Index  | Recent Threads  | Unanswered Threads  | Who's Active  | Guidelines  | Search
 

Quick Go ยป
No member browsing this thread
Thread Status: Active
Total posts in this thread: 14598
Posts: 14598   Pages: 1460   [ Previous Page | 279 280 281 282 283 284 285 286 287 288 | Next Page ]
[ Jump to Last Post ]
Post new Thread
Author
Previous Thread This topic has been viewed 2029632 times and has 14597 replies Next Thread
jonnieb-uk
Ace Cruncher
England
Joined: Nov 30, 2011
Post Count: 6105
Status: Offline
Project Badges:
Reply to this Post  Reply with Quote 
In Other News

jhindo Mar 13, 2014 8:26:08 PM
We have found that a few of our members have unexpectedly had their team choice changed to the "Ripple Labs" team. After investigating this, we can confirm that there was no break-in to World Community Grid and users' devices were in no way compromised.

We have identified a computer that was trying combinations of user names and common passwords against our website in an attempt to find combinations that worked. This activity began on March 11, 2014 and successfully guessed the passwords of a few of our volunteers. It appears that users whose passwords were guessed had their account's team choice changed to the "Ripple Labs" team but were otherwise left unmodified. Within 36 hours of the attack, this computer was blocked. We have been monitoring our systems closely for similar attempts. We will notify all members who joined the Ripple Lab team since this began and ask them to confirm their intention to be on that team.

We take security very seriously and follow industry best practices to best protect our users. We will continue to use best practices to block such password-guessing attempts. We will also conduct a complete review of other aspects of account and password management and determine what, if any, additional changes should be made there.

We are sorry to see that this happened to a few of our members. To avoid this kind of problem in the future, we strongly advise all users to adopt the best practice of selecting passwords that are not trivial or common. Avoid using short passwords and those containing simple words, obvious number, letter or keyboard sequences. You can see examples of weak passwords that should be avoided here: http://boingboing.net/2013/12/07/worst-passwords.html. We also advise that you avoid using the same password across multiple sites.

Great that it's been sorted by the tech team. Plaudits all round biggrin biggrin hugs hugs applause applause

So it's been resolved. Nothing sophisticated just old fashioned password cracking. Nothing new to be learnt by those involved in the attempt. But at the moment informing the members (other than those few members directly affected) consists of a post in the middle of a forum thread. No special announcement, no News item etc. So much for WCG's vaunted new Communications policy. d oh

It seems to me that since this happened to [just] a few of our members the policy is we won't tell anyone else and it will all be forgotten.

Maybe I'm wrong in which case I'll retract the post. Time will tell.
----------------------------------------

To Join follow this link: Join the UK Team All Welcome! UK Team thread
----------------------------------------
[Edit 1 times, last edit by jonnieb-uk at Mar 13, 2014 10:28:09 PM]
[Mar 13, 2014 9:58:27 PM]   Link   Report threatening or abusive post: please login first  Go to top 
genhos
Veteran Cruncher
UK
Joined: Apr 26, 2009
Post Count: 1103
Status: Offline
Project Badges:
Reply to this Post  Reply with Quote 
Re: In Other News

Welcome back TMC.

On the face of it, Joe87, that mobo looks pretty good to me but I'm no expert. My dad's computer is a 6core AMD running at around 3.2ghz and crunches through nicely, think it's a FX6300 (rings a bell in me ol' brain cell) Black Edition but not sure.
----------------------------------------
[Mar 13, 2014 11:03:37 PM]   Link   Report threatening or abusive post: please login first  Go to top 
Former Member
Cruncher
Joined: May 22, 2018
Post Count: 0
Status: Offline
Reply to this Post  Reply with Quote 
Re: In Other News

Sounds ok - if nothing else, put your password in brackets, maybe put an exclamation mark at the front, an underscore at the end, replace 'a' with '@', 'i' with '1' etc, or use a multitude of random password generators to create a 32 character random string and store it in a multitude of password lockers so you don't have to remember it.

Excellent work by the admins byw, as always.

More importantly though, welcome back tmc - great to have you back.
[Mar 13, 2014 11:52:52 PM]   Link   Report threatening or abusive post: please login first  Go to top 
Thargor
Veteran Cruncher
UK
Joined: Feb 3, 2012
Post Count: 1291
Status: Offline
Project Badges:
Reply to this Post  Reply with Quote 
Re: In Other News

Sounds ok - if nothing else, put your password in brackets, maybe put an exclamation mark at the front, an underscore at the end, replace 'a' with '@', 'i' with '1' etc, or use a multitude of random password generators to create a 32 character random string and store it in a multitude of password lockers so you don't have to remember it.

