Post
Topic
Board Meta
Re: Account hacked -- should I blame admins or not?
by
zoeh
on 11/12/2018, 08:55:42 UTC
Apparently, my account got hacked on the 1st November by the unknown hacker for unknown reasons.

First of all, my password was secure atleast with 3 capital letters, 6 numeric numbers and the rest was just small letters.

It came as a surprise when I tried logging just now, but I was unable due to the unknown hacker my account. The next move that anyone would take after, would be recovering the password using the email. Then again, the email was invalid.

Then I headed to bitcointalk search box and tried searching the account user name, it showed up and indicated that it was last active this morning, and proceed to show last posts and noticed that the new owner is making use of it by participating in signature campaigns and social media campaigns, and probably hacking some forum users. This individual is impersonating me and in a way ruining my reputation since I am not well aware what he uses the account for. 

Enough about that, let head over to the forum security now.

After I released that the account email and passwords were changed, I then headed to my mailbox, searched bitcointalk on the search box to find out what really happened, and guess what happen; this happened:
https://i.imgur.com/tEfWDCy.png

This is what was happening, the bitcointalk team was telling me that the email has changed. I mean, what happened to " Confirm that you are changing the email by clicking this option? Even a site that was built a day ago has that.

The admin should do a better job in securing the forum because at the moment, I don't consider it safe, how can users not confirm the emails addresses they are changing? instead, they get a notification inform them that the email changed whereas the user didn't change it. Sometimes, we take more than month without accessing the forum, so the 14 day notification doesn't do much- look at me now.

Now my Snr Member account is hacked, when will I rank as senior again since they have introduced this merit system?
Please do something about this, there have too may complain regarding hacked account.

This is my email looked before the hack - 1 November. Bitcointalk PMs:
https://i.imgur.com/zOisUw3.png

You should definitely blame the admins, as do I. My account was hacked this summer, it had a secure password, but this forum is not secure at all, there's no email confirmation about changing the email address, no 2FA and what grinds mt gears is "If this change wasn't made by you, lock your account".

I clicked that link, and now both the hacker and I are locked out of my account, I had a thread active for more than a month, a few high ranking members verified that I'm genuine, but no, the admins don't give a fuck.

It took me more than a year to rise that account from the ground, 750+ posts and 101 merit, that is not easy to attain right now.
My point exactly, thank you for highlighting it, you and I have one thing in common, which is feeling that the forum isn't secure enough. The  admin should do something about this issue or their accounts will follow as well. It takes years to grow an account, especially with this merit system, and it sucks to see accounts being deprived from original users whereas the admin don't give a damn, they don't even bother responding to our messages, I find it somehow unproffessional, but its their choice.

Yeah, you should blame the admins so your account won't be recovered and get ignored as long as you live. But even if you can get patient enough and wait until theymos for a year he doesn't even read a single word to your thread though.
Whats the use of having admins if they can't even recover a simple account, what they do is ignore users messages, and it's not doing anything but harm to this forum.

Most likely your account didn't get hacked. It is far more likely that your password got phished by visiting one of the several clone phishing sites.
You will never know buddy and I am not arguing with your statement, but I have also installed, metamask, metacert and alot more to ensure a secure browser. However, even if that might have been the case, users should atleast be informed when an intruder is accessing their account and change the email and password, especially from an unathorised IP address.