Post
Topic
Board Gambling
Re: Primedice domain access restored. Please stand-by for more details
by
adaseb
on 08/03/2018, 22:18:34 UTC
Hey guys,

As many of you are probably already aware we are back up and running! Yeeey! Smiley


On your login you will be asked to reset your password, you can do that in one of two ways.

1. You can change password from any device that is still logged into your account.
2. You can contact our support team. ( Please note that support will be slower than usual due to huge amount of tickets we are getting at this moment.

Also for users safety all withdrawals are currently on manual.

I think what is really scary about this incident is imagine what could of happebed if the hackers weren't lazy.

They would at an unsuspecting time ( when PD dev are sleeping ) commit the hack and make the phishing site look for authentic.

When someone tried to login, they would go to the real PD and perform a withdraw.

The way the registrar handled this situation was very dangerous. Hopefully many Bitcoin sites and services can learn from this incident.

In this case, Primedice can't be reached via IP: if they change the DNS, they can't find the authentic website.
Of course, your idea is valid and can be used in some websites.


Yes but this is not what happened is it?

Basically the registrar redirected the traffic to a different IP.

The old site was still accessible by the old IP.

The hacker would simply record the usernames and passwords and then go to the real Primedice website by the IP address.

Plus, it takes a few hours for DNS to update. It's not instant but bottle necked by the ISP