Except WCG only supports alphanumeric-only passwords up to 15 characters long! sad
----------------------------------------

[Mar 14, 2014 12:06:16 AM]   Link   Report threatening or abusive post: please login first  Go to top 
Former Member
Cruncher
Joined: May 22, 2018
Post Count: 0
Status: Offline
Reply to this Post  Reply with Quote 
Re: In Other News

I guess that explains why we're all getting hacked.

So, use a 15 character random string without brackets, '@'s, '!'s etc.

I stand by my tmc comment though ๐Ÿ˜Š.
[Mar 14, 2014 12:59:28 AM]   Link   Report threatening or abusive post: please login first  Go to top 
Former Member
Cruncher
Joined: May 22, 2018
Post Count: 0
Status: Offline
Reply to this Post  Reply with Quote 
Re: In Other News

Mornin.................. biggrin
[Mar 14, 2014 6:16:40 AM]   Link   Report threatening or abusive post: please login first  Go to top 
Former Member
Cruncher
Joined: May 22, 2018
Post Count: 0
Status: Offline
Reply to this Post  Reply with Quote 
Re: In Other News

Windows Updates are in the wild.........................! biggrin
[Mar 14, 2014 7:51:08 AM]   Link   Report threatening or abusive post: please login first  Go to top 
Barnsley_Tatts
Senior Cruncher
Joined: Nov 3, 2005
Post Count: 283
Status: Offline
Project Badges:
Reply to this Post  Reply with Quote 
Re: In Other News

jhindo Mar 13, 2014 8:26:08 PM
We have found that a few of our members have unexpectedly had their team choice changed to the "Ripple Labs" team. After investigating this, we can confirm that there was no break-in to World Community Grid and users' devices were in no way compromised.

We have identified a computer that was trying combinations of user names and common passwords against our website in an attempt to find combinations that worked. This activity began on March 11, 2014 and successfully guessed the passwords of a few of our volunteers. It appears that users whose passwords were guessed had their account's team choice changed to the "Ripple Labs" team but were otherwise left unmodified. Within 36 hours of the attack, this computer was blocked. We have been monitoring our systems closely for similar attempts. We will notify all members who joined the Ripple Lab team since this began and ask them to confirm their intention to be on that team.

We take security very seriously and follow industry best practices to best protect our users. We will continue to use best practices to block such password-guessing attempts. We will also conduct a complete review of other aspects of account and password management and determine what, if any, additional changes should be made there.

We are sorry to see that this happened to a few of our members. To avoid this kind of problem in the future, we strongly advise all users to adopt the best practice of selecting passwords that are not trivial or common. Avoid using short passwords and those containing simple words, obvious number, letter or keyboard sequences. You can see examples of weak passwords that should be avoided here: http://boingboing.net/2013/12/07/worst-passwords.html. We also advise that you avoid using the same password across multiple sites.

Great that it's been sorted by the tech team. Plaudits all round biggrin biggrin hugs hugs applause applause

So it's been resolved. Nothing sophisticated just old fashioned password cracking. Nothing new to be learnt by those involved in the attempt. But at the moment informing the members (other than those few members directly affected) consists of a post in the middle of a forum thread. No special announcement, no News item etc. So much for WCG's vaunted new Communications policy. d oh

It seems to me that since this happened to [just] a few of our members the policy is we won't tell anyone else and it will all be forgotten.

Maybe I'm wrong in which case I'll retract the post. Time will tell.


So.... It's my own fault really for having a weak password? I used the same pw when I first signed up to Seti back in 1999, then the same one when I signed up to United Devices in 2003. Never had a problem for 15 years until Ripple came along. Hmmm......
----------------------------------------

[Mar 14, 2014 8:31:47 AM]   Link   Report threatening or abusive post: please login first  Go to top 
jonnieb-uk
Ace Cruncher
England
Joined: Nov 30, 2011
Post Count: 6105
Status: Offline
Project Badges:
Reply to this Post  Reply with Quote 
Morning Update

Congratulations to the following UK team members on achieving a Personal Milestone in yesterday's crunching: biggrin hugs

Steven Langston 12 years RunTime
Joe87 moves into the UK top 400 RunTime Rankings at #398
mike@oberon 13,000,000 Points
barrie.trevena moves into the UK top 250 Results Rankings at #250

Congratulations also to the following UK team members on setting new PBs biggrin hugs
	Steven Langston  	Runtime	12:17:08:50	Points	        	Results		
DaveSchofield Runtime 2:01:55:54 Points Results
Peter2004 Runtime Points 33,406 Results
Tom.tamplint Runtime Points Results 4

