• Ever wanted an RSS feed of all your favorite gaming news sites? Go check out our new Gaming Headlines feed! Read more about it here.
  • We have made minor adjustments to how the search bar works on ResetEra. You can read about the changes here.

TI92

Alt account
Banned
Oct 25, 2017
5,598
Just had an IP from Brazil try to log into my GOG account, just an FYI for everyone to turn on two factor and potentially change your passwords.
 

Deleted member 9237

User requested account closure
Banned
Oct 26, 2017
1,789
This is a bit premature don't you think?

I wouldn't worry until GOG issues a statement. Attacks on individuals happens all the time.
 

MattB

Avenger
Oct 25, 2017
2,904
Just had an IP from Brazil try to log into my GOG account, just an FYI for everyone to turn on two factor and potentially change your passwords.
That honestly doesn't mean anything on there end. Could be any site that you use that same email with and someone tried it on gog.
 
Oct 27, 2017
42,700
I always wonder why these password leaks are so damaging. Surely these services aren't storing plain text passwords in their DB, are they? Because having access to a salted hash of a password should be almost useless
 

dom

â–˛ Legend â–˛
Avenger
Oct 25, 2017
10,453
I don't think it was GOG. Someone tried to log into my gamestop account. For sure a new large database was released though. Looks like some are trying to log into gaming affiliated sites.
 

Agent_Tiro

Member
Oct 26, 2017
49
I always wonder why these password leaks are so damaging. Surely these services aren't storing plain text passwords in their DB, are they? Because having access to a salted hash of a password should be almost useless

Hashes can be cracked. Lots of free software out there that can do it. Only problem will be processing power.
 

dickroach

Self-Requested Ban
Banned
Oct 25, 2017
953
no email here, but regardless i just logged in to change my password, and saw I have 2FA enabled. :\
 

Al3x1s

Banned
Nov 13, 2017
2,824
Greece
www.gog.com best place for DRM-free games :)

It used to be mean good old games because they mostly re-released old games like say, Wing Commander or System Shock but these days they get most any game as long as the publisher doesn't mind removing DRM (so, AAA games not so much, but everything else, like PC strategy games, indie games, etc).
 

Fjordson

Member
Oct 25, 2017
5,010
I got that yesterday as well, said it was a Brazilian IP.

Thankfully had 2FA on, but went in and changed my password.
 

GaimeGuy

Banned
Oct 25, 2017
5,092
I always wonder why these password leaks are so damaging. Surely these services aren't storing plain text passwords in their DB, are they? Because having access to a salted hash of a password should be almost useless
In a dictionary attack, a password dictionary is run through a hashing algorithm and compared to the list of
hashed pws
 

Robin Hood

Member
Oct 27, 2017
136
Yupp, got an email about someone attempting to log in from Brazil. Luckily I had 2 step authentification set up via email already.


OS:
Other
Browser:
Other
Estimated location:
Brazil, Rio de Janeiro
 

Gabora

Member
Oct 25, 2017
3,071
Sao Paulo, Brazil
whenever I try to change my password or log in (logged out after I couldn't change my password) the tab crashes, something is definitely going on

Edit: signed in on chrome and changed my pass
 

Tawney Bomb

Avenger
Oct 25, 2017
1,346
Ohio
I got one earlier, glad I had 2FA setup.

Just had someone log into my deactivated Facebook account a few weeks ago too.
 
Oct 27, 2017
42,700
In a dictionary attack, a password dictionary is run through a hashing algorithm and compared to the list of
hashed pws
Isn't that only effective if people use common words/phrases as passwords AND no salting or random manipulation is done to them before storing? I know Slack, for instance, has salting done on a per-password basis
 

Deleted member 11517

User requested account closure
Banned
Oct 27, 2017
4,260
Honestly, for things that you pay for with actual money I never understand why not just everyone gets their own personal email address so they could always prove ownership, say with their passport or similar, as it is now all that really needs to happen is someone getting access to your email and potentially thousands upon thousands dollars or whatever are lost.

How it is now isn't really secure 2fa or not, if you lose access to your email or phone it's pretty much useless, isn't it?
 

ArchAngel

Avenger
Oct 25, 2017
1,475
Didn't get any email yet, but I have 2FA active and just changed my password. Thanks for the info!
 

Pizza Dog

Avenger
Oct 25, 2017
1,477
Happened to me too, had an attempted logon from Brazil the other day and got the email because of the two factor authentication I didn't even remember having turned on, good thing I did. Everyone should change their passwords and enable 2FA as a precaution.
 

Kilbane65

Member
Oct 27, 2017
1,460
Makes me wonder why would anyone bother to break into someone else's GOG account. All their games are DRM free and could probably be found on torrent sites with considerable less effort than what would take to break a bunch of hashed passwords.
 
OP
OP
TI92

TI92

Alt account
Banned
Oct 25, 2017
5,598
Yeah, they were able to guess my password correctly. It was one of the last few sites I hadn't changed my generic password to a random 16 character string yet so makes sense it would be easy for them to get.

But just sharing so everyone is able to change theirs
 

Deleted member 11986

User requested account closure
Member
Oct 27, 2017
1,040
It' year's end, folk. By definition it's the time it increases hackers attacks. Just remove any potencial credit card info you have in any form of online store. Hackers gotta pay for their psn/ xbox live cards with your credit cards.
 

Saoshyant

Member
Oct 25, 2017
1,996
Portugal
I didn't receive an email, but as it turns out my 2FA was disabled. I immediatelly enabled it, inserted the code that was sent to my email, got a confirnation that it was enabled, then reloaded my settings page just find out it was disabled again. Did this song and dance one more time, result, 2FA currently disabled with me trying to enable it at a time a massive hack is ongoing. Good job, GOG.

Makes me wonder why would anyone bother to break into someone else's GOG account. All their games are DRM free and could probably be found on torrent sites with considerable less effort than what would take to break a bunch of hashed passwords.

They aren't breaking into people's accounts to play their game collection. The intention is very likely the same as PSN hacks: account reselling to a target audience that doesn't know better.
 

thediamondage

Member
Oct 25, 2017
11,277
Good time to remind everyone they should be using some sort of password database, whether its KeePass or 1Pass or LastPass or whatever, that lets you have an entry for every single website with its own database entry of username, password, email, secret Q&A, pin, etc. The program/site should let you generate unique passwords for every site and quickly get to them when needed. The database itself should be password protected since its a single point of vulnerability for all your information. Any gmails you use should have 2FA enabled via your phone/etc so hackers can't bypass a lot of security by simply hacking into your email.

I've used KeePass for years, have 400+ entries in it for pretty much everything in my life, and keep the database backed up to google drive and OneDrive but also have a strong password protecting the db itself. Its on my phone as well and I have thumb drives with the KDX file that I keept at the bank at at my parents bank (cross country) in case of natural disaster.

Your digital "identity" is the most valuable thing you have nowadays between banks, stocks, credit cards, etc.