<…>
Today at 09:26:50 AM - bbvedf - password changed
And by change, it's just "password change" so i am wondering how he could have been able to access his account to change the password if he already wasn't able to log in.
@bbvedf is from my local board, and has opened a thread there to try to get some help on the matter (see
Ayuda con mi cuenta de BCT – it’s in Spanish though). The way he’s depicting the events, he claims that he was “silently hacked”. That is to say, someone gained access to his account, using his same credentials (not changing them), and published the fake Ann thread from his account. If true, that would be the best way to use an account for wrong doing, although it does constitute a very difficult case to prove.
It also likely denotes a weak password management, as for this to happen without brute force, he would have to have used the same password in a crypto related site and have the password leaked from there. That alone is arguably irresponsible to some extent, but I’m pretty sure there are thousands of users here that use the same password on a couple of sites.
The only possible way to move on with trying to clear @bbvedf’s claims (which are very similar to @Mrengage’s) would be for both of the to ask @theymos for their access logs for the date of events, and see what that may show. It certainly will not be conclusive, but may show something interesting (i.e. common IPs from Russia for example – again not conclusive, but opens a door to suspicion).
Looking at the archived thread (
http://archive.fo/yfa4D), I believe tagging the accounts is correct (how not to, seeing the evidence), but it would be good to know if we are facing a couple of more intelligent account hacks here, where the accounts are only taken temporarily without changing the credentials. It’s likely nearly impossible to prove this were it to be true, but the IP logs could help to raise suspicion or drown it altogether.
Of course making IP log retrieval a general habit would be a pain in the back side, and likely won’t be done except on an rare occasions, but perhaps it’s worth a go here to see what it may lead to.