Private servers data breach

11/25/2020 15:21 jaren#1
I'm sure I'm not the only receiving pop ups from google chrome saying some of my passwords have been found in data breaches. When I check which ones, it happens to be old accounts from blazegn, playcronos, rebellion-online, electus, literally no other. Almost as if all of our logins are being sold.
11/25/2020 16:47 Judgelemental#2
Same.

All we can do now is change our passwords frequently, use a password manager, use throw-away emails for SRO related stuff and never download and run clients on the same computer where we keep our most important stuff on. (even the 'clean' client has cryptominters into it, if you scan it).
11/26/2020 10:04 jaren#3
Quote:
Originally Posted by Judgelemental View Post
Same.

All we can do now is change our passwords frequently, use a password manager, use throw-away emails for SRO related stuff and never download and run clients on the same computer where we keep our most important stuff on. (even the 'clean' client has cryptominters into it, if you scan it).
Sad... I think this is it for me and silkroad.
11/26/2020 10:49 Judgelemental#4
Quote:
Originally Posted by Javiscript View Post
Sad... I think this is it for me and silkroad.
I have never received any suspicious or fraudulent emails so far and if I did, it probably never got to see the light of the day out of my spam folder.
All is fine. Yes, they've got my email but so what, nothing I can do. I need my email and as long as its security is not compromised it's fine, no one has ever tried to break into it.
If I ever want to play SRO, I just download pservers on my throwaway laptop, I suggest you do the same.
11/26/2020 22:23 notHype*#5
Quote:
Originally Posted by Javiscript View Post
I'm sure I'm not the only receiving pop ups from google chrome saying some of my passwords have been found in data breaches. When I check which ones, it happens to be old accounts from blazegn, playcronos, rebellion-online, electus, literally no other. Almost as if all of our logins are being sold.
Passwords are hashed in md5 encryption, at least for the server-side of Silkroad. Unless someone has some unreleased miracle cracker, md5 is a one-sided type of encryption and cannot be reversed to find your actual password in alphanumerals.

Point being --- even if your information has been "sold" which I highly doubt, your character should not be at risk.

I can't assure that it is like this for WEBSITE logins, because every website is different, but either way, most websites enable you to create two seperate passwords: one for game and one for website account. So, I wouldn't worry a ton if I were you.
11/29/2020 11:11 jaren#6
Quote:
Originally Posted by notHype* View Post
Passwords are hashed in md5 encryption, at least for the server-side of Silkroad. Unless someone has some unreleased miracle cracker, md5 is a one-sided type of encryption and cannot be reversed to find your actual password in alphanumerals.

Point being --- even if your information has been "sold" which I highly doubt, your character should not be at risk.

I can't assure that it is like this for WEBSITE logins, because every website is different, but either way, most websites enable you to create two seperate passwords: one for game and one for website account. So, I wouldn't worry a ton if I were you.
Yeah I wasn't worried since I use different passwords and logins for silkroad but I found that curious so I just thought I'd share here. Thank you guys for your responses.
11/30/2020 12:37 gigola123#7
Quote:
Originally Posted by notHype* View Post
Passwords are hashed in md5 encryption, at least for the server-side of Silkroad. Unless someone has some unreleased miracle cracker, md5 is a one-sided type of encryption and cannot be reversed to find your actual password in alphanumerals.

Point being --- even if your information has been "sold" which I highly doubt, your character should not be at risk.

I can't assure that it is like this for WEBSITE logins, because every website is different, but either way, most websites enable you to create two seperate passwords: one for game and one for website account. So, I wouldn't worry a ton if I were you.
Seen some big servers here which store clear password in an other table "UserClearPassword" with proxy even "UserAttemptConnexion" with : "JID", "username", "clear_password", "success".

Then they can see each of your password in clear, if you put the same email you'll get f*****, so don't trust any one here, even the "most advanced pserv" ^^