Pages:
Author

Topic: Why bctalk accounts are getting hacked? (Read 428 times)

sr. member
Activity: 602
Merit: 327
Politeness: 1227: - 0 / +1
August 26, 2018, 09:27:09 PM
#27
Did you even read the link I posted?
Yeah I did.
I've read the topic about this secret question in the link you have provided
But didn't read several replies as the OP already gave me the information I'm looking for. Anyway thanks for the info.
Don't worry... follow this
Thanks @mdayonliner.
legendary
Activity: 2758
Merit: 6830
August 26, 2018, 07:27:19 AM
#26
I've read the topic about this secret question in the link you have provided in the first page but I'm just wondering why the description says different. Well I believe you now as there are several members who already tested it out.
Did you even read the link I posted? Or just the title?

The forum software (SMF) includes the Secret Question method of recovery by default. However, theymos disabled that option for security purposes due to the 2015 hack that leaked the Secret Questions and Answers of the users. He didn't change the page text (that says you can recover your acc with the Secret Question), but it doesn't matter.

[...] The reason that the accounts are locked is because the May 2015 hack leaked Bitcointalk's database which did not securely secure the Secret Question and Answer. To prevent people from guessing the answers, theymos made it so that accounts that are recovered using the secret question are automatically locked when the option is attempted. This is to prevent hackers who may be able to guess the answers from the leaked database. [...]
copper member
Activity: 630
Merit: 420
We are Bitcoin!
August 26, 2018, 06:23:03 AM
#25
Most of the accounts are registered after 2015
I never seen any stats. My one was just an assumption.

But actually, I've set a secret question in my account before. I just forgot what's the answer  Huh
Don't worry... follow this
sr. member
Activity: 602
Merit: 327
Politeness: 1227: - 0 / +1
August 26, 2018, 01:17:34 AM
#24
Spoiler: NO. No one can access your account with just the secret answer. This will only lock your account - as explained in the previous page. Please read the whole thread before making a new post.
I never tried/used secret password and I don't plan to use it for unknown reasons but if no one can access your account by just using it, why it says "To help retrieve your password, enter a question here with an answer that only you know. Using this feature is not recommended. Anyone who guesses your secret answer will have access to your account. It's like a second password."

It means anyone who can guess it will have access to the account because it's like a second password and is used to retrieve the account. I'm really confused which one to believe. But I don't want to try it myself.

But actually, I've set a secret question in my account before. I just forgot what's the answer  Huh

I've read the topic about this secret question in the link you have provided in the first page but I'm just wondering why the description says different. Well I believe you now as there are several members who already tested it out.
legendary
Activity: 2758
Merit: 6830
August 25, 2018, 11:46:24 PM
#23
~
If you are so sure about this, why don't you set up a Secret Question and try yourself?

Spoiler: NO. No one can access your account with just the secret answer. This will only lock your account - as explained in the previous page. Please read the whole thread before making a new post.

sr. member
Activity: 602
Merit: 327
Politeness: 1227: - 0 / +1
August 25, 2018, 05:21:34 PM
#22
I'm also wondering why there are still issues about hacked account excluding those accounts that has been hacked in that database leak back in 2015. I mean, are they too careless?

I'm thinking that maybe some bounties also contains phishing. Some bounties requires a some sort of "google form" where applicants must fill up first and it's possible that some of those forms are phishing. As we can see, most of those reported accounts that has been hacked are participating bounties.

- Don’t click on links posted on this forum
That would definitely avoid phishing links  Cheesy but not all links posted in this forum are phishing. I prefer "Checking the link first before clicking it" since some links are useful and some are obviously not phishing.
I hardly believe the number of people using a weak password is so hight
Yeah, people would be so stupid to put "123455789" or "qwerty" etc as their password. Though some really do  Grin

I'm taking good care of my account, I'm checking links before I click them, I'm not logging in to any public PC or someone else's phone and I'm using a strong password, lets just see if my account will still be hacked in the future. But I'm hoping I will not happen.

My additional tip is to avoid joining bounties/airdrops or check their form first before putting information or clicking the link. It's really possible that some phishing links are from other bounties/airdrops.

Is anyone ever think of that?

There are more accounts hacked with a low rank than a hight one
It's probably because I'm right that most of these accounts are participating bounties where some bounties contains phishing.
jr. member
Activity: 112
Merit: 3
Linux Forever... Resistance is futile!!!
August 25, 2018, 04:48:37 PM
#21
I hope that the launched of the new bitcointalk forum will have a more security feautures like 2fa or the use of verified signed bitcoin address.
Actually most of the hacks are coming from "Secret Question".
If you dont have "Secret Question" and want to change email or password, forum will send you email notification to approve your request.
But if you have "Secret Question" , it will ask it, then the hacker have unlimited tries/retries to guess the answer and change your email and password.

Mine got hacked by my "Secret Question" .
If the "Secret Question" is one of the reasons why accounts are being hacked, then why is it still there? More people will get confused whether they will use it or not. Huh


Please either dont quote a message or fully quote it ...


You can see this in your profile>Account Related Settings>Secret Question
Its written in BOLD :

Using this feature is not recommended. Anyone who guesses your secret answer will have access to your account. It's like a second password.



legendary
Activity: 2534
Merit: 1517
#1 VIP Crypto Casino
August 25, 2018, 03:54:16 PM
#20
No, frequent users do not use google to connect to the forum. Either they type the URL address or they use the bookmarked URL in their browser
Quote
a bitcoinTalk account with a good rank worth good money.
There are more accounts hacked with a low rank than a hight one
~

This is true it is due to the fact that most users are of low rank as the photo below shows, and of course the people who have been here on the forum for a long time have also learned about how others protect themselves, so I think that, apart from the accounts attacked during the hacker attack, the oldest accounts are the safest ones


credits to: https://bitcointalksearch.org/topic/2-million-users-and-their-stats-4901670
full member
Activity: 434
Merit: 246
August 25, 2018, 03:22:22 PM
#19
- Don’t click on links posted on this forum
This is a very good point. I nearly fell for a Phishing Scam after clicking on a link posted in the Services board. The link took me to a page looking identical to the login screen of bitcointalk.org. Luckily for me, I checked the URL, which of course wasn't on the bitcointalk domain, and I didn't enter my login data. But someone else (or me in a different situation) might have overlooked the URL check.
copper member
Activity: 2940
Merit: 4101
Top Crypto Casino
August 25, 2018, 02:16:51 PM
#18
There was a database leak in 2015. My guess is most of these hacks are related to this database leak.

Most of the accounts are registered after 2015


You can also take consideration of the phishing sites. When you look for bitcoinTalk on google, it pulls up few phishing sites who wants the credentials of your bitcoinTalk account. So phishing sites are another way of getting hacks.

No, frequent users do not use google to connect to the forum. Either they type the URL address or they use the bookmarked URL in their browser
Quote
a bitcoinTalk account with a good rank worth good money.
There are more accounts hacked with a low rank than a hight one

Quote
main reason of account hacks is phishing websites and people using weak passwords.
I hardly believe the number of people using a weak password is so hight
legendary
Activity: 2534
Merit: 1517
#1 VIP Crypto Casino
August 25, 2018, 01:05:25 PM
#17
The reason why the accounts are hacked seems obvious to me and is an economic move, accounts stolen are used to wear the signature with a high rank or to be sold.
High rank accounts can be worth thousands of dollars and provide thousands of dollars from various signatures campaigns.
How are these accounts hacked? First of all the ignorance of the users.
Edit: (somone wrote this link seconds before me Grin )
You can follow this guide to learn more about the security of your account https://bitcointalksearch.org/topic/m.44294262
newbie
Activity: 112
Merit: 0
August 25, 2018, 01:04:29 PM
#16
My MEW was hacked yesterday. the reason is because i joined some airdrops yesterday. most of the time phising site , copyboard, using same Email and password for every wallet, saving password in browser etc. there are many other reason and many new ways created everyday. For your protection https://bitcointalk.org/index.php?topic=4920096.0%20[Guide read this topic. It will be helpful.
copper member
Activity: 630
Merit: 420
We are Bitcoin!
August 25, 2018, 12:31:29 PM
#15
AFAIK, the "Secret Question" actually locks your account. So I don't think it's one of the major reasons why many accounts are getting hacked.
Spot on! Secret Question account recovery just locks the account, it has nothing to do with account hack.