UK team - Individual Ranking Movements
					        
RunTime Points Results
oz_mingus up 1 place to 44 Peter2004 up 1 place to 68 Clockwork up 1 place to 110
aldude52 up 1 place to 96 l3xs up 1 place to 100 adjordan up 1 place to 187
Peter2004 up 2 places to 117 Animusintorq up 1 place to 147 mulliada up 3 places to 226
Drus up 1 place to 155 mulliada up 2 places to 163 stephen.g.hu up 2 places to 234
tuseef up 1 place to 165 Matthew674 up 1 place to 302 barrie.treve up 1 place to 250
datahelp up 1 place to 213 Joe87 up 2 places to 369 cmcmanus up 1 place to 254
mulliada up 6 places to 245 Tom.tamplint up 2 places to 378 Joe87 up 4 places to 380
cmcmanus up 3 places to 269 Tom.tamplint up 6 places to 424
stephen.g.hu up 2 places to 271
tomwklynn up 1 place to 274
adjordan up 3 places to 285
Joe87 up 6 places to 398
isandunk down 1 place to 286 adjordan down 1 place to 165 Animusintorq down 1 place to 188
isandunk down 1 place to 148

UK team Comparison of Daily RunTime, Points, Results
			                          	Hours		Points		      Results	
Yesterday's Production 0:325:03:51:10 sick 7,803 1,305,456 1,796
Average per cd
March 327.2 sick 7,848 1,272,428 1,713
February 355.7 8,520 1,407,471 1,877
January 346.0 8,304 1,326,007 1,655

Average Daily Crunching Comparison
         	RunTime			Points		        	        Results		
14-Mar 13-Mar +/- 14-Mar 13-Mar +/- 14-Mar 13-Mar +/-
7day Avg 305.07 308.08 -3.01 1,158,777 1,158,718 59 1,698 1,705 -7
14day Avg 335.87 338.70 -2.82 1,322,333 1,340,835 -18,502 1,684 1,677 7
28day Avg 344.72 347.18 -2.45 1,371,659 1,382,598 -10,940 1,819 1,834 -15

Milestone Targets for the UK team
	       	Target   		Current  	To Do    	7day Avg.	  Estimate	
RunTime 1,250 years 441,577 14,673 305.1 48 days May-01-2014
Points 1,750,000,000 1,515,369,286 234,630,714 1,158,777 202 days Oct-02-2014
Results 3,500,000 3,093,705 406,295 1,698 239 days Nov-08-2014

No. Of Members Active Yesterday
       					        Day	        out of	 Tot.	
Total 68 ,, ,, 108
Group 1 23 ,, ,, 24
Group 2 14 ,, ,, 15
Group 3 18 ,, ,, 26
Group 4 3 ,, ,, 10
InAct New 3 ,, ,, 9
InActive 0 ,, ,, 16
New/Restart 7 ,, ,, 8

----------------------------------------

To Join follow this link: Join the UK Team All Welcome! UK Team thread
[Mar 14, 2014 9:06:42 AM]   Link   Report threatening or abusive post: please login first  Go to top 
jonnieb-uk
Ace Cruncher
England
Joined: Nov 30, 2011
Post Count: 6105
Status: Offline
Project Badges:
Reply to this Post  Reply with Quote 
Morning Update II

Daily Global5000
    		         RT(days)  #			Points 	     #		     Results	     #	
1 GrumpyCat 30.4 886 Soong 136,381 719 crooks_uk 207 658
2 Soong 25.8 1,072 GrumpyCat 114,459 879 Soong 151 950
3 crooks_uk 21.9 1,279 crooks_uk 101,152 1,032 GrumpyCat 143 1,009
4 Thargor 21.4 1,315 arkangath 93,744 1,120 Scribe 114 1,311
5 arkangath 19.9 1,427 Mike D Green 70,797 1,564 fosking 111 1,351
6 Mike D Green 17.3 1,693 fosking 60,731 1,907 arkangath 106 1,433
7 RTS48 16.2 1,829 RTS48 59,242 1,961 Mike D Green 94 1,667
8 Scribe 13.5 2,266 Scribe 57,379 2,040 RTS48 89 1,775
9 Steven Langs 12.7 2,424 Thargor 57,014 2,063 djerram 70 2,407
10 fosking 12.5 2,460 stroudwaterb 46,188 2,699 stroudwaterb 54 3,333
11 stroudwaterb 12.3 2,511 djerram 38,508 3,431 Steven Langs 53 3,420
12 Ian_UK 10.9 2,893 Steven Langs 36,597 3,673 Thargor 52 3,513
13 Labinopper 8.0 4,284 Peter2004 33,406 4,108 Peter2004 48 3,874
14 djerram 7.8 4,398 Labinopper 31,071 4,462
15 Ian_UK 30,511 4,572

The Daily Global5000 accounted for 78.1% of yesterdays RunTime of 797.5 years
----------------------------------------

To Join follow this link: Join the UK Team All Welcome! UK Team thread
[Mar 14, 2014 9:10:45 AM]   Link   Report threatening or abusive post: please login first  Go to top 
Posts: 14598   Pages: 1460   [ Previous Page | 279 280 281 282 283 284 285 286 287 288 | Next Page ]
[ Jump to Last Post ]
Post new Thread