces of the hackers been removed?

you'd hope so but theres always odds theres stuff missed
Discord: Alicitzen#1312
Image
Image
Image
Image
Image
Image
Image
Image
Image
Image
User avatar
Alicitzen
Valentines 2017
Valentines 2017
 
Posts: 7991
Joined: Mon Mar 10, 2014 10:56 am
Location: Chaldea

Re: Data Security Update 1/4/2019

Postby YFYDB » Sat Jan 05, 2019 12:28 pm

Before that topic there was so much spam and now there are few posts to read, great. Less stuff to read.
I hope admins will be done with that quickly, so we will be able to solve next problem i mean kicking out the moderators from Discord, who are biased.
But now, admins check everything 55 times and change all your passwords.

Don't use password Admin1234 and nothing simple like that, really xd
My avatar is a random picture found in the internet.
User avatar
YFYDB
Witch
Witch
 
Posts: 41
Joined: Thu Aug 03, 2017 9:08 am

Re: Data Security Update 1/4/2019

Postby Jerme » Sat Jan 05, 2019 3:05 pm

@YFYDB: Apart from the Trial System Discord server there is no official ToS Discord, which means those are community coordinated and not controlled/hosted/made by BMG or Staff.
Disclaimer: I try to abide by the game's softfilter and use the appropriate replacements, when I am using the forums. Those will be set in brackets. Example: [tarnation]
Visit my role suggestions and give me feedback: http://www.blankmediagames.com/phpbb/viewtopic.php?f=27&t=28949

Visit the Testing Grounds
Occupation: A developers pain and joy (QA-fox), currently "hired" by Ralozey
User avatar
Jerme
Global Moderator
Global Moderator
 
Posts: 28197
Joined: Thu Apr 30, 2015 2:09 pm

Re: Data Security Update 1/4/2019

Postby EnigmaMRZ » Sat Jan 05, 2019 4:13 pm

How do I request to see what info BMG has on me?
Some men aren't looking for anything logical, like money. They cant be bought, bullied, reasoned or negotiated with. Some men just want to watch the world burn.

417 wins, 273 loses,11 draws

SKINS: War torn Santa, Prince, Beelzebub, Tamer of Frost, Uriel, Van Helsing, Edward Teach , Lycanthorpe, Dexter, Jester


Notable achievements: Town of Salem expert and Lucky Paranoia .
User avatar
EnigmaMRZ
Jester
Jester
 
Posts: 11
Joined: Thu Dec 31, 2015 9:54 am
Location: London

Re: Data Security Update 1/4/2019

Postby VoidRuler » Sat Jan 05, 2019 5:45 pm

Malfoydragon wrote:Has the malware, the hackers, and all traces of the hackers been removed?

There was malware? I'm really scared now, does this mean like there was malware on the actual site or forums? I thought all that happened was the data breach and DDOS.
Edit: I asked someone about this and they explained the malware was what got the database. I didn't understand and thought you meant like malware could've been downloaded from the site onto peoples' computers. Ignore this reply.
User avatar
VoidRuler
Mafioso
Mafioso
 
Posts: 1467
Joined: Wed Jul 23, 2014 5:59 pm

Re: Data Security Update 1/4/2019

Postby James2 » Sat Jan 05, 2019 11:40 pm

Achilles wrote:We have also added 2FA to admin accounts on PHPBB as a temporary measure and will be looking to migrate to a newer forum technology as a long term solution.


I once ran a forum that had like five people on it, and it was prophpbb so I didn't even have access to the password database.

I still had the decency to use a strong and unique password for that account.

