Index  | Recent Threads  | Unanswered Threads  | Who's Active  | Guidelines  | Search
 

Quick Go »
No member browsing this thread
Thread Status: Active
Total posts in this thread: 18
Posts: 18   Pages: 2   [ Previous Page | 1 2 ]
[ Jump to Last Post ]
Post new Thread
Author
Previous Thread This topic has been viewed 5667 times and has 17 replies Next Thread
twilyth
Master Cruncher
US
Joined: Mar 30, 2007
Post Count: 2130
Status: Offline
Project Badges:
Reply to this Post  Reply with Quote 
Re: "no one has 'hacked' me, until Ripple came along"

fitze: I agree. The word was just starting to get out when Ripple killed Computing for Good. Of course my "conspiracy theory" on this is that WCG didn't want to take the responsibility for accounts getting hacked, especially since they know as well as we do that people re-use passwords and a hacked account on WCG could lead to other more serious breaches for those people. So from WCG's perspective as well as the 85% of people here who never participated in the XRP giveaway, I'm sure the attitude is 'good riddance.'

As an admin at other sites though, perhaps you could explain to the staff at WCG just how easy it is to institute a policy of notifying people when multiple invalid password attempts have been made. I'm sure they would like us to believe it would require too much effort for them to provide this elemental form of account security. Perhaps you can convince them otherwise.
----------------------------------------


[Apr 24, 2014 9:08:24 PM]   Link   Report threatening or abusive post: please login first  Go to top 
jhindo
Former World Community Grid Admin
Joined: Aug 25, 2009
Post Count: 250
Status: Offline
Project Badges:
Reply to this Post  Reply with Quote 
Re: "no one has 'hacked' me, until Ripple came along"

Since the brute force attack, we have implemented additional security measures, ones which I can't discuss, and are currently implementing further security features - those we will be communicating with our members once they're ready. I'm sure you can understand that in certain cases, we can't disclose full details, as such details could help potential hackers.
[Apr 30, 2014 1:52:45 PM]   Link   Report threatening or abusive post: please login first  Go to top 
Former Member
Cruncher
Joined: May 22, 2018
Post Count: 0
Status: Offline
Reply to this Post  Reply with Quote 
Re: "no one has 'hacked' me, until Ripple came along"

twilyth:

I ran a very old script, so I don't know if this is correct.

It looks like WCG is:

IBM Canada, I think near Toronto. Hosted by AT&T, Running Linux with IBM HTTP Server, Apache, Apache Jakarta,Java Servlet, vaScript, jQuery, CSS, RSS and Doctype is HTML5.

So if this is close to what they are running they can notifying people when multiple invalid password attempts with a email. The code is availible free using Open Source Software code, but why do it, if the person like I said is that stupid with a bad password they should be hacked.

twilyth, the post after you from jhindo said it was a brute force attack (old school) the log files will show that and the alarms should have gone off. They should have put monkey in the middle code for a quick stop of brute force attack, but it was just ONE person :-).

Thank you for the good laugh "Perhaps you can convince them otherwise" You do not tell IBM what to do, they tell you what to do.

jhindo:

Good forward motion implementing additional security measures.

So it was a old school brute force dictionary attack from ONE person, now that is good security laugh, ONE PERSON!

I say it was someone/group that did not like Rippple Labs because RL would soon be #1 on all Team Statistics in less then one year! They did research in months what other teams are taking years to do for research and the other teams don't like it!.

Also your log files should show the IP address of the brute force and you should know who it was! don't you think?

Later, going to the Pub to buy some fish and chips and pay with my Ripples, will let me? :-)

HELL NO!
[May 7, 2014 12:38:49 AM]   Link   Report threatening or abusive post: please login first  Go to top 
twilyth
Master Cruncher
US
Joined: Mar 30, 2007
Post Count: 2130
Status: Offline
Project Badges:
Reply to this Post  Reply with Quote 
Re: "no one has 'hacked' me, until Ripple came along"

Thanks fitze. I didn't notice jhindo's post until just now. I try to keep up with the forum but I guess a few get by me from time to time.

Thanks for that information about WCG's setup. If you can get all of that just from running a script it's a little strange they can't just tell us these things. Anyway, thanks again.

I think they originally said it was a dictionary attack - more or less the same thing.

Have a round for me. Cheers! wink
----------------------------------------


[May 7, 2014 5:23:03 AM]   Link   Report threatening or abusive post: please login first  Go to top 
Barnsley_Tatts
Senior Cruncher
Joined: Nov 3, 2005
Post Count: 291
Status: Offline
Project Badges:
Reply to this Post  Reply with Quote 
Re: "no one has 'hacked' me, until Ripple came along"



So please don't say "until Ripple came along"



Sadly, it's true. I started in 1999 with SETI, moved to United Devices/Grid/WCG in 2003, and used the same password, and I've never had an issue. It was a simple password, as I wasn't really bothered if someone did compromise it, it wasn't worth anything anyway.

Ripple arrived, and a Ripple member had a go at my account, and was successful. Fortunately I checked the team forum, and our resident Stat-Meister alerted me to the fact my team had changed. I obviously changed it back.

So, after 14 years Ripple arrive, someone from Team Ripple cracks my account and you don't want me to say "until Ripple came along"? Sorry, the facts dictate otherwise.
----------------------------------------

[May 7, 2014 10:24:56 AM]   Link   Report threatening or abusive post: please login first  Go to top 
jhindo
Former World Community Grid Admin
Joined: Aug 25, 2009
Post Count: 250
Status: Offline
Project Badges:
Reply to this Post  Reply with Quote 
Re: "no one has 'hacked' me, until Ripple came along"

As I mentioned in my last post in this thread, we were working on implementing additional security measures.

Included in today's website release is a new feature to help members keep accounts secure. From now on, any time your email address, password, team affiliation or member name is changed, we will email you to notify you, giving you an opportunity to quickly identify and reverse any changes not initiated by you.

We encourage members to ensure the email address in their profile is up to date to make the most of this feature.
[May 29, 2014 9:03:59 PM]   Link   Report threatening or abusive post: please login first  Go to top 
yoro42
Ace Cruncher
United States
Joined: Feb 19, 2011
Post Count: 8979
Status: Offline
Project Badges:
Reply to this Post  Reply with Quote 
Re: "no one has 'hacked' me, until Ripple came along"

Thank you for the update and notification.
----------------------------------------

[May 29, 2014 9:24:13 PM]   Link   Report threatening or abusive post: please login first  Go to top 
yoro42
Ace Cruncher
United States
Joined: Feb 19, 2011
Post Count: 8979
Status: Offline
Project Badges:
Reply to this Post  Reply with Quote 
Re: "no one has 'hacked' me, until Ripple came along"

Thank you for the update and notification.

My previous comment was quite an understatement. Impressive work and implementation.

Thanks to all involved,

yoro42
----------------------------------------

[May 29, 2014 9:37:18 PM]   Link   Report threatening or abusive post: please login first  Go to top 
Posts: 18   Pages: 2   [ Previous Page | 1 2 ]
[ Jump to Last Post ]
Post new Thread