I remember I was worried about Secret Question too since I heard that it can lock the account. I was looking for help here and there to know how to remove it so that I can feel safe. Then one day after following a post, I gave it a try to remove it and it worked. Since then I have no secret question attached with my account.
full member
Activity: 484
Merit: 124
August 25, 2018, 12:13:56 PM
#14
Database leak become the main reason why many account got hacked.
Why they want to hack ?
Because some account may worth more than $ 1000 !
legendary
Activity: 2758
Merit: 6830
August 25, 2018, 11:04:08 AM
#13
If the "Secret Question" is one of the reasons why accounts are being hacked, then why is it still there? More people will get confused whether they will use it or not. Huh
AFAIK, the "Secret Question" actually locks your account. So I don't think it's one of the major reasons why many accounts are getting hacked. My guess is that most people are getting hacked because they are using the same password in other websites - e.g ICO related websites/dashboards, which is even worse - or because their computer are infected. I've never seen a tech-savvy user getting hacked here.

Mine got hacked by my "Secret Question" .
It didn't.

For reference: PSA: ACCOUNTS WILL BE LOCKED IF THE SECRET QUESTION IS USED TO RECOVER IT
sr. member
Activity: 1162
Merit: 450
August 25, 2018, 09:09:50 AM
#12
I hope that the launched of the new bitcointalk forum will have a more security feautures like 2fa or the use of verified signed bitcoin address.
Actually most of the hacks are coming from "Secret Question".
If you dont have "Secret Question" and want to change email or password, forum will send you email notification to approve your request.
But if you have "Secret Question" , it will ask it, then the hacker have unlimited tries/retries to guess the answer and change your email and password.

Mine got hacked by my "Secret Question" .
If the "Secret Question" is one of the reasons why accounts are being hacked, then why is it still there? More people will get confused whether they will use it or not. Huh
full member
Activity: 378
Merit: 104
August 25, 2018, 08:04:57 AM
#11
I saw many people's account are hacked any how.My question is how can anyone hack accounts? And how we can protect our accounts? I don't know if this topic should be written here but i really need these answer.               
Based from my findings, most of the hacks are because of the database leakage last 2015 and also the security features of the site that time that are not yet fixed that time, and also to those people that are not changing their passwords.
mk4
legendary
Activity: 2870
Merit: 3873
Paldo.io 🤖
August 25, 2018, 06:35:34 AM
#10
Basically, users are not quite fond of protecting their accounts by not using a security question, that, is the very best assurance of security you can have in forum. And most of the hacked accounts as you can see are those accounts for sell, without having escrow, if i am not mistaken. 

The reasons why people are getting hacked are most likely not only because of the security question feature. There are a lot of ways of people getting hacked. I personally think the #1 reason is still that people use the same passwords on multiple accounts; and if one of those account's password gets leaked, then the hacker pretty much has access to almost every account the user has. And that's just the tip of the iceberg. There are lots more ways.
jr. member
Activity: 112
Merit: 3
Linux Forever... Resistance is futile!!!
August 25, 2018, 06:07:44 AM
#9
Basically, users are not quite fond of protecting their accounts by not using a security question, that, is the very best assurance of security you can have in forum. And most of the hacked accounts as you can see are those accounts for sell, without having escrow, if i am not mistaken.  


Actually most of the hacks are coming from "Secret Question".
If you dont have "Secret Question" and want to change email or password, forum will send you email notification to approve your request.
But if you have "Secret Question" , it will ask it, then the hacker have unlimited tries/retries to guess the answer and change your email and password.

Mine got hacked by my "Secret Question" .



Quote from: Account Related Settings
Secret Question:
To help retrieve your password, enter a question here with an answer that only you know.
Using this feature is not recommended. Anyone who guesses your secret answer will have access to your account. It's like a second password.
legendary
Activity: 3234
Merit: 1375
Slava Ukraini!
August 25, 2018, 05:19:57 AM
#8
I saw many people's account are hacked any how.My question is how can anyone hack accounts? And how we can protect our accounts? I don't know if this topic should be written here but i really need these answer.              
There was a database leak in 2015. My guess is most of these hacks are related to this database leak.
I don't think that database leak in 2015 is the main reason of high number of hacked accounts. As I see, biggest number of hacked accounts was made after 2015. So, probably main reason of account hacks is phishing websites and people using weak passwords.
Pages:
Jump to: