Pages:
Author

Topic: NXT account hacked. All assets gone. - page 2. (Read 2559 times)

sr. member
Activity: 368
Merit: 250
August 31, 2014, 03:30:34 PM
#25
Thanks EvilDave.  While I'm changing ALL of my passwords I don't want to put my old one out yet.  It was very simple for a hacker and I meant to change it but kept putting it off.  It was just a Word+number+symbol.  Twelve characters.  Bad, bad, bad.  For anyone who is out there reading this and thinks they have a 'good enough' password, for goodness sakes update it right now.  This truly sucks, and you don't want to be in my postion.  Undecided

Actually the PW strength probably wasn't the issue.

Malware and using it on other sites are more than likely the issue.

If you were too lazy to change it,

then there is a high probability you reused it or a similar variation of it somewhere else.

~BCX~

Ah...trojans and dodgy sites are possible, but don't forget that there are also guys running rainbow tables against the NXT blockchain 24/7.
Any simple (or well known) password will be compromised, given enough time.
Had a guy on www.NXTforum.org a few days ago who had chosen a Bible verse as his password, and that got compromised pretty quickly.

The answer is simple: use a complex password, ffs. Not one that is easy to remember......
35 characters, upper+lower case, numbers and symbols.

@Yuzu: I know how much getting shit stolen hurts, so post or PM me your new NXT account (with a supersecure password) and I'll send 1000 NXT to help you back on track a little bit.

Dave, that's so damn nice of you.  But I can't take anything from anybody, though I appreciate the offer more than I can tell you.  Take that 1000NXT and get some of a nice asset like USDbitfnx.  It's a nice quiet little asset that pays out every two weeks.  I'm going to buy more of it when I get more funds.  But thanks, thanks, thanks!
legendary
Activity: 1540
Merit: 1011
FUD Philanthropist™
August 31, 2014, 03:29:41 PM
#24
This is what worries me about NXT. Can't you just literally bruteforce it until you come across weak passwords?

yeah and that is not FUD'ing but a valid concern !!!
sr. member
Activity: 336
Merit: 260
August 31, 2014, 03:27:32 PM
#23
This is what worries me about NXT. Can't you just literally bruteforce it until you come across weak passwords?

Someone is doing exactly that. Try to create an account with a simple password, fund it with a few coins and track how long it'll take for coins to disappear Smiley Someone did that experiment in Bitcoin with a brain wallet too, brain wallet with a phrase like 'hello, world' or something, it was gone in 5 mins. Moral of the story: use a truely random pass of 20+ chars and keep your PC clean from trojans of course.
hero member
Activity: 532
Merit: 500
August 31, 2014, 03:24:05 PM
#22
This is what worries me about NXT. Can't you just literally bruteforce it until you come across weak passwords?
sr. member
Activity: 336
Merit: 260
August 31, 2014, 03:12:40 PM
#21

Actually the PW strength probably wasn't the issue.


In NXT, which is a brain wallet, PW strength is exactly the issue.

OP says it was a word + number + symbol = 12 chars.

So, something like this: Generation5!

It was most likely brute-forced using a dictionary.

Something like this: MaQorLdNxE5!    would be much more secure, also 12 characters, but no dictionary words. At least 20 or more random characters are recommended for better security, with no dictionary words.
hero member
Activity: 854
Merit: 1001
August 31, 2014, 03:11:33 PM
#20
Thanks EvilDave.  While I'm changing ALL of my passwords I don't want to put my old one out yet.  It was very simple for a hacker and I meant to change it but kept putting it off.  It was just a Word+number+symbol.  Twelve characters.  Bad, bad, bad.  For anyone who is out there reading this and thinks they have a 'good enough' password, for goodness sakes update it right now.  This truly sucks, and you don't want to be in my postion.  Undecided

Actually the PW strength probably wasn't the issue.

Malware and using it on other sites are more than likely the issue.

If you were too lazy to change it,

then there is a high probability you reused it or a similar variation of it somewhere else.

~BCX~

Ah...trojans and dodgy sites are possible, but don't forget that there are also guys running rainbow tables against the NXT blockchain 24/7.
Any simple (or well known) password will be compromised, given enough time.
Had a guy on www.NXTforum.org a few days ago who had chosen a Bible verse as his password, and that got compromised pretty quickly.

The answer is simple: use a complex password, ffs. Not one that is easy to remember......
35 characters, upper+lower case, numbers and symbols.

@Yuzu: I know how much getting shit stolen hurts, so post or PM me your new NXT account (with a supersecure password) and I'll send 1000 NXT to help you back on track a little bit.
sr. member
Activity: 368
Merit: 250
August 31, 2014, 02:56:30 PM
#19
Thanks EvilDave.  While I'm changing ALL of my passwords I don't want to put my old one out yet.  It was very simple for a hacker and I meant to change it but kept putting it off.  It was just a Word+number+symbol.  Twelve characters.  Bad, bad, bad.  For anyone who is out there reading this and thinks they have a 'good enough' password, for goodness sakes update it right now.  This truly sucks, and you don't want to be in my postion.  Undecided

Actually the PW strength probably wasn't the issue.

Malware and using it on other sites are more than likely the issue.

If you were too lazy to change it,

then there is a high probability you reused it or a similar variation of it somewhere else.