I also regularly checked the admin logs.
James2
Godfather
Godfather
 
Posts: 1555
Joined: Tue Jun 16, 2015 9:53 am

Re: Data Security Update 1/4/2019

Postby PootatoGamer » Sun Jan 06, 2019 6:43 am

So... I checked the 'how to change my password' topic, and it says if I change my forum password then automatically changes my game password too. But, my forum and game password already different, it never was the same. So what now?
User avatar
PootatoGamer
Witch
Witch
 
Posts: 47
Joined: Fri Oct 14, 2016 12:56 pm

Re: Data Security Update 1/4/2019

Postby Flavorable » Sun Jan 06, 2019 6:45 am

Kasaya wrote:So... I checked the 'how to change my password' topic, and it says if I change my forum password then automatically changes my game password too. But, my forum and game password already different, it never was the same. So what now?


Log in to the forum with your game account and thn change your password.
No reply to your support ticket after 15 business days? PM me with your ticket number.

You may PM me for clarifications on appeal verdicts, but keep in mind the verdict will not change.

Do you have 151+ games played and want to help rid the community of toxic players and gamethrowers? Join the Trial System today: https://www.blankmediagames.com/Trial/#start

Also, check out the Trial System Discord Server: https://discord.gg/K5SnyJS
User avatar
Flavorable
Global Moderator
Global Moderator
 
Posts: 9279
Joined: Thu Apr 28, 2016 3:24 am
Location: Netherlands

Re: Data Security Update 1/4/2019

Postby PootatoGamer » Sun Jan 06, 2019 7:32 am

Flavorable wrote:
Kasaya wrote:So... I checked the 'how to change my password' topic, and it says if I change my forum password then automatically changes my game password too. But, my forum and game password already different, it never was the same. So what now?


Log in to the forum with your game account and thn change your password.

This was my game account, but I changed my in-game name and it didn't changed here.
User avatar
PootatoGamer
Witch
Witch
 
Posts: 47
Joined: Fri Oct 14, 2016 12:56 pm

Re: Data Security Update 1/4/2019

Postby Alicitzen » Sun Jan 06, 2019 8:04 am

Kasaya wrote:
Flavorable wrote:
Kasaya wrote:So... I checked the 'how to change my password' topic, and it says if I change my forum password then automatically changes my game password too. But, my forum and game password already different, it never was the same. So what now?


Log in to the forum with your game account and thn change your password.

This was my game account, but I changed my in-game name and it didn't changed here.

yah you need to report that so it can be changed to match, i had that issue for a bit when i username swapped
Discord: Alicitzen#1312
Image
Image
Image
Image
Image
Image
Image
Image
Image
Image
User avatar
Alicitzen
Valentines 2017
Valentines 2017
 
Posts: 7991
Joined: Mon Mar 10, 2014 10:56 am
Location: Chaldea

Re: Data Security Update 1/4/2019

Postby nexttrain6 » Sun Jan 06, 2019 10:00 pm

I made an account for my friend and forgot the email is there any way I can find out what email the account is using? i know both the email and password but i just need to know the email so i can validate it before the switch
nexttrain6
Executioner
Executioner
 
Posts: 22
Joined: Sun Feb 15, 2015 10:10 pm

Re: Data Security Update 1/4/2019

Postby Ericmalveni » Mon Jan 07, 2019 12:12 pm

How am I to change my Town of Salem password?
Ericmalveni
Witch
Witch
 
Posts: 51
Joined: Thu May 01, 2014 10:12 am

Re: Data Security Update 1/4/2019

Postby Jerme » Mon Jan 07, 2019 1:04 pm

Ericmalveni wrote:How am I to change my Town of Salem password?

ucp.php?i=profile&mode=reg_details
Disclaimer: I try to abide by the game's softfilter and use the appropriate replacements, when I am using the forums. Those will be set in brackets. Example: [tarnation]
Visit my role suggestions and give me feedback: http://www.blankmediagames.com/phpbb/viewtopic.php?f=27&t=28949

Visit the Testing Grounds
Occupation: A developers pain and joy (QA-fox), currently "hired" by Ralozey
User avatar
Jerme
Global Moderator
Global Moderator
 
