We are currently experiencing payment processing issues. Our team is working to resolve the problem as quickly as possible. Thank you for your patience
Was our personal information compromised before?
0
Can Jacob or any admins address this particular statement the hackers made?
"After Hibia lazily logged into SSH and dealt with the aftershock of how easy it was, he downloaded the Sanshee database which contained hundreds of rows of sensitive user information (Full names, E-mails, Unsalted MD5 encrytped passwords, Home Addresses, Phone Numbers) - If we wanted to blackmail you, here would have been a good place to start, did we share any of this? No. Did we ever threaten you? No. Did we share ANY senstive data? No. Did we tell you what happened? Yes. Did you follow up by telling everyone their information was compromised? No. Users and Staff were unaware of their sensitive data being known - so much so that many of you are using the same passwords you used on Sanshee around various facets of the internet--for that matter, if you don't trust either of us as decent people you should change your passwords if any of them were used to register to Sanshee. Years later and you've finally been warned, and not by the person who should have warned you. Not warning your users that their data was stolen is outright irresponsible. "
I'm giving the benefit of the doubt to Jacob and his crew, since this could just be pure BS. However, I would like to know if there's any grain of truth to what they're saying, and what they're referring to (particularly when this happened). Luckily I never registered at the site, but I'm assuming some people have.
"After Hibia lazily logged into SSH and dealt with the aftershock of how easy it was, he downloaded the Sanshee database which contained hundreds of rows of sensitive user information (Full names, E-mails, Unsalted MD5 encrytped passwords, Home Addresses, Phone Numbers) - If we wanted to blackmail you, here would have been a good place to start, did we share any of this? No. Did we ever threaten you? No. Did we share ANY senstive data? No. Did we tell you what happened? Yes. Did you follow up by telling everyone their information was compromised? No. Users and Staff were unaware of their sensitive data being known - so much so that many of you are using the same passwords you used on Sanshee around various facets of the internet--for that matter, if you don't trust either of us as decent people you should change your passwords if any of them were used to register to Sanshee. Years later and you've finally been warned, and not by the person who should have warned you. Not warning your users that their data was stolen is outright irresponsible. "
I'm giving the benefit of the doubt to Jacob and his crew, since this could just be pure BS. However, I would like to know if there's any grain of truth to what they're saying, and what they're referring to (particularly when this happened). Luckily I never registered at the site, but I'm assuming some people have.
0
Gravity cat
the adequately amused
According to that front page post that the hackers put up, yes it was compromised in the past. The one that Jacob put up on the Front Page says that when Fakku got hacked this time, it wasn't.
0
Gravity cat wrote...
According to that front page post that the hackers put up, yes it was compromised in the past. The one that Jacob put up on the Front Page says that when Fakku got hacked this time, it wasn't.But it sounds like in both cases, the hackers had access to it, but simply didn't pursue taking a malicious route. This worries me a lot, since I use the same password for 90% of the sites I use.
0
Gravity cat
the adequately amused
Red Vodka wrote...
Gravity cat wrote...
According to that front page post that the hackers put up, yes it was compromised in the past. The one that Jacob put up on the Front Page says that when Fakku got hacked this time, it wasn't.But it sounds like in both cases, the hackers had access to it, but simply didn't pursue taking a malicious route. This worries me a lot, since I use the same password for 90% of the sites I use.
From what I can gather, Jacob's account was compromised last time, due to having a very weak password and was found out because he was using a very predictable ecryption technique. This time it wasn't Jacob's.
0
echoeagle3
Oppai Overlord
From my understanding of what happened the answer is yes. It seems that the hackers were trying to make a point to Jacob. They were trying to get him to increase his security on the network and to inform us, the users, of this security breach. I don't believe that they ever planned to use any of our, the users, personal information for malicious purposes. Their goal appeared to be making a point. They wanted to point out that Jacob has been a poor admin and that our personal information COULD HAVE been used for malicious purposes, not that it actually was this time.