~BCX~

You're right about that.  I have no one to blame but myself.  Like I said, it will never happen again.  Not to me.  I'm just posting this as a warning to those who might have done what I did.
sr. member
Activity: 368
Merit: 250
August 31, 2014, 02:49:44 PM
#18
Thanks EvilDave.  While I'm changing ALL of my passwords I don't want to put my old one out yet.  It was very simple for a hacker and I meant to change it but kept putting it off.  It was just a Word+number+symbol.  Twelve characters.  Bad, bad, bad.  For anyone who is out there reading this and thinks they have a 'good enough' password, for goodness sakes update it right now.  This truly sucks, and you don't want to be in my postion.  Undecided
legendary
Activity: 1210
Merit: 1024
August 31, 2014, 02:46:37 PM
#17
It appears to have a lot of hack on NXT lately.

A 3rd party  casual observer may will rightfully think this is a coin with security issues.



Fixed that for you.

Isn't roll backs part of the unique built in features to prevent successful thefts in NXT?


~BCX~
hero member
Activity: 854
Merit: 1001
August 31, 2014, 02:44:03 PM
#16
It appears to have a lot of hack on NXT lately.

A 3rd party observer may think this is a coin security issue.

The recent NXT thefts had sod-all to do with NXT security, but are all about password security.
Whether its guys choosing "dog" as a secure password for a brainwallet, or server admins using the same password for everything......it's always password security or simple social engineering behind most crypto-thefts.

NXT didn't do a rollback when they were hacked, but thanks for taking this post and making it all about an agenda.  I messed up with and didn't have a secure enough password, and I'm not asking for anything except information anyone might have.

it was a fair and quite funny joke considering the exchange BTER was hacked for NXT a matter of 2/3 weeks ago.
So in case people don't know out there that is why the joke is funny.. HA HA
(NXT cheerleaders asked for a rollback on the BTER hack)

nothing to do with an "agenda" bud lol

BTER were the guys keen on the rollback, most of NXT community were against it, so Spoetnik is kinda twisting the truth here.
And, yeah, way to express some sympathy.

@Yuzu: what was your password/passphrase ?
It's been compromised, so it's fuck-all good to you now, but it'd be good to see an example of a compromised password.
Might serve as a warning for other people: Choose a very secure password for your crypto! 8 lowercase characters doesn't hack it any more.
You have my sympathy, btw, thieves suck.
legendary
Activity: 1334
Merit: 1004
TTM
August 31, 2014, 02:42:02 PM
#15
Use keepassx. Free and mac os support Wink
sr. member
Activity: 368
Merit: 250
August 31, 2014, 02:31:50 PM
#14
I'm a bud-ette.  I guess I just don't see the humor in all my assets being gone.  My sense of humor today is quite gone.  As for security issues, I can't really say.  My password wasn't very strong.  And other people don't seem to be having a problem. 
legendary
Activity: 1540
Merit: 1011
FUD Philanthropist™
August 31, 2014, 02:30:46 PM
#13
It appears to have a lot of hack on NXT lately.

A 3rd party observer may think this is a coin security issue.

yup !

i agree.. seems to be a lot of security issues swirling around this coin.. not a good impression at all !
legendary
Activity: 1540
Merit: 1011
FUD Philanthropist™
August 31, 2014, 02:29:48 PM
#12
NXT didn't do a rollback when they were hacked, but thanks for taking this post and making it all about an agenda.  I messed up with and didn't have a secure enough password, and I'm not asking for anything except information anyone might have.

it was a fair and quite funny joke considering the exchange BTER was hacked for NXT a matter of 2/3 weeks ago.
So in case people don't know out there that is why the joke is funny.. HA HA
(NXT cheerleaders asked for a rollback on the BTER hack)

nothing to do with an "agenda" bud lol
full member
Activity: 213
Merit: 100
August 31, 2014, 02:27:08 PM
#11
It appears to have a lot of hack on NXT lately.

A 3rd party observer may think this is a coin security issue.
sr. member
Activity: 368
Merit: 250
August 31, 2014, 02:25:36 PM
#10
NXT didn't do a rollback when they were hacked, but thanks for taking this post and making it all about an agenda.  I messed up with and didn't have a secure enough password, and I'm not asking for anything except information anyone might have.
legendary
Activity: 1540
Merit: 1011
FUD Philanthropist™
August 31, 2014, 02:20:38 PM
#9
just ask for a rollback.


lol so true !

and this makes me think.. we can now so he "private" this coin really is..

see what was suggested here "anon" coin floggers see how easy the technique of cross referencing is ?
see how your stupid anon gimmick coins are a joke yet ?

edit:
i like Password Depot
but i don't think they have a mac version Sad
it can run in free ware mode i here and has free mobile version.
http://www.password-depot.com/download.htm
http://www.password-depot.com/download-special-editions.htm

it has lots of features and was one of the best when i seen reviews first online too.
They are faster at updating the Firefox plugin compared to Kaspersky's Pass manager.

i like the tray icon.. you can right click it and select make new password.. really easy !
no reason for weak passwords these days..
member
Activity: 74
Merit: 10
August 31, 2014, 01:45:47 PM
#8
Thank you very much.  I'll look into 1password.

Keepass is good too and does an OSX version.

http://sourceforge.net/projects/keepass/
legendary
Activity: 812
Merit: 1000
August 31, 2014, 01:20:55 PM
#7

dam this sucks Sad
sr. member
Activity: 368
Merit: 250
August 31, 2014, 12:36:53 PM
#6
Thank you very much.  I'll look into 1password.
Pages:
Jump to: