| Index | Recent Threads | Unanswered Threads | Who's Active | Guidelines | Search |
| World Community Grid Forums
|
| No member browsing this thread |
|
Thread Status: Active Total posts in this thread: 46
|
|
| Author |
|
|
twilyth
Master Cruncher US Joined: Mar 30, 2007 Post Count: 2130 Status: Offline Project Badges:
|
Keith: I don't think Ripple is going to be too concerned with WCG accts getting hacked. People over on the Ripple Forum are already a little displeased about the lack of response some there see on the part of Ripple to technical issues.
----------------------------------------Anyway, it's not really an issue as long as people have access to their own accts and can change the password. The only time it might become an issue is if someone decides at some point to change team affiliation for the purpose of earning XRPs. Then it will depend on whether or not the association between your WCG id and whatever Ripple wallet a hacker created to receive those XRP's is permanent or not. I thought it was but at least one other poster here claims it isn't. It should be simple enough to test though if anyone is interested. ![]() ![]() |
||
|
|
twilyth
Master Cruncher US Joined: Mar 30, 2007 Post Count: 2130 Status: Offline Project Badges:
|
What worries me more is all of the people who don't really pay attention to their stats or team affiliation, which is probably most of them. It will be interesting to see what the WCG staff uncovers and if they deem it appropriate to do a mass email alerting people to the possibility and implications.
----------------------------------------![]() ![]() |
||
|
|
Former Member
Cruncher Joined: May 22, 2018 Post Count: 0 Status: Offline |
What worries me more is all of the people who don't really pay attention to their stats or team affiliation, which is probably most of them. It will be interesting to see what the WCG staff uncovers and if they deem it appropriate to do a mass email alerting people to the possibility and implications. Getting yourself a signature with a team indication is one step.........but..................if you do not even bother to post on the forums then even that is no help ![]() |
||
|
|
branjo
Master Cruncher Slovakia Joined: Jun 29, 2012 Post Count: 1892 Status: Offline Project Badges:
|
jonnieb-uk wrote: What's the source of your info branjo The /boinc/stats/user.gz file produced at 18:12UTC shows him as XtremeSystems and the Ripple Labs member status shows him as retired. IDK jonnieb, it was probably sorted by name. Because when I clicked the link provided by Scribe, the top 2 records were "99hawk from XS to RL" and "99hawk from RL to XS" I am sorry for pressing the panic button Cheers ![]() ![]() Crunching@Home since January 13 2000. Shrubbing@Home since January 5 2006 ![]() [Edit 2 times, last edit by branjo at Mar 13, 2014 11:05:34 AM] |
||
|
|
jonnieb-uk
Ace Cruncher England Joined: Nov 30, 2011 Post Count: 6105 Status: Offline Project Badges:
|
Until we hear from WCG speoulation about the cause of these involuntary team movements is just that - speculation.
----------------------------------------As I posted yesterday Anything that disturbs user confidence in the security and integrity of WCG is worrying. WCG have said they are investigating which is good. Further updates would be helpful in maintaining user confidence but I suspect WCG will want to dot all the i's and cross all the t's before we are told anything more. |
||
|
|
Former Member
Cruncher Joined: May 22, 2018 Post Count: 0 Status: Offline |
IF password hacking is (part of) the cause of what is being discussed here, then it is likely that a contributing factor would be whether or not the WCG systems make it possible to try a dictionary attack or not. If the systems already, or could be changed to, either disable access to an account after a fixed number of failed attempts, or if the systems were set to respond exponentially slower to each subsequent failed attempt, then this avenue would be closed.
It's not rocket science, but I have no idea if these systems work this way. |
||
|
|
jhindo
Former World Community Grid Admin Joined: Aug 25, 2009 Post Count: 250 Status: Offline Project Badges:
|
We have found that a few of our members have unexpectedly had their team choice changed to the "Ripple Labs" team. After investigating this, we can confirm that there was no break-in to World Community Grid and users' devices were in no way compromised.
We have identified a computer that was trying combinations of user names and common passwords against our website in an attempt to find combinations that worked. This activity began on March 11, 2014 and successfully guessed the passwords of a few of our volunteers. It appears that users whose passwords were guessed had their account's team choice changed to the "Ripple Labs" team but were otherwise left unmodified. Within 36 hours of the attack, this computer was blocked. We have been monitoring our systems closely for similar attempts. We will notify all members who joined the Ripple Lab team since this began and ask them to confirm their intention to be on that team. We take security very seriously and follow industry best practices to best protect our users. We will continue to use best practices to block such password-guessing attempts. We will also conduct a complete review of other aspects of account and password management and determine what, if any, additional changes should be made there. We are sorry to see that this happened to a few of our members. To avoid this kind of problem in the future, we strongly advise all users to adopt the best practice of selecting passwords that are not trivial or common. Avoid using short passwords and those containing simple words, obvious number, letter or keyboard sequences. You can see examples of weak passwords that should be avoided here: http://boingboing.net/2013/12/07/worst-passwords.html. We also advise that you avoid using the same password across multiple sites. |
||
|
|
Falconet
Master Cruncher Portugal Joined: Mar 9, 2009 Post Count: 3315 Status: Offline Project Badges:
|
Thanks jhindo,
----------------------------------------Any chance you could send the IP address and other data of that computer to the authorities? ![]() - AMD Ryzen 5 1600AF 6C/12T 3.2 GHz - 85W - AMD Ryzen 5 2500U 4C/8T 2.0 GHz - 28W - AMD Ryzen 7 7730U 8C/16T 3.0 GHz |
||
|
|
twilyth
Master Cruncher US Joined: Mar 30, 2007 Post Count: 2130 Status: Offline Project Badges:
|
It might be a good idea to enforce certain minimum strength criteria for password changes.
----------------------------------------Monitoring accts that change to the Ripple Teams might be adequate in the short term but if history has shown us anything it's how resourceful hackers can be. So a mass mailing alerting people of the issue might be a good idea as well, but only after password strength criteria are in place. ![]() ![]() |
||
|
|
AgrFan
Senior Cruncher USA Joined: Apr 17, 2008 Post Count: 396 Status: Offline Project Badges:
|
jhindo, please relay my appreciation to everyone involved in finding the root cause and resolution for this issue.
----------------------------------------Kudos to the WCG staff ... THANKS!!! My team did not change today so all looks to be back to normal ![]()
[Edit 1 times, last edit by AgrFan at Mar 14, 2014 12:10:51 AM] |
||
|
|
|