Posts: 28197
Joined: Thu Apr 30, 2015 2:09 pm

Re: Data Security Update 1/4/2019

Postby Giumuscul » Mon Jan 07, 2019 7:49 pm

Yo can anyone answer me why I should change all my passwords for non town of salem things, like why? and if its just to make sure, how possible is it for my other accounts to get hacked?
Giumuscul
Newbie
Newbie
 
Posts: 2
Joined: Fri Nov 03, 2017 9:20 pm

Re: Data Security Update 1/4/2019

Postby Giumuscul » Mon Jan 07, 2019 8:14 pm

Hello, I really need help. I had my town of Salem password saved and forgot which one it was and now due to the data breach i have a new one. although because I forgot my original password I don't know which other passwords to change for other accounts. Please help
Giumuscul
Newbie
Newbie
 
Posts: 2
Joined: Fri Nov 03, 2017 9:20 pm

Re: Data Security Update 1/4/2019

Postby orangeandblack5 » Mon Jan 07, 2019 10:37 pm

If you want to be safe, change all of them - there's always the chance that some bot somewhere will try your username/e-mail and password somewhere you don't want them accessing. Granted, data breaches like this tend to happen more often than you'd like (I've had accounts on each of my seven e-mail accounts breached multiple times over the past few years) so changing everything up is probably for the best.
Image
Spoiler:
SwampRabbit wrote:your idea is that no town should ever be able to confirm themselves as town.

that is the dumbest idea I think I have heard.

ElderSivart wrote:I'm confused as to why BMG made a UI for Pirate and not Hypnotist.

Sarah Thorpe wrote:Role Ideas is great for masochists.
User avatar
orangeandblack5
Halloween 2017 Winner
Halloween 2017 Winner
 
Posts: 5767
Joined: Tue Mar 17, 2015 9:24 pm
Location: University of Michigan

Re: Data Security Update 1/4/2019

Postby Malfoydragon » Tue Jan 08, 2019 11:44 pm

Malfoydragon wrote:Has the malware, the hackers, and all traces of the hackers been removed?


I'd like a clear answer from staff on this please, because I changed my password to a temporary password, if everything is removed I can create a permanent password for this account.
Malfoydragon
Witch
Witch
 
Posts: 51
Joined: Sun Sep 02, 2018 3:11 am

Re: Data Security Update 1/4/2019

Postby orangeandblack5 » Wed Jan 09, 2019 7:35 am

They may force reset all passwords, to be safe - so I wouldn't do that just yet.
Image
Spoiler:
SwampRabbit wrote:your idea is that no town should ever be able to confirm themselves as town.

that is the dumbest idea I think I have heard.

ElderSivart wrote:I'm confused as to why BMG made a UI for Pirate and not Hypnotist.

Sarah Thorpe wrote:Role Ideas is great for masochists.
User avatar
orangeandblack5
Halloween 2017 Winner
Halloween 2017 Winner
 
Posts: 5767
Joined: Tue Mar 17, 2015 9:24 pm
Location: University of Michigan

Re: Data Security Update 1/4/2019

Postby shapesifter13 » Wed Jan 09, 2019 2:26 pm

Malfoydragon wrote:
Malfoydragon wrote:Has the malware, the hackers, and all traces of the hackers been removed?


I'd like a clear answer from staff on this please, because I changed my password to a temporary password, if everything is removed I can create a permanent password for this account.


We believe we have fixed all the holes, but we are having a security firm audit everything currently. Once they gives us the all clear we will be making every user change their password with a new force password reset feature we are working on.
shapesifter13
Developer
Developer
 
Posts: 4681
Joined: Fri Jan 02, 2015 4:55 pm

Re: Data Security Update 1/4/2019

Postby mdb1023 » Wed Jan 09, 2019 5:24 pm

Dammit I already changed my password. Can I change it and then change it back to what I have now?
Discord: Finn#5059

http://www.twitch.tv/mikeakafinn?sr=a

Do you like Mafia? You'll love Survivor, and and we're hosting games of them all the time! It's super easy to join and learn how to play, and the best part is- it's all on discord! Join the Finnvivor discord server to see when signups for a new game go up! Click here to join the server or DM me on discord for details! !
User avatar
mdb1023
Serial Killer
Serial Killer
 
Posts: 2127
Joined: Mon Mar 30, 2015 2:45 pm
Location: At work, rehearsal, or finishing whatever I pushed off to the last minute this time.

