NATION

PASSWORD

Data leak

Bug reports, general help, ideas for improvements, and questions about how things are meant to work.

Advertisement

Remove ads

User avatar
[violet]
Executive Director
 
Posts: 16205
Founded: Antiquity

Postby [violet] » Tue Mar 03, 2015 3:01 pm

Alexanda wrote:For security reasons, I have deleted my E-Mail from the settings page, and resigned from the World Assembly. Does that ensure that, if my nation is involved in a future leak and information is released, my E-Mail shan't be made public?

Not completely, no. Your old email address will almost certainly still be stored somewhere, such as in backups, logfiles, and a 'prior emails' utility we use for nation recovery (and in the Data Leak Checker tool, to tell you whether an older nation of yours might have been affected). If you are concerned about this, please contact us. Which I see you've done, so I'll discuss it with you further privately there.

User avatar
Xmara
Negotiator
 
Posts: 5373
Founded: Mar 31, 2014
Left-Leaning College State

Postby Xmara » Tue Mar 03, 2015 4:18 pm

How will the data leak affect the victim nations? I was fortunately not affected.

Also I estimated that if only 0.08% of the world was affected, then the leak affected 10 nations (but you probably already knew that).
/ˈzmaːrʌ/
Info
Our Leader
Status- Code Green- All clear
I mostly use NS stats, except for population and tax rates.
We are not Estonia.
A 16.8 civilization, according to this index.
Flag Waver



Support
Ukraine

User avatar
Valrifell
Post Czar
 
Posts: 31063
Founded: Aug 18, 2013
Ex-Nation

Postby Valrifell » Tue Mar 03, 2015 4:38 pm

Xmara wrote:How will the data leak affect the victim nations? I was fortunately not affected.

Also I estimated that if only 0.08% of the world was affected, then the leak affected 10 nations (but you probably already knew that).


Except this leak affected 0.08% of all nations created in the history of ever.
HAVING AN ALL CAPS SIG MAKES ME FEEL SMART

User avatar
Mesoland
Senator
 
Posts: 4069
Founded: Feb 12, 2011
Ex-Nation

Postby Mesoland » Tue Mar 03, 2015 4:38 pm

Xmara wrote:How will the data leak affect the victim nations? I was fortunately not affected.

Also I estimated that if only 0.08% of the world was affected, then the leak affected 10 nations (but you probably already knew that).

It seems as though it affected CTEs as well. A puppet of mine that had been dead for over two years was affected by the leak.

User avatar
[violet]
Executive Director
 
Posts: 16205
Founded: Antiquity

Postby [violet] » Tue Mar 03, 2015 5:20 pm

Xmara wrote:How will the data leak affect the victim nations? I was fortunately not affected.

Also I estimated that if only 0.08% of the world was affected, then the leak affected 10 nations (but you probably already knew that).

About 10 live nations (actually 17), but also a little over three thousand ex-nations. Details are in the News post.

If affected, the primary problem is that password hashes were exposed, which means that potentially an unknown person could have downloaded the file, viewed it, set to work cracking the password hashes, and, if successful, could then revive the nations and take control of them. For those that had email addresses set, the larger concern is probably that the same combination of email address and password might have been used by the player on other, more important sites, like their email host or bank. Which is bad practice and why you shouldn't do that. But what internet bad guys do is look for email/password combinations and try them on other sites, hoping the user might have used them there, too.

User avatar
Xmara
Negotiator
 
Posts: 5373
Founded: Mar 31, 2014
Left-Leaning College State

Postby Xmara » Tue Mar 03, 2015 5:36 pm

So it attacked dead nations too?

I had a nation on here about 3 years ago (Tiggerland) that ceased to exist and I never recovered it. How do I know if it was affected?
/ˈzmaːrʌ/
Info
Our Leader
Status- Code Green- All clear
I mostly use NS stats, except for population and tax rates.
We are not Estonia.
A 16.8 civilization, according to this index.
Flag Waver



Support
Ukraine

User avatar
Reploid Productions
Director of Moderation
 
Posts: 30507
Founded: Antiquity
Democratic Socialists

Postby Reploid Productions » Tue Mar 03, 2015 5:39 pm

Xmara wrote:So it attacked dead nations too?

I had a nation on here about 3 years ago (Tiggerland) that ceased to exist and I never recovered it. How do I know if it was affected?

Drop us a line asking about the nation name via the Getting Help page, and we can check for you. :)
Forum mod since May 8, 2003 -- Game mod since May 19, 2003 -- Nation turned 20 on March 23, 2023!
Sunset's DoGA FAQ - For those using DoGA to make their NS military and such.
One Stop Rules Shop -- Reppy's Sig Workshop -- Getting Help Page
[violet] wrote:Maybe we could power our new search engine from the sexual tension between you two.
Char Aznable/Giant Meteor 2024! - Forcing humanity to move into space and progress whether we goddamn want to or not!

User avatar
Allancia
Negotiator
 
Posts: 6571
Founded: Jul 24, 2013
Ex-Nation

Postby Allancia » Tue Mar 03, 2015 5:39 pm

Xmara wrote:So it attacked dead nations too?

I had a nation on here about 3 years ago (Tiggerland) that ceased to exist and I never recovered it. How do I know if it was affected?


You can revive nations very easily. Just type in its name, and put in its old password.
"One of the great things about books is sometimes there are some fantastic pictures."
-George Bush

User avatar
Xmara
Negotiator
 
Posts: 5373
Founded: Mar 31, 2014
Left-Leaning College State

Postby Xmara » Tue Mar 03, 2015 5:42 pm

...except I lost the password. That's why it died in the first place.
/ˈzmaːrʌ/
Info
Our Leader
Status- Code Green- All clear
I mostly use NS stats, except for population and tax rates.
We are not Estonia.
A 16.8 civilization, according to this index.
Flag Waver



Support
Ukraine

User avatar
Sad-States
Envoy
 
Posts: 207
Founded: Oct 04, 2013
Ex-Nation

Postby Sad-States » Tue Mar 03, 2015 6:45 pm

I use LastPass, a very good service that holds all of your passwords. You can randomly generate passwords as well, and LP is a very safe program in my eyes and as well in others. Lifehacker released an article stating why it's safe and discussing the common question people think of when thinking about using LP, 'What if Lastpass gets hacked?' I am sure there are many other articles on the internet as well supporting all of this.

Lastpass: https://lastpass.com/
Lifehacker's Article: http://lifehacker.com/is-lastpass-secure-what-happens-if-it-gets-hacked-1555511389
Last edited by Sad-States on Tue Mar 03, 2015 6:48 pm, edited 1 time in total.
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
- Former Magister to The East Pacific | Former Officer to the EPSA | Former Officer of HR to The Rejected Realms | -
- Former Evocatus to Legio Pacifica -
Proud Warden to the Order of The Grey Wardens
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-

User avatar
Edgy Opinions
Senator
 
Posts: 4400
Founded: Dec 31, 2014
Ex-Nation

Postby Edgy Opinions » Tue Mar 03, 2015 6:53 pm

Sad-States wrote:I use LastPass, a very good service that holds all of your passwords. You can randomly generate passwords as well, and LP is a very safe program in my eyes and as well in others. Lifehacker released an article stating why it's