Pages:
Author

Topic: I suspect GPUMax was compromised and passwords stolen - page 3. (Read 6356 times)

legendary
Activity: 1050
Merit: 1003
In the last 24 hours there have been two GLBSE accounts (that I know of) that have been cleared out.

The common theme between them is that both users had GPUMax accounts, with passwords that were either the same (as the GLBSE accounts password) or similar.

I emailed the GPUMax website yesterday (the email in their whois records as there isn't anything on the site) to inform them of this.

Since I've not seen any notice regarding GPUMax I feel that it is my responsibility to bring this to public attention.

If you have a GPUMax account it is highly likely that it's password has somehow been compromised.

If you use the same or a similar password elsewhere (GLBSE, MtGox, Email whatever) please change them now.

If you are a GLBSE user I would encourage you to use two-factor authentication, there have already been over 3 accounts which have been protected by this.

Nefario.

If the people used the same or similar password on 2 sites, isn't it reasonable to expect that they used it on other sites as well?

The question should be what percentage of GBLSE users also use GPUmax? If this percentage is very low, then Nefario is probably right.
sr. member
Activity: 378
Merit: 250
"Yes I am a pirate, 200 years too late."
We have a lot of users and I guess since your users have a GPUMAX account with the "same" password it must have been us that leaked them.  If users are using the same password on GLBSE and GPUMAX, you can be pretty sure they're using the same password for other sites as well.

Our users information is hashed and salted using the latest cryptography methods available.  I can assure you, we didn't leak anything.  

On a side note, considering you know who runs GPUMAX, you could have easily sent me PM before spreading more FUD in the market.

Edit:  Our whois lists [email protected] which shows nothing from you or anything related to security. Found it hiding in the spam trap.

-pirate




legendary
Activity: 1050
Merit: 1003
Perhaps nothing is compromised, but it is just the operator exploiting his password haul?
vip
Activity: 574
Merit: 500
Don't send me a pm unless you gpg encrypt it.
In the last 24 hours there have been two GLBSE accounts (that I know of) that have been cleared out.

The common theme between them is that both users had GPUMax accounts, with passwords that were either the same (as the GLBSE accounts password) or similar.

I emailed the GPUMax website yesterday (the email in their whois records as there isn't anything on the site) to inform them of this.

Since I've not seen any notice regarding GPUMax I feel that it is my responsibility to bring this to public attention.

If you have a GPUMax account it is highly likely that it's password has somehow been compromised.

If you use the same or a similar password elsewhere (GLBSE, MtGox, Email whatever) please change them now.

If you are a GLBSE user I would encourage you to use two-factor authentication, there have already been over 3 accounts which have been protected by this.

Nefario.

If the people used the same or similar password on 2 sites, isn't it reasonable to expect that they used it on other sites as well?
hero member
Activity: 602
Merit: 512
GLBSE Support [email protected]
In the last 24 hours there have been two GLBSE accounts (that I know of) that have been cleared out.

The common theme between them is that both users had GPUMax accounts, with passwords that were either the same (as the GLBSE accounts password) or similar.

I emailed the GPUMax website yesterday (the email in their whois records as there isn't anything on the site) to inform them of this.

Since I've not seen any notice regarding GPUMax I feel that it is my responsibility to bring this to public attention.

If you have a GPUMax account it is highly likely that it's password has somehow been compromised.

If you use the same or a similar password elsewhere (GLBSE, MtGox, Email whatever) please change them now.

If you are a GLBSE user I would encourage you to use two-factor authentication, there have already been over 3 accounts which have been protected by this.

Nefario.
Pages:
Jump to: