NATION

PASSWORD

Data leak

Bug reports, general help, ideas for improvements, and questions about how things are meant to work.

Advertisement

Remove ads

User avatar
The Imperium Collectives
Envoy
 
Posts: 246
Founded: Mar 14, 2014
Corrupt Dictatorship

Postby The Imperium Collectives » Mon Mar 02, 2015 3:04 pm

Apologies if this was asked or answered before, but like others are saying, what if a puppet has been leaked? I don't use puppets anymore, and the ones I keep track of are now currently destroyed. I have not created a new puppet in at least a month, so I'm fairly certain all puppets of mine are gone from the game. Would there be any security problems or anything notable?

These windswept isles, unwavering and proud

The Northern Lordships of The Imperium Collectives

User avatar
SalusaSecondus
Senior Admin
 
Posts: 354
Founded: Jun 12, 2003
Father Knows Best State

Postby SalusaSecondus » Mon Mar 02, 2015 3:10 pm

Deian salazar wrote:Well if a data leak happens like this again, will it be as major, or more affecting or less?


Well, if a dataleak happens like this again, it will be identical!

Snark aside, all events are unique. We're taking this as an opportunity to go over some of our code and tighten things up so the likelihood of things happening again is even lower than it was before.

User avatar
Greater Minsk
Civilian
 
Posts: 1
Founded: Feb 24, 2015
Ex-Nation

Postby Greater Minsk » Mon Mar 02, 2015 3:30 pm

*realizes that a different puppet of mine was affected*

:? :? :?

User avatar
Themiclesia
Postmaster-General
 
Posts: 10713
Founded: Feb 12, 2013
Ex-Nation

Postby Themiclesia » Mon Mar 02, 2015 3:33 pm

This is bad, because my hundreds of accounts scattered across the internet use the same password. :palm:
NS stats not in effect
(except in F7)
Gameside factbooks not canon
Sample military factbook
Nations:
Themiclesia
Camia
Antari
>>>Member of Septentrion, Atlas, Alithea, Tyran<<<
Left-of-centre, multiple home countries and native languages, socially and fiscally liberal; he/him/his
Pro: diversity, choice, liberty, democracy, equality | Anti: racism, sexism, nationalism, dictatorship, war
News | Court of Appeal overturns Sgt. Ker conviction for larceny in quartermaster's pantry | TNS Hat runs aground in foreign harbour, hull unhurt | House of Lords passes Stamp Collection Act, counterfeiting used stamps now a crime | New bicycle lanes under the elevated railways | Demonstration against rights abuses in Menghe in Crystal Park, MoD: parade to be postponed for civic activity

User avatar
[violet]
Executive Director
 
Posts: 16205
Founded: Antiquity

Postby [violet] » Mon Mar 02, 2015 3:39 pm

Blekksprutia wrote:Darn, I (or one of my puppets, can't tell) was leaked. Did they get TGs from everyone?

We actually don't know that "they" got anything; we just know the file was exposed to the internet, which means it could have been downloaded by anyone. I only have detailed access logs going back two weeks, which shows nobody downloaded it before the player who reported it to us.

As per the News post, the file exposed data on 3,325 nations, many of which were holding telegrams under the old TG system, where messages were written directly into nation files. This caused a further 3,460 nations to be affected in the sense that a TG they sent was exposed.

The Data Leak Checker tool will tell you if you are one of those people, and advise you to contact us so we can show you what the messages were. So far I haven't seen anything anyone will be embarrassed about; the great majority are recruitment TGs.

User avatar
[violet]
Executive Director
 
Posts: 16205
Founded: Antiquity

Postby [violet] » Mon Mar 02, 2015 3:41 pm

Themiclesia wrote:This is bad, because my hundreds of accounts scattered across the internet use the same password. :palm:

Please note that only 0.08% of nations are affected, and Themiclesia isn't one of them.

