Results 1 to 10 of 10
  1. #1
    Community Member LevelJ's Avatar
    Join Date
    Jun 2011
    Posts
    213

    Default It appears DDO had a Security Breach (EDIT: in 2013, I fail)

    So I found out through a family member who also plays DDO that he discovered via a news report that there was a security breach in various sites, and after checking he and I discovered that both our info had been compromised on DDO. I haven't seen anything from SSG on this, so wanted to spread the word so people can take the necessary precautions to avoid security issues.

    EDIT: Here's the source for the news article my family member found this on: https://www.waaytv.com/content/news/...504556831.html

    EDIT 2: It appears the site is still displaying the breach from 2013 and that this one is NOT tied to the one that occurred more recently for other sites (as mentioned by Lynn below). Apologies for the misunderstanding.

    -Jayron
    Last edited by LevelJ; 01-18-2019 at 10:45 PM.


  2. #2
    Founder & Super Hero Arkat's Avatar
    Join Date
    Feb 2006
    Posts
    380

    Default

    Link plz.
    Quote Originally Posted by Aelonwy View Post
    Quote Originally Posted by Cordovan View Post
    The release notes themselves are essentially the same as was seen on Lamannia most recently.
    This^, in so many words, is how you say time and feedback on Lamannia are wasted.

  3. #3
    Bwest Fwiends Memnir's Avatar
    Join Date
    Jul 2006
    Posts
    0

    Default

    Exit, pursued by a bear. ~ William Shakespeare (stage direction from The Winter's Tale)

    .60284.

  4. #4
    Community Member LevelJ's Avatar
    Join Date
    Jun 2011
    Posts
    213

    Default

    Quote Originally Posted by Arkat View Post
    Link plz.
    https://www.waaytv.com/content/news/...504556831.html is where my family member found it, originally via a tweet of theirs. When we both checked to verify if our info was compromised, DDO was listed.


    -Jayron


  5. #5
    Systems Designer
    Lynnabel's Avatar
    Join Date
    Jul 2016
    Posts
    0

    Default

    Quote Originally Posted by LevelJ View Post
    https://www.waaytv.com/content/news/...504556831.html is where my family member found it, originally via a tweet of theirs. When we both checked to verify if our info was compromised, DDO was listed.


    -Jayron
    https://haveibeenpwned.com/PwnedWebsites

    The breach in question did absolutely occur, but in April of 2013. You can search for DDO (ctrl-f and "Dungeons" will get you there on the above link) to check the details. That being said, a strong password is very important, and there is no harm at all in being overprotective of your digital data. I'd recommend a password manager to generate secure passwords, and using 2-factor authentication with whatever password manager you go with. I believe the Chrome browser has recently started suggesting secure passwords via auto-fill, and taking advantage of those is very easy.
    100% radical, enthusiasm enthusiast.

    "Have you tried preproccing feat directory?"

  6. #6
    Community Member SiliconScout's Avatar
    Join Date
    Oct 2007
    Posts
    594

    Default

    Quote Originally Posted by LevelJ View Post
    So I found out through a family member who also plays DDO that he discovered via a news report that there was a security breach in various sites, and after checking he and I discovered that both our info had been compromised on DDO. I haven't seen anything from SSG on this, so wanted to spread the word so people can take the necessary precautions to avoid security issues.

    EDIT: Here's the source for the news article my family member found this on: https://www.waaytv.com/content/news/...504556831.html


    -Jayron
    Gonna assume that this link goes to have I been powned. Turbine did have a breach but it was 5 or 6 years ago as I recall. I don't believe any passwords were taken but they suggested / required a password change at the time. I don't honestly recall that clearly. I do recall that there was no billing / CC data taken and that was all that mattered to me as I use a different password for every site / logon that i have so I just changed my password at the time.

    I think if there was a new breach SSG would be notifying people. They would legally be required to in many jurisdictions that they operate in.

    **edit** I should have read the thread before replying I guess eh! Looks like I was right at least, if redundant.
    Last edited by SiliconScout; 01-18-2019 at 10:35 PM. Reason: I didn't read the other replies .. duh
    “Bad men need nothing more to compass their ends, than that good men should look on and do nothing. He is not a good man who, without a protest, allows wrong to be committed in his name, and with the means which he helps to supply, because he will not trouble himself to use his mind on the subject.”

  7. #7
    Community Member LevelJ's Avatar
    Join Date
    Jun 2011
    Posts
    213

    Default

    Quote Originally Posted by Lynnabel View Post
    https://haveibeenpwned.com/PwnedWebsites

    The breach in question did absolutely occur, but in April of 2013. You can search for DDO (ctrl-f and "Dungeons" will get you there on the above link) to check the details. That being said, a strong password is very important, and there is no harm at all in being overprotective of your digital data. I'd recommend a password manager to generate secure passwords, and using 2-factor authentication with whatever password manager you go with. I believe the Chrome browser has recently started suggesting secure passwords via auto-fill, and taking advantage of those is very easy.
    Ah, if that's the case than it's not the same as the recent one. Admittedly I had changed my passwords back then when that happened, so when I saw this and DDO was mentioned I thought it was a new one.

    Apologies for causing a ruckus.


  8. #8
    Community Member Jerevth's Avatar
    Join Date
    Mar 2016
    Posts
    1,832

    Default

    Quote Originally Posted by LevelJ View Post
    Ah, if that's the case than it's not the same as the recent one. Admittedly I had changed my passwords back then when that happened, so when I saw this and DDO was mentioned I thought it was a new one.

    Apologies for causing a ruckus.
    Kudos for accepting responsibility and updating the OP. I'd give you rep but I have none to give.
    If nothing else I'm considering changing my password to something tougher than it is now; why give my wife more ammo to try and take away my favorite(and only) vice. (Coffee and bacon are already severely restricted.) I swear that woman was an artificer in a past life; always on repeater.

    Lynnabel: if we remove our credit information from the auto-renewal for subscriptions, does it remove that from your database or merely unset a flag for the renewal?
    In all posts: Assume I'm just providing a personal opinion rather than trying to speak for everyone.
    *All posts should be taken as humorously intended and if you are struggling to decide if I insulted you; I didn't.

  9. #9
    Community Member
    Join Date
    Nov 2010
    Posts
    547

    Default

    Quote Originally Posted by Lynnabel View Post
    https://haveibeenpwned.com/PwnedWebsites

    The breach in question did absolutely occur, but in April of 2013. You can search for DDO (ctrl-f and "Dungeons" will get you there on the above link) to check the details. That being said, a strong password is very important, and there is no harm at all in being overprotective of your digital data. I'd recommend a password manager to generate secure passwords, and using 2-factor authentication with whatever password manager you go with. I believe the Chrome browser has recently started suggesting secure passwords via auto-fill, and taking advantage of those is very easy.
    Very good to see a prompt response from a responsible authority. Thanks!

  10. #10
    Bwest Fwiends Memnir's Avatar
    Join Date
    Jul 2006
    Posts
    0

    Default

    Quote Originally Posted by LevelJ View Post
    Apologies for causing a ruckus.
    No ruckus, and no apologies needed at all.

    I just personally prefer to read about security breaches for myself, hence my post above. But, my passwords needed refreshing - and this was a reminder to do so and I've now done so. You had our best interests at heart, and it's appreciated.
    Exit, pursued by a bear. ~ William Shakespeare (stage direction from The Winter's Tale)

    .60284.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

This form's session has expired. You need to reload the page.

Reload