Re: Data Security Update 1/4/2019

Postby danzho55 » Wed Jan 09, 2019 9:46 pm

If my account was linked to my steam account, does that mean my steam info is compromised aswell? Also, since I forgot my old password a year ago, I've been resetting my password and just logging in with the password that was sent to my email. If I never bothered to update my password, does that mean they don't have my original password?
danzho55
Newbie
Newbie
 
Posts: 1
Joined: Sun Dec 20, 2015 9:05 pm

Re: Data Security Update 1/4/2019

Postby Jerme » Wed Jan 09, 2019 10:59 pm

danzho55 wrote:If my account was linked to my steam account, does that mean my steam info is compromised aswell? Also, since I forgot my old password a year ago, I've been resetting my password and just logging in with the password that was sent to my email. If I never bothered to update my password, does that mean they don't have my original password?

No Steaminfo was taken as far as I've seen, as only the forum DB was breached instead of the one of the game (in which only your Steam ID is saved in). Thus the hackers do not have gotten any Steaminfo on that (or onyl the email if you use the same for Steam and ToS). Only the hash of the passwor was taken, so with work they could decode it, but this cna take a while to be done.
Disclaimer: I try to abide by the game's softfilter and use the appropriate replacements, when I am using the forums. Those will be set in brackets. Example: [tarnation]
Visit my role suggestions and give me feedback: http://www.blankmediagames.com/phpbb/viewtopic.php?f=27&t=28949

Visit the Testing Grounds
Occupation: A developers pain and joy (QA-fox), currently "hired" by Ralozey
User avatar
Jerme
Global Moderator
Global Moderator
 
Posts: 28197
Joined: Thu Apr 30, 2015 2:09 pm

Re: Data Security Update 1/4/2019

Postby Jerme » Thu Jan 10, 2019 11:33 am

Gutten wrote:Considering you are sending out plain text passwords through emails, I’d say you deserve what’s coming to you.

That password is supposed to be one use only in order to have it changed.
Disclaimer: I try to abide by the game's softfilter and use the appropriate replacements, when I am using the forums. Those will be set in brackets. Example: [tarnation]
Visit my role suggestions and give me feedback: http://www.blankmediagames.com/phpbb/viewtopic.php?f=27&t=28949

Visit the Testing Grounds
Occupation: A developers pain and joy (QA-fox), currently "hired" by Ralozey
User avatar
Jerme
Global Moderator
Global Moderator
 
Posts: 28197
Joined: Thu Apr 30, 2015 2:09 pm

Re: Data Security Update 1/4/2019

Postby Phone0Ix » Thu Jan 10, 2019 11:54 am

shapesifter13 wrote:
Malfoydragon wrote:
Malfoydragon wrote:Has the malware, the hackers, and all traces of the hackers been removed?


I'd like a clear answer from staff on this please, because I changed my password to a temporary password, if everything is removed I can create a permanent password for this account.


We believe we have fixed all the holes, but we are having a security firm audit everything currently. Once they gives us the all clear we will be making every user change their password with a new force password reset feature we are working on.

Can you give a warning a week before the reset? Because I'm still afraid my friend will use their account with the password reset. In that way my friend can contact the admins when emails to your team are stopped being about the breach and he can contact you to get to change their email
Call me Phone Ig

Or Silver because of my old discord name. Or Mikan because of my new discord name. Or Julian as that's my actual name
User avatar
Phone0Ix
[Forum Mafia XVII] Winner
[Forum Mafia XVII] Winner
 
Posts: 429
Joined: Sun Jul 24, 2016 11:00 am
Location: The Netherlands

PreviousNext

Return to Announcements

Who is online

Users browsing this forum: No registered users and 4 guests