But it is really bad practice to use the same email/password combination on everything. You shouldn't do that.

User avatar
[violet]
Executive Director
 
Posts: 16205
Founded: Antiquity

Postby [violet] » Mon Mar 02, 2015 3:48 pm

The Imperium Collectives wrote:Apologies if this was asked or answered before, but like others are saying, what if a puppet has been leaked? I don't use puppets anymore, and the ones I keep track of are now currently destroyed. I have not created a new puppet in at least a month, so I'm fairly certain all puppets of mine are gone from the game. Would there be any security problems or anything notable?

The Data Leak Checker tool will tell if you if any puppet that ever shared an email address with your main is part of the leak. If you have puppets with no email addresses, your exposure is a lot more limited, since there's no personal information and no possibility that someone could use the leaked data to find other accounts of yours across the internet with the same combination of email address and password. In this situation, your worst case is that someone (a) has obtained the data, (b) manages to decrypt the password hashes, then (c) revives your old dead puppet. This strikes me as an unlikely scenario, but you should be aware of it.

User avatar
Nanatsu no Tsuki
Post-Apocalypse Survivor
 
Posts: 203853
Founded: Feb 10, 2008
Inoffensive Centrist Democracy

Postby Nanatsu no Tsuki » Mon Mar 02, 2015 4:30 pm

My nation wasn't affected but I took the advice regardless and changed passwords here and in other websites. One can never be too careful.

Anyway, NS admins, thanks for the transparency in letting us know this happened.
Slava Ukraini
Also: THERNSY!!
Your story isn't over;֍Help save transgender people's lives֍Help for feral cats
Cat with internet access||Supposedly heartless, & a d*ck.||Is maith an t-earra an tsíocháin.||No TGs
RIP: Dyakovo & Ashmoria

User avatar
[violet]
Executive Director
 
Posts: 16205
Founded: Antiquity

Postby [violet] » Mon Mar 02, 2015 4:55 pm

While we're talking security, can I recommend 2-factor authentication for sites you really care about, like your email account. Here is Google's version.

It means that even if someone discovers your username and password, they can't get into your account unless they have your phone as well.

It's not widely available (and we don't have it here), but for things like banking and email, if your provider has it, it's usually worth using.

User avatar
Lost heros
Powerbroker
 
Posts: 9622
Founded: Jan 19, 2012
Ex-Nation

Postby Lost heros » Mon Mar 02, 2015 6:08 pm

Are old ex-nations also at risk for potential leakage?
Last edited by Lost Heros on Sun Mar 6, 2016 12:00, edited 173 times in total.


You can send me a TG. I won't mind.

"The first man to compare the cheeks of a young woman to a rose was obviously a poet; the first to repeat it was possibly an idiot." - Salvador Dali

User avatar
[violet]
Executive Director
 
Posts: 16205
Founded: Antiquity

Postby [violet] » Mon Mar 02, 2015 6:26 pm

Lost heros wrote:Are old ex-nations also at risk for potential leakage?

Yes, almost all of the exposed ones are ex-nations. Some ceased to exist more than a decade ago.

If your current nation has an email address set, though, then the Data Leak Checker will search for any exposed nation that had the same address. This way, you can tell whether your email address is involved in any way on any nation past or present.

User avatar
The Union of the West
Minister
 
Posts: 2211
Founded: Jul 07, 2013
Ex-Nation

Postby The Union of the West » Mon Mar 02, 2015 6:55 pm

Only (encrypted) password hashes were exposed, not plaintext passwords. However, you should still change your password if it was exposed, because hashes aren't impervious to brute-force cracking by an attacker who has your data offline, especially if your password contains dictionary words.


Perhaps you should use salted hashes to encrypt the passwords. They provide better protection against dictionary attacks and rainbow table attacks.
☩ Orthodox Christian ☩
If more of us valued food and cheer and song above hoarded gold, it would be a merrier world.

