• WANTED: Happy members who like to discuss audio and other topics related to our interest. Desire to learn and share knowledge of science required. There are many reviews of audio hardware and expert members to help answer your questions. Click here to have your audio equipment measured for free!

Warning: change your password please!

AdamG

Helping stretch the audiophile budget…
Moderator
Forum Donor
Joined
Jan 3, 2021
Messages
4,747
Likes
15,733
Location
Reality

sarumbear

Master Contributor
Forum Donor
Joined
Aug 15, 2020
Messages
7,604
Likes
7,324
Location
UK
After changing my password I've checked my last messages to see if someone is selling cooking ware with my account.

Good luck to everyone. Be safe, be aware...
In my case they changed my email address. I lost access to my account while the hacker was selling equipment pretending to be me.
 

Doodski

Grand Contributor
Forum Donor
Joined
Dec 9, 2019
Messages
21,614
Likes
21,899
Location
Canada
Well... Ima glad I changed mine out for a very very strong password because I previously used a very simple one temporarily and forgot to go back and update it. It would not be a biggie if it was cracked because all my stuff has different passwords. Have funnnn scanning for passwords whack job(s). :D
 

Digby

Major Contributor
Joined
Mar 12, 2021
Messages
1,632
Likes
1,560
Unless you are like me, whose login is hijacked by someone who were selling equipment through my profile…
Was it only your account here that was compromised or others elsewhere? Were you using a password which could be guessed (by a computer) relatively quickly. Did you get to the bottom of this?
 

sarumbear

Master Contributor
Forum Donor
Joined
Aug 15, 2020
Messages
7,604
Likes
7,324
Location
UK
Was it only your account here that was compromised or others elsewhere? Were you using a password which could be guessed (by a computer) relatively quickly. Did you get to the bottom of this?
I was told at the time that I was the only one for a long while.

The password I was using required tens of years to be hacked and it was not listed on the pawned databases. How it was hacked I do not know. The same password was used on my own server (by mistake) but there were no logins to that server. Both passwords are now changed to different ones.

The problem was that after accessing my account they have not only changed the password but changed the email address as well, effectively blocking my access to ASR. I had to create a temporary account in order to reach the admins.
 

Doodski

Grand Contributor
Forum Donor
Joined
Dec 9, 2019
Messages
21,614
Likes
21,899
Location
Canada
I was told at the time that I was the only one for a long while.

The password I was using required tens of years to be hacked and it was not listed on the pawned databases. How it was hacked I do not know. The same password was used on my own server (by mistake) but there were no logins to that server. Both passwords are now changed to different ones.

The problem was that after accessing my account they have not only changed the password but changed the email address as well, effectively blocking my access to ASR. I had to create a temporary account in order to reach the admins.
They brute forced it with passwords and got lucky. Scary that they picked you out.
 

mhardy6647

Grand Contributor
Joined
Dec 12, 2019
Messages
11,407
Likes
24,762
Just remember to keep it in the drawer, and don’t use one with this on the cover:
View attachment 258152
This is easy to fix.

1674087072974.png
 

restorer-john

Grand Contributor
Joined
Mar 1, 2018
Messages
12,728
Likes
38,936
Location
Gold Coast, Queensland, Australia
I would argue that the best place to keep your passwords in 2023 is ironically, on a piece of paper somewhere in your house. It limits potential access to the one random burglar who is more likely to be interested in your iPads, laptops, jewelry, cameras, cash and gaming consoles.
 
Last edited:
OP
amirm

amirm

Founder/Admin
Staff Member
CFO (Chief Fun Officer)
Joined
Feb 13, 2016
Messages
44,679
Likes
241,149
Location
Seattle Area
Sounds like the site is being targeted but it is only being hit on an individual-by-individual level thus far. I trust only a salted hash is stored behind the scenes, rather than our whole passwords, to limit impact if there were a data breach?
Yes, it uses modified salted hash using bcrypt library.
 
OP
amirm

amirm

Founder/Admin
Staff Member
CFO (Chief Fun Officer)
Joined
Feb 13, 2016
Messages
44,679
Likes
241,149
Location
Seattle Area
FYI we discovered 3 more today. Our spam filters are catching them after the fact by quarantining the posts. It is possible there are more that we are not seeing although that is unlikely. So scale is small but not zero or random.
 

Mr. Widget

Major Contributor
Forum Donor
Joined
Oct 11, 2022
Messages
1,177
Likes
1,777
Location
SF Bay Area
FYI we discovered 3 more today. Our spam filters are catching them after the fact by quarantining the posts. It is possible there are more that we are not seeing although that is unlikely. So scale is small but not zero or random.
Thanks for keeping us informed.
 

Keened

Senior Member
Forum Donor
Joined
Nov 2, 2021
Messages
329
Likes
219
If the passwords are encrypted then how can it be breached? Either social engineering or scanning for passwords must be done?
Not all encryption is equally well implemented. If they don't salt the codes then they become significantly more susceptible to rainbow tables and such. Or the messages are encrypted but the keys are held in plain text somewhere along the way and no one is auditing the logs, maybe you don't get them all, but you get enough over time.

Three to one to me suggests sockpuppets which are endemic on forums and to be expected without necessarily malicious intent.

Either way the alert is appreciated, but something going out via email would probably be best next time. I didn't see this until I specifically clicked into the reviews list.
 

BlackTalon

Addicted to Fun and Learning
Forum Donor
Joined
Apr 14, 2021
Messages
595
Likes
953
Location
DC
It was only a matter of time until the brains at PS Audio and Audioquest used all of their extensive engineering knowledge to break into ASR...
 

Beershaun

Major Contributor
Forum Donor
Joined
Oct 3, 2019
Messages
1,877
Likes
1,922
Updated and 2FA added. Thanks for the head's up!
 

bakker_be

Active Member
Joined
May 20, 2018
Messages
188
Likes
116
Location
Belgium
Top Bottom