View previous topic :: View next topic |
Author |
Message |
|
Angel M Cazares
Joined: 23 Sep 2010
Posts: 5519
Location: Iscandar
|
Posted: Fri Aug 11, 2017 5:00 pm
|
|
|
Thanks for explaining what happened. I hope you are able to recover the domain. What happened to ANN sucks, but I am glad the content and communication were mostly uninterrupted. And Christopher, you should sue your phone carrier and demand from them the money this whole affair is going to cost ANN.
|
Back to top |
|
|
dtm42
Joined: 05 Feb 2008
Posts: 14084
Location: currently stalking my waifu
|
Posted: Fri Aug 11, 2017 5:01 pm
|
|
|
I am confused. You keep mentioning .cc, but don't you mean the .com domain instead? You already have access to the .cc domain because that's the site I'm reading this on.
Also no mention of how Zac got hacked?
Edit: looks like you fixed it already
|
Back to top |
|
|
JacobC
ANN Past Staff
Joined: 15 Jan 2008
Posts: 3728
Location: SoCal
|
Posted: Fri Aug 11, 2017 5:02 pm
|
|
|
dtm42 wrote: | I am confused. You keep mentioning .cc, but don't you mean the .com domain instead? You already have access to the .cc domain because that's the site I'm reading this on.
Also no mention of how Zac got hacked? |
That was an autocorrect error applied over the site that affected the article's text. It's been fixed now.
|
Back to top |
|
|
Emma Iveli
Joined: 19 Jun 2005
Posts: 679
Location: Hobo with internet
|
Posted: Fri Aug 11, 2017 5:03 pm
|
|
|
I've been a member for years and been coming for even longer. I love this site and it sucks this happened.
Last edited by Emma Iveli on Fri Aug 11, 2017 5:04 pm; edited 1 time in total
|
Back to top |
|
|
mgosdin
Joined: 17 Jul 2011
Posts: 1302
Location: Kissimmee, Florida, USA
|
Posted: Fri Aug 11, 2017 5:04 pm
|
|
|
No matter how good the security it can always be compromised by "social engineering" or more to the point the human factor. ( One place I worked at was hit with the "dump a bunch of virus hacked thumb drives" in the parking garage. We got hit, but it wasn't even aimed at us but rather another government tenant in the building. )
I know this is a nightmare for all of you, right up there with the worst I've ever been a part of. It will settle down and things will go back to "normal". And most important of all, we will still be here looking to read the latest on our favorite Anime.
Mark Gosdin
|
Back to top |
|
|
Farix
Joined: 28 Feb 2007
Posts: 152
|
Posted: Fri Aug 11, 2017 5:09 pm
|
|
|
Quote: | Cell phones aren't perfect 2-Factor security. |
This is one of the things that annoy me with 2-factor authentication. Many websites require a cellphone for 2-factor authentication to work. However, I live in an area were cellphone coverage is extremely spotty if not non-existent once you go outside of town (I live 4 miles outside the nearest town). Thus, 2-factor authentication that requires a cellphone is completely useless to me.
|
Back to top |
|
|
penguintruth
Joined: 08 Dec 2004
Posts: 8506
Location: Penguinopolis
|
Posted: Fri Aug 11, 2017 5:13 pm
|
|
|
If this hacker can ever be identified, they should be sued for any loss of revenue.
|
Back to top |
|
|
Asrialys
Joined: 12 Dec 2006
Posts: 1164
|
Posted: Fri Aug 11, 2017 5:21 pm
|
|
|
Quote: | After three failures, they tried my cell phone company's online chat feature where they were able to convince a customer service representative (CSR) to make the transfer.
...
They also used my phone number to recover the password for ANN's @Anime twitter account, delete the account, and then rename their own account to @Anime. |
Wow. These parts right here suck. Good thing there are two identical Twitter accounts.
|
Back to top |
|
|
Parse Error
Joined: 09 Oct 2009
Posts: 592
|
Posted: Fri Aug 11, 2017 5:26 pm
|
|
|
farix wrote: | This is one of the things that annoy me with 2-factor authentication. |
People always get angry with me for pointing this out, but 2FA is pointless anyway. A strong password is just as effective at discouraging or stopping the same kind of random or scripted attacks that it does, but neither one can prevent a targeted attack from succeeding. Regardless of method, there's always a procedure to keep the rightful owner from getting permanently locked out of their account, which can always be exploited by someone else. The only real solution is to assume that everything will eventually get hacked, and try limit the damage that can be done. Anything else only provides the illusion of security.
|
Back to top |
|
|
HueyLion
Joined: 14 Feb 2014
Posts: 914
|
Posted: Fri Aug 11, 2017 5:27 pm
|
|
|
the Main lesson here is people...NEVER USE PHONE NUMBERS FOR EMAIL RECOVERY!
Always rely on a second email or secret question like us commoners...
|
Back to top |
|
|
Parsifal24
|
Posted: Fri Aug 11, 2017 5:29 pm
|
|
|
I appreciate the transparency I honestly didn't expect to be told anything which ANN is well within their right for security reasons or simply to "save face." But it's nice to be told how and why something bad happened from the source.
Hopefully things will get back to normal for everybody and this will all seem like a bad dream. Till that day keep on keeping on and know you're all appreciated for the hard work everyone does.
|
Back to top |
|
|
Primus
Joined: 01 Mar 2006
Posts: 2831
Location: Toronto
|
Posted: Fri Aug 11, 2017 5:32 pm
|
|
|
dtm42 wrote: | Also no mention of how Zac got hacked? |
Did Zac register his Twitter account with an @animenewsnetwork(.)com email? If so, the people behind this probably used the reset password option and intercepted the email.
|
Back to top |
|
|
Farix
Joined: 28 Feb 2007
Posts: 152
|
Posted: Fri Aug 11, 2017 5:39 pm
|
|
|
Parse Error wrote: |
farix wrote: | This is one of the things that annoy me with 2-factor authentication. |
People always get angry with me for pointing this out, but 2FA is pointless anyway. |
But never the less, too many websites—particularly banking and retailers—still try to force it on you. It's as if they cannot conceive that someone, especially in the US, wouldn't either have a cellphone or spend most of their time out of range.
|
Back to top |
|
|
kiminobokuwa
Joined: 18 Sep 2015
Posts: 547
|
Posted: Fri Aug 11, 2017 5:41 pm
|
|
|
This is scary!! Why doesn't phone companies use a secret code word to access the account instead of cell-phone verification?? Either way, hopefully this wasn't a personal attack and just a regualr hacker. I mean, I heard hackers use this method cause it's easier but damn, i never knew it was THAT easy!! I hope you can recover the domain because I've been a long time fan of this site!! Hope you guys can recover and push through to stay strong!! Also sue the hell out of the phone company for damages if u can because they basically had and took no extra steps to secure your account!!
|
Back to top |
|
|
XerneasYveltal
Joined: 09 Jun 2015
Posts: 676
Location: Philippines
|
Posted: Fri Aug 11, 2017 5:51 pm
|
|
|
Thanks for telling us what was going on.
I have no idea as to why did ANN's website suddenly change its look by the time the hack started.
|
Back to top |
|
|
|