2.5 Million Xbox and PlayStation Gamers' Details Have Been Leaked From Piracy Forums (thenextweb.com)
Xbox360ISO.com and PSPISO.com have been hacked by an unknown attacker in late 2015 and the details of the 2.5 million users affected have been leaked online. The leaked information contains email addresses, IP addresses, usernames and passwords. The Next Web reports: It seems that the operator of these sites did nothing to protect the latter, as all passwords were "protected" using the MD5 hashing system, which is trivially easy to overcome. For reference, that's the same hashing system used by LinkedIn. As the names of these sites imply, they were used to share pirated copies of games for Microsoft and Sony's gaming platforms. They also both have a thriving community where people discussed a variety of tech-related topics, including gaming news and software development. If you think you might have had an account on these sites at one point, and want to check if you were affected, you can visit Troy Hunt's Have I Been Pwned. If you have, it's worth emphasizing that anyone who gained access to that site, and anyone who has since downloaded the data dump, will be able to discern your password. If you've used it on another website or platform, you should change it.
From this totally wholesome-on-the-up-and-up site. Color me surprised. This is why we use throw away email addys for this sort of thing kids.
You are being ripped off every second of every day, so that advertisers can help rip you off even more tomorrow.
It took me to the "Have I been Pwned?" site
NONONONONONONONONONONONONO!!!!! Do not fucking do this Slashdot! This is not funny! This is not appropriate. You want to take me to another website after clicking on white space? What the sleazy clickbit malware satan in hell are you doing?P NO! Bad Slashdot! Evil Slashdot. Stop it. This will not do. We are not amused.
Other than that, I have no strong feelings on the ,matter
The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
The number of times I have had to explain to customers how to do password storage right is staggering. Most still believe a single hash is enough (well, to be fair, for a high-entropy password it is). Some have at least heard of salting the hash. But as soon as you come to iteration, most are clueless, and if you put in things like a large-memory-property (to prevent brute-forcing by FPGAs and graphics-cards), you have lost them completely. Many people just stop learning when there is no direct need to and these are the same people that in many cases write security-critical software.
On the other hand, PBKDF2 has been available since 2000, packing hashing, iteration and salting in a nice package. And Argon2 now adds large memory and other nice properties and essentially solves the problem. People just seem to be completely unaware of this.
Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
Worst.
I'm not a gamer. Don't play them, but get the fuck off my lawn!
Sheesh.
2.5 million game pirates had their information leaked from a sketchy ass website over a year ago and now are acting offended someone may steal from them
I started to type up a rant about how this headline was completely misleading... but instead I'll just same "I'm done".
/screw you guys, I'm going home.
Umm, I'm not a gamer for couple of reasons dolt!
1. My info is my own. I "share" bits and pieces when absolutely necessary.
2. Games bore me.
You're not too bright, are you?
Social networking? Nah, not my thing and I find facebook et al. to be far too intrusive.
If you'd bother to read and UNDERSTAND what I'd written, you'd see we're close to being on the same page. Only diiference is, I choose not
to be a raving dickhead about it.
At first I though it was a joke - but maybe you're a _real_ straight-man - but you definitely hit the nail on the head.
CAP === 'falsify'
I apologize to you, it was wrong, you weren't my target audience. No offense intended to you personnally.
You are mixing unrelated issues and acting superior about it.
The problem lies in not using a salt, not in using MD5.
Gotta love unsubstantiated and unverifiable claims on the internet. "My life is *serious*, man! I have a murderer trying to murder me!"
If someone has "tried to kill [you] a couple of times" why did a "real man" like you have to wait for a woman to take out the restraining order? Wouldn't a "real man" deal with that himself?
Sorry, reads like fantasy/bullshit.
If you can't trust a piracy forum to protect your online details then who can you trust?
Source? No way something like this happens with out at least local news getting involved
Microsoft, Sony, and other companies sue over 1 million people for piracy. Here's a thought for the conspiracy theorists: Perhaps Microsoft, Sony, and other companies hired the hacker(s).