Hey guys,
As many of you are probably already aware we are back up and running! Yeeey!
On your login you will be asked to reset your password, you can do that in one of two ways.
1. You can change password from any device that is still logged into your account.
2. You can contact our support team. ( Please note that support will be slower than usual due to huge amount of tickets we are getting at this moment.
Also for users safety all withdrawals are currently on manual.
I think what is really scary about this incident is imagine what could of happebed if the hackers weren't lazy.
They would at an unsuspecting time ( when PD dev are sleeping ) commit the hack and make the phishing site look for authentic.
When someone tried to login, they would go to the real PD and perform a withdraw.
The way the registrar handled this situation was very dangerous. Hopefully many Bitcoin sites and services can learn from this incident.
In this case, Primedice can't be reached via IP: if they change the DNS, they can't find the authentic website.
Of course, your idea is valid and can be used in some websites.
Yes but this is not what happened is it?
Basically the registrar redirected the traffic to a different IP.
The old site was still accessible by the old IP.
The hacker would simply record the usernames and passwords and then go to the real Primedice website by the IP address.
Plus, it takes a few hours for DNS to update. It's not instant but bottle necked by the ISP
Well it would be hard to pull off we have 24/7 support which is also always monitoring the site so we would take quick actions at any time. They can always reach me if not all devs and admins.
Thats why having 24/7 support proved to be very important and useful and we are one of the few sites that have it.
Stunna will post more details on how it happened.
It was not even remotely our fault and you will know why soon.
I hope we handled it well in the best way possible for all of our users and even though this was not our fault all the transactions sent to the phishing address will be refunded.
Again thank you all for support on this and for helping us get that phishing waring so fast.