User avatar
Gregoryisgodistan
Senator
 
Posts: 3907
Founded: Jun 22, 2013
Ex-Nation

Postby Gregoryisgodistan » Mon Mar 02, 2015 7:00 pm

About ten years ago, my sister and I had NS accounts that have long since ceased to exist. Although I wound up creating a new nation about a year and a half ago and joined the forums, she never rejoined. Would it be possible for me to check on her behalf to see if her nation was affected since she has no NS account currently and no desire to create one?
Gregoryisgodistan, population 75,000,000. All citizens are required to worship Lord Almighty Gregory, our head of state, as a deity.
IBS II Champions
Beach Cup IX Round of 16
World Indoor Soccer Championship 6 - 2nd place
BoI XIV Champion
IBS III Champions
WCoH 22 Round of 16
WB XXII 10th Place in Casaran, advanced to Round of 32
IBS IV host, champion
4th in WCoH 23
WBC 29 QF
HWC 12 hosts
WJHC VI 2nd place,
CoH 60 4th place
WCoH XXIV Champs
CoH 61 Runner-Up
IBS VI Champs
BOI XVI Host
IBS VII Champs
WCoH XXV 2nd Place
WBC 32 2nd Place
IBS VIII host and champs
WBC 33 Host/QF
WCoH 27 co-host and champs
WC 72 Qualifier
WBC 34 champs
CoH 67 Third place

User avatar
Reploid Productions
Director of Moderation
 
Posts: 30507
Founded: Antiquity
Democratic Socialists

Postby Reploid Productions » Mon Mar 02, 2015 7:04 pm

Gregoryisgodistan wrote:About ten years ago, my sister and I had NS accounts that have long since ceased to exist. Although I wound up creating a new nation about a year and a half ago and joined the forums, she never rejoined. Would it be possible for me to check on her behalf to see if her nation was affected since she has no NS account currently and no desire to create one?

Sure, just file a GHR telling us the account name and we can check for you. :)
Forum mod since May 8, 2003 -- Game mod since May 19, 2003 -- Nation turned 20 on March 23, 2023!
Sunset's DoGA FAQ - For those using DoGA to make their NS military and such.
One Stop Rules Shop -- Reppy's Sig Workshop -- Getting Help Page
[violet] wrote:Maybe we could power our new search engine from the sexual tension between you two.
Char Aznable/Giant Meteor 2024! - Forcing humanity to move into space and progress whether we goddamn want to or not!

User avatar
Gregoryisgodistan
Senator
 
Posts: 3907
Founded: Jun 22, 2013
Ex-Nation

Postby Gregoryisgodistan » Mon Mar 02, 2015 7:05 pm

Reploid Productions wrote:
Gregoryisgodistan wrote:About ten years ago, my sister and I had NS accounts that have long since ceased to exist. Although I wound up creating a new nation about a year and a half ago and joined the forums, she never rejoined. Would it be possible for me to check on her behalf to see if her nation was affected since she has no NS account currently and no desire to create one?

Sure, just file a GHR telling us the account name and we can check for you. :)


Ok, thanks.
Gregoryisgodistan, population 75,000,000. All citizens are required to worship Lord Almighty Gregory, our head of state, as a deity.
IBS II Champions
Beach Cup IX Round of 16
World Indoor Soccer Championship 6 - 2nd place
BoI XIV Champion
IBS III Champions
WCoH 22 Round of 16
WB XXII 10th Place in Casaran, advanced to Round of 32
IBS IV host, champion
4th in WCoH 23
WBC 29 QF
HWC 12 hosts
WJHC VI 2nd place,
CoH 60 4th place
WCoH XXIV Champs
CoH 61 Runner-Up
IBS VI Champs
BOI XVI Host
IBS VII Champs
WCoH XXV 2nd Place
WBC 32 2nd Place
IBS VIII host and champs
WBC 33 Host/QF
WCoH 27 co-host and champs
WC 72 Qualifier
WBC 34 champs
CoH 67 Third place

User avatar
Yao
Spokesperson
 
Posts: 159
Founded: May 26, 2012
Ex-Nation

Postby Yao » Mon Mar 02, 2015 7:55 pm

Is there a way to check CTE'd nations?