0
animefreak_usa
Child of Samael
They got nothing on me outside of my fake ip address and the fact i fucking your woman/man. I never bought anything here.
0
My post here is my response to everything from the event three years ago. In this instance it was not my account that was compromised and no user data was lost, they messed around with an admins account which they previously had access to. Their actions were limited to front paging a post and vandalizing some manga.
The event three years ago happened when I recruited Tranquility (a FAKKU moderator at the time) to help me with some code on Sanshee before it went live. Specifically he was working on PayPal integration. When I took him on I changed the password on the database to "fakku123" because I didn't want him to see the password I had been using up until then. Unfortunately that particular server was using CPanel, so when I changed the database password it automatically changed the SSH password as well. Shortly after Sanshee went live, Tranquility shared that password with Hibia (the disgruntled ex admin I mentioned), and he immediately went into the database and reversed the encryption on my Sanshee account (which was the same password used on my main FAKKU account and my email) and stole a bunch of data off the server. That's where any notion that what they did was somehow not malicious, they broke the law and stole data.
The users that had created accounts on Sanshee at the time (three years ago) had sensitive information exposed. The hackers chose to focus entirely on me. To quote my post in the other topic... " they broke into all of my email accounts, my Skype account, my Facebook, and spent the day masquerading as me while I frantically tried to recover everything. He went as far as pulling up emails between myself and my ex-girlfriend and tried to use them against me. They downloaded all of the email I had sent in the past three years and tried to blackmail me using every random thing they found. And to top it all off after I got everything back they tried to ask me for a job."
I am all for having flaws pointed out so that they can be fixed, this was not the way to do it. At the time I chose not to pursue any legal action because Hibia lives in another country and Tranquility (though now a black hat) was someone I once respected. Plus I was a lot younger and didn't really understand the options I had.
The funny thing is I had already gone and fixed everything in the post linked above (you can now view controversial and popular manga from the past month) If they had just sent me an email with their complains a much more mature dialogue could have started, and progress would have been made.
The event three years ago happened when I recruited Tranquility (a FAKKU moderator at the time) to help me with some code on Sanshee before it went live. Specifically he was working on PayPal integration. When I took him on I changed the password on the database to "fakku123" because I didn't want him to see the password I had been using up until then. Unfortunately that particular server was using CPanel, so when I changed the database password it automatically changed the SSH password as well. Shortly after Sanshee went live, Tranquility shared that password with Hibia (the disgruntled ex admin I mentioned), and he immediately went into the database and reversed the encryption on my Sanshee account (which was the same password used on my main FAKKU account and my email) and stole a bunch of data off the server. That's where any notion that what they did was somehow not malicious, they broke the law and stole data.
The users that had created accounts on Sanshee at the time (three years ago) had sensitive information exposed. The hackers chose to focus entirely on me. To quote my post in the other topic... " they broke into all of my email accounts, my Skype account, my Facebook, and spent the day masquerading as me while I frantically tried to recover everything. He went as far as pulling up emails between myself and my ex-girlfriend and tried to use them against me. They downloaded all of the email I had sent in the past three years and tried to blackmail me using every random thing they found. And to top it all off after I got everything back they tried to ask me for a job."
I am all for having flaws pointed out so that they can be fixed, this was not the way to do it. At the time I chose not to pursue any legal action because Hibia lives in another country and Tranquility (though now a black hat) was someone I once respected. Plus I was a lot younger and didn't really understand the options I had.
The funny thing is I had already gone and fixed everything in the post linked above (you can now view controversial and popular manga from the past month) If they had just sent me an email with their complains a much more mature dialogue could have started, and progress would have been made.
0
Cinia Pacifica
Ojou-sama Writer
Jacob wrote...
And if I'm reading correctly he is once again asking for a job in his post last week.[color=red][b]There are thousands of users around the globe, you'll find someone more trust worthy and respectable in due time.