Announcement

Collapse
No announcement yet.

Ubuntu Forums hacked

Collapse
This topic is closed.
X
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    #46
    Originally posted by Snowhog View Post
    ...A good practice (enforced by (all) U.S. Government agencies) is to require password changes at set intervals. Not changing your password results in suspension of the account.
    I have never met someone who didn't just have 2 numbers in their password for the month when that is required, thus making it a less safe password. I absolutely hate those policies. You either end up with the above, or passwords written down on a post-it, usually stuck to the monitor.

    Comment


      #47
      Enter "Keepassx" or some facsimile.
      Boot Info Script

      Comment


        #48
        Originally posted by claydoh View Post
        man people are getting pissy over on UF trying to log in, etc. Seems they direct people to "ubuntu one" - which is using their Single Sign-On system (SSO) which is used for Launchpad, the wikis, etc, including U1. SO some are thinking they are being forced to sign up for U! ... This is a classic tl;dr as this was clearly explained on the main page. Having said that, going to login.ubuntu.com makes it look like you are signing up for U1 (and in a sense you are)
        Yes, the description could be better. You're really using your Ubuntu SSO account here, which just so happens to be used for Launchpad, Ubuntu Wiki, and Ubuntu One. Now they're adding the forum. Makes sense, really.

        But the amount of stupid on display in the discussion is breathtaking. People are claiming the forum was hacked, that vBulletin is unsafe, that a subsequent vB hack would give the attacker access to credit card numbers in U1. Come on, Ubuntu forum people! Didn't you read the explanation? The "hack" was through an existing but forgotten administrator account. The only "vulnerability" here is human forgetfulness.

        Comment


          #49
          I think I'll wait until the dust settles before I post anything over there.
          Kubuntu 22.04 (desktop & laptop), Windows 7 &2K (via VirtualBox on desktop PC)
          ================================

          Comment


            #50
            I've been posting all day long....no dust...clean as a whistle...spic & span, as they say.
            I'm just trying to help those that have been in the dark for the past two weeks. Lots of posted issues already.
            Boot Info Script

            Comment


              #51
              Originally posted by SteveRiley View Post
              Didn't you read the explanation? The "hack" was through an existing but forgotten administrator account. The only "vulnerability" here is human forgetfulness.
              Here's a detailed description of the attack (http://blog.canonical.com/2013/07/30...a-post-mortem/).

              While the compromised mod account was the root cause...those sort of things do happen, so they probably should have been more prepared for it. An actually some vbulletin defaults played a part.

              Comment


                #52
                Originally posted by claydoh View Post
                This is a classic tl;dr as this was clearly explained on the main page. Having said that, going to login.ubuntu.com makes it look like you are signing up for U1 (and in a sense you are)
                I can't believe the number of disgruntled users that must have read the warning after they logged-in with an email address that was not registered at UF and found that they had created a new account. So many complaints about years of posting history lost and so many users seem to be criticising UF/Canonical for not keeping their data safe but have little idea as to what that data actually is.

                I certainly would not want to be a UF administrator right now.

                Originally posted by claydoh View Post
                And gee, that theme is still garish.
                But they are Canonical approved colours though.

                Comment


                  #53
                  I just tried logging in and it won't accept either of my email addresses. So I tried registering and got the same thing. So, I guess I don't register. It's no biggie, I only get to those forums via google searches anyway.
                  I do not personally use Kubuntu, but I'm the tech support for my daughter who does.

                  Comment


                    #54
                    Originally posted by Buddlespit View Post
                    I just tried logging in and it won't accept either of my email addresses. So I tried registering and got the same thing. So, I guess I don't register. It's no biggie, I only get to those forums via google searches anyway.
                    You could try contacting them. I just tried to login and my old one would not work, but I was able to re-register.

                    Edit:
                    You did create a matching account at Ubuntu One, right? They're requiring that now.

                    I'm back in there. I had saved links to all the posts I made there before. I tried them and they're there. Looks like they did their backing up. Hopefully the entire database of posts is there. It would be a shame if all that were lost.
                    Last edited by Tom_ZeCat; Aug 01, 2013, 06:04 AM.
                    Kubuntu 22.04 (desktop & laptop), Windows 7 &2K (via VirtualBox on desktop PC)
                    ================================

                    Comment


                      #55
                      I already have a Ubuntu One account, so I did not have any problems. Had LastPass generate a new password for the site. I too, do not visit that forum often, usually as a result of a Startpage search, but if you want to post to a thread, you must be logged in.

                      Comment

                      Working...
                      X