User avatar
SalusaSecondus
Senior Admin
 
Posts: 354
Founded: Jun 12, 2003
Father Knows Best State

Data leak

Postby SalusaSecondus » Mon Mar 02, 2015 8:04 pm

The Union of the West wrote:
Only (encrypted) password hashes were exposed, not plaintext passwords. However, you should still change your password if it was exposed, because hashes aren't impervious to brute-force cracking by an attacker who has your data offline, especially if your password contains dictionary words.


Perhaps you should use salted hashes to encrypt the passwords. They provide better protection against dictionary attacks and rainbow table attacks.


"Encryption" isn't quite accurate. Everything is properly hashed with one-way cryptographic functions. :)

User avatar
Kaiserholt
Diplomat
 
Posts: 845
Founded: Sep 04, 2012
Father Knows Best State

Postby Kaiserholt » Mon Mar 02, 2015 8:36 pm

I checked, and my nation was not affected. But for some reason there are Chinese / Japanese characters next to my World Assembly / Dispatches toggle. Is this a game feature, or is something else wrong? I didn't put any such changes on my account.

Even though I am not affected, still changing my passwords :ugeek:
"Hello, Masaki home. Oh, that sounds like if I were married to the family. How embarrassing. What do you think? Do you think it sounds that way?"

"I have been many things in my life, Mollari. I have been silly. I have been quiet when I should have spoken. I have been foolish. And I have wasted far too much time. But I am still Centauri. And I am not afraid."

"You are elevating futility to a high art. There is nothing you can do to prevent the catharsis of spurious morality."

User avatar
Alyakia
Post Marshal
 
Posts: 18422
Founded: Jul 12, 2011
Democratic Socialists

Postby Alyakia » Mon Mar 02, 2015 10:26 pm

Kaiserholt wrote:I checked, and my nation was not affected. But for some reason there are Chinese / Japanese characters next to my World Assembly / Dispatches toggle. Is this a game feature, or is something else wrong? I didn't put any such changes on my account.

Even though I am not affected, still changing my passwords :ugeek:


could you, uh, screenshot that
pro: good
anti: bad

The UK and EU are Better Together

"Margaret Thatcher showed the world that women are not too soft or the weaker sex, and can be as heartless, horrible, and amoral as any male politician."

User avatar
[violet]
Executive Director
 
Posts: 16205
Founded: Antiquity

Postby [violet] » Mon Mar 02, 2015 10:52 pm

Kaiserholt wrote:I checked, and my nation was not affected. But for some reason there are Chinese / Japanese characters next to my World Assembly / Dispatches toggle.

This is an unrelated browser issue. Please start a new thread in Technical to report that, with a screenshot if you can.

User avatar
Kemintiri of Kemet
Envoy
 
Posts: 241
Founded: Jan 24, 2015
Ex-Nation

Postby Kemintiri of Kemet » Tue Mar 03, 2015 12:11 am

About my friend---can I GHR on their behalfs about his two nations: DEATed and CTE'd?

(It's a bit of a pain to contact him IRL (but we both can) #exitcodes #timezones)
Yo Mama|Elegy for Easter|Black of Knight|On Tagger's Fields|Raid Regions|A Thousand Days of Mourning In Honour Of My Fallen Loved One|Love-lies-bleeding|It Is Heartbreak
Կէմինտիրի Թեոդորա Շնեժ Մոնտրէսոր
Kemintiri T'yeodora Snez Montresor

100 Invader 63 Defender
Niece of Tim Stark, Escade and Solorni
Daughter of Severisen and Xoriet
Niece-by-marriage of Dalimbar
Granddaughter of Minineenee
Descendant of Astarial
Half-sister of Rirersyl
Sister of Ramaeus
Cousin of Knot

User avatar
[violet]
Executive Director
 
Posts: 16205
Founded: Antiquity

Postby [violet] » Tue Mar 03, 2015 12:30 am

Kemintiri of Kemet wrote:About my friend---can I GHR on their behalfs about his two nations: DEATed and CTE'd?

