Important Security Information.

Anything to do with the clan - suggestions - democracy - announcements - citadel.

Moderators: Citadel Overseer, Media, Liaison Team

User avatar
Deep_Pain
KoA Alumni
KoA Alumni
Posts: 6986
Joined: Wed Dec 05, 2007 6:00 am
RSN: Deep Pain
RSN2: Choose Life

Important Security Information.

Post by Deep_Pain » Mon Jul 30, 2012 11:24 pm

There have been some security Issues on the site lately.

A person or a group of people have been trying to access KoA forum accounts.

Some of the accounts they are trying to access have been inactive / disabled for quite some time. So it is likely the source of any information gathered is from outside of KoA. Possibly the old hacked databases of zybez and runehead or something simular.

It seems that most of these attempts have been fruitless - we believe that one KoA forum account has been compromised - this account has been deactivated.

The way they seem to be doing this is by gleaning information found on the web ( facebook, koa forums, fansites etc.. ) to either guess the password of a user or guess what their recovery questions may be. IE: if you have it on facebook that your favourite food is paella and one of your recover questions on your email is what's your favourite food - by building up a profile of someone over various sites - they may gain access to your email then reset your password on koa or runescape via your email.

Several KoA users have reported that someone has tried resetting the email password.

We've taken several steps to combat this. Some of these include - removing birthdays from the calendar. making sure there is no way of seeing your email address. Setting a complexity level on new/changed passwords.

If your account security is good - this should not affect you.

Security tips:
Tamal wrote: Securing your Email
Email security is not just about having a good password, it's also about having good password recoveries. If your email account works off birthday (or some other piece of personal information that can be discovered on the internet) then it's a good idea to change your password recoveries to information that is not discoverable. If birthday is a part of your password recovery process then is a good idea to remove your birthday from your KoA profile and Facebook/any other social network.
Make sure your password is secure - IE: of a length at least more than 8 characters - when possible use special characters - not using words - using a mix of upper and lower case - Use different passwords everywhere!
for more information on how to make a secure password - please see here: http://netsecurity.about.com/cs/general ... 12103b.htm

It doesnt seem to be the case that virus's or trojans etc.. are being used.. but with the possibility that there may be compromised accounts on KoA or rs players you know on facebook etc..- if someone sends you a pm with a link or posts a link on the forums, just be sure what you are clicking (mouse hover).

Don't post personal information used in recovery questions on the web.

If any of your accounts koa - email - facebook etc.. have had someome try to recover your account via recovery questions it should in some way record some information on this - ie send you an email. If this happens please let us know.

Just to re-assure they've only tried logging onto a few accounts - mainly today - this is something we're pro-actively dealing with.

EDIT:

for hotmail and I believe yahoo email accounts you can set them to not use recovery questions but set up a phone number for it to call or text with recovery info.
Image
Image
Image
Image

It is said that your life flashes before your eyes just before you die. That is true, it's called Life.

User avatar
Fluff
Posts: 3443
Joined: Sun Jul 11, 2010 8:59 am
RSN: Fluff n Slay
Location: England

Re: Important Security Information.

Post by Fluff » Tue Jul 31, 2012 12:07 am

Thanks Deep
ImageImage
Image

User avatar
syfyqueen
Posts: 1350
Joined: Sat May 12, 2012 6:51 pm
RSN: Syfyqueen
Location: Florida

Re: Important Security Information.

Post by syfyqueen » Tue Jul 31, 2012 12:35 am

WOW ~ WTF is wrong with people!? I guess they don't have anything better to do with their lives than hack other people and make our lives hell for trying to play a damn game. Several people have quit this clan recently and it makes me wonder if it may be one of them? I sure as hell hope not, but these days I don't trust anybody; no matter how well I think I know 'em...... :evil: :-x
ImageImage
Image

Torri
Posts: 318
Joined: Wed Aug 18, 2010 7:35 pm
RSN: Tynset
Location: Well, part of me's in Michigan ;)

Re: Important Security Information.

Post by Torri » Tue Jul 31, 2012 2:31 am

:| People nowdays are just ****ed up! Thank you for being on top of it! I <3 you guys!
[img]http://imageshack.us/a/img43/5832/36320 ... 081185.jpg[/img]

[spoiler][sig]2012-03_Firemaking_1st-Torri.png[/sig][/spoiler]

Diplomatt
Inactive
Posts: 3120
Joined: Sun Apr 04, 2010 1:36 pm
RSN: Diplomatt
Location: England

Re: Important Security Information.

Post by Diplomatt » Tue Jul 31, 2012 6:54 am

With reference to KoA Facebook group, the current policy is that it is a 'closed group'. This means you have to be invited/ ask to join. All members of staff are admin of the facebook group and can delete/ add members.

I will endevour to go through all the security tonight to see if their is any other security measures we can implement on the group.

Keep Safe!

User avatar
Oobz
Clan Member
Clan Member
Posts: 6617
Joined: Thu Mar 18, 2010 10:56 am
RSN: Oobz
Location: Pembrokeshire

Re: Important Security Information.

Post by Oobz » Tue Jul 31, 2012 6:56 am

Thanks Andy!
Image Image

lacey days
Clan Member
Clan Member
Posts: 563
Joined: Wed Sep 07, 2011 9:22 pm
RSN: Lacey Days
Location: Southampton
RSN2: AgedSquirel

Re: Important Security Information.