(It's a bit of a pain to contact him IRL (but we both can) #exitcodes #timezones)

Yes, we can certainly say whether their nations were affected. On the slim chance they were, we would be limited in how much detail we can give you about it.
Last edited by [violet] on Tue Mar 03, 2015 12:30 am, edited 1 time in total.

User avatar
Kemintiri of Kemet
Envoy
 
Posts: 241
Founded: Jan 24, 2015
Ex-Nation

Postby Kemintiri of Kemet » Tue Mar 03, 2015 12:33 am

[violet] wrote:
Kemintiri of Kemet wrote:About my friend---can I GHR on their behalfs about his two nations: DEATed and CTE'd?

(It's a bit of a pain to contact him IRL (but we both can) #exitcodes #timezones)

Yes, we can certainly say whether their nations were affected. On the slim chance they were, we would be limited in how much detail we can give you about it.

Thank you very much: both his nations are unaffected. :)
Last edited by Kemintiri of Kemet on Tue Mar 03, 2015 12:49 am, edited 1 time in total.
Yo Mama|Elegy for Easter|Black of Knight|On Tagger's Fields|Raid Regions|A Thousand Days of Mourning In Honour Of My Fallen Loved One|Love-lies-bleeding|It Is Heartbreak
Կէմինտիրի Թեոդորա Շնեժ Մոնտրէսոր
Kemintiri T'yeodora Snez Montresor

100 Invader 63 Defender
Niece of Tim Stark, Escade and Solorni
Daughter of Severisen and Xoriet
Niece-by-marriage of Dalimbar
Granddaughter of Minineenee
Descendant of Astarial
Half-sister of Rirersyl
Sister of Ramaeus
Cousin of Knot

User avatar
Alexanda
Ambassador
 
Posts: 1640
Founded: May 10, 2014
Ex-Nation

Postby Alexanda » Tue Mar 03, 2015 1:57 pm

For security reasons, I have deleted my E-Mail from the settings page, and resigned from the World Assembly. Does that ensure that, if my nation is involved in a future leak and information is released, my E-Mail shan't be made public?
I do not use N.S Tracker.
PRO: Conservative Party, Christianity, Thatcherism, Margaret Thatcher, Privatisation, Capitalism, Monarchy, Democracy, British Commonwealth
ANTI: Socialism, Communism, Homosexual Marriage, Homophobia, E.U dominance of the U.K, State-owned industries, Terrorism
My condolences to those who were killed in the recent terror attacks, and may God help us defeat the twisted ideology which prompted such evil!

User avatar
Kocahisar
Civil Servant
 
Posts: 8
Founded: Feb 14, 2015
Ex-Nation

Postby Kocahisar » Tue Mar 03, 2015 2:49 pm

Alexanda wrote:For security reasons, I have deleted my E-Mail from the settings page, and resigned from the World Assembly. Does that ensure that, if my nation is involved in a future leak and information is released, my E-Mail shan't be made public?

the email could still be in the server
98% of all Internet users would cry if Facebook broke down. If you are part of that 2% who simply would sit back and laugh, copy and paste this into your sig.

PreviousNext

Advertisement

Remove ads

Return to Technical

Who is online

Users browsing this forum: Azmeny, Bormiar, Caranelia, Greater New Orleans, Khantin, Micro Gettysburg, Northern Valmont, Patriums, The Endless Eventide, The Scandoslavic Empire, Volaworand

Advertisement

Remove ads