Post by lacey days » Tue Jul 31, 2012 7:34 am

Sometimes I wonder why people behave the way they do......? Is it because they can do something that they do?
Ty guys for being so careful with our security.
*•„¸¸„•*^*•„¸¸^*•„¸¸..;Lacey Days;..¸¸„•*^¸¸„•*^*•„¸¸„•*
¸;›^¸.¸•º°˜°º•„¸¸„..Catch a star for me..„¸¸„•º°˜°º•¸.¸^‹;¸
..........`«„¸¸„»´.........˜°º•„¸¸„...„¸¸„•º°˜..........`«„¸¸„»´.........

Image

Image

Image

User avatar
Cally Raven
Site Admin
Site Admin
Posts: 6102
Joined: Tue Aug 02, 2011 10:06 am
RSN: Cally Raven
Location: Bolton

Re: Important Security Information.

Post by Cally Raven » Tue Jul 31, 2012 7:37 am

Thx guys, so annoying that people can do these things :(
Image
Image]
Image
Image
Image
Image

User avatar
Kevinsaurus
Posts: 378
Joined: Fri Oct 07, 2011 2:29 am
RSN: Kevinsaurus
Location: USA (EST)

Re: Important Security Information.

Post by Kevinsaurus » Tue Jul 31, 2012 10:08 am

Definitely important to be extra careful when it comes to security, even the smallest of things can make a difference. Thanks for this Deep.
[center][url=http://runetrack.com/profile.php?user=Kevinsaurus][img]http://runetrack.com/sigs/stat/t5lejie/ ... saurus.png[/img][/url]
[sig]2012_08_magic2.png[/sig][/center]

Diplomatt
Inactive
Posts: 3120
Joined: Sun Apr 04, 2010 1:36 pm
RSN: Diplomatt
Location: England

Re: Important Security Information.

Post by Diplomatt » Tue Jul 31, 2012 4:45 pm

I've edited the Facebook Group to the maximum security it allows. It was a 'closed group' so anyone could see the group and who was in it, but only members could see posts, it is now a 'secret group'. Only members of the group can see anything about it.

I would also recommend you re-set up the securities on your Facebook accounts anyway. The more you have it locked down to 'outsiders'/ 'non-friends', the less they can get!

User avatar
Katy
KoA Alumni
KoA Alumni
Posts: 1975
Joined: Fri Feb 03, 2012 6:48 pm
RSN: K aty
Location: La La Land

Re: Important Security Information.

Post by Katy » Tue Jul 31, 2012 4:51 pm

Pilgrim Matt wrote: I would also recommend you re-set up the securities on your Facebook accounts anyway. The more you have it locked down to 'outsiders'/ 'non-friends', the less they can get!
Could do with some pointers on how to check my fb securities...before they changed it all it was dead easy...now seems more complicated :S
Having a dirty mind makes ordinary conversations much more interesting



“She who dies with the most shoes wins!

Diplomatt
Inactive
Posts: 3120
Joined: Sun Apr 04, 2010 1:36 pm
RSN: Diplomatt
Location: England

Re: Important Security Information.

Post by Diplomatt » Tue Jul 31, 2012 5:58 pm

Kk Katy, will do a little guide!

User avatar
magerpainz
KoA Alumni
KoA Alumni
Posts: 2871
Joined: Tue Nov 23, 2010 11:18 pm
RSN: Magerpainz

Re: Important Security Information.

Post by magerpainz » Sun Aug 05, 2012 8:17 pm

I think we need to be more careful with new applicants. Maybe keep the "good lucks", "Here's your sigggy", "see you in the CC" etc. to a minimum until Admin. has a chance to verify and accept any applications. Just a thought. One response from staff advising them that admin will be along shortly should suffice until admin decides.
Image Image Image
Sometimes..standing for what you believe...means standing alone!
"Live your life. Take chances. Be crazy. Don't wait. Right now is the oldest you've ever been and the youngest you will ever be again!"
I want a Spartan Woman!

Torri
Posts: 318
Joined: Wed Aug 18, 2010 7:35 pm
RSN: Tynset
Location: Well, part of me's in Michigan ;)

Re: Important Security Information.

Post by Torri » Sun Aug 05, 2012 8:27 pm

magerpainz wrote:I think we need to be more careful with new applicants. Maybe keep the "good lucks", "Here's your sigggy", "see you in the CC" etc. to a minimum until Admin. has a chance to verify and accept any applications. Just a thought. One response from staff advising them that admin will be along shortly should suffice until admin decides.

A side note to this: The applications section is viewable by anyone who registers to apply, whether they've been accepted yet or not. It would help to possibly lock that area, so that members can view it yet not post (other than staff) until the person is accepted. Then make them have to post an intro to say hello on. That keeps members' info in the hidden areas until the person is verified.
[img]http://imageshack.us/a/img43/5832/36320 ... 081185.jpg[/img]

[spoiler][sig]2012-03_Firemaking_1st-Torri.png[/sig][/spoiler]

User avatar
Oobz
Clan Member
Clan Member
Posts: 6617
Joined: Thu Mar 18, 2010 10:56 am
RSN: Oobz
Location: Pembrokeshire

Re: Important Security Information.

Post by Oobz » Sun Aug 05, 2012 9:15 pm

Torri wrote:A side note to this: The applications section is viewable by anyone who registers to apply, whether they've been accepted yet or not. It would help to possibly lock that area, so that members can view it yet not post (other than staff) until the person is accepted. Then make them have to post an intro to say hello on. That keeps members' info in the hidden areas until the person is verified.
Admin are discussing this atm, you must be able to read minds :P
Image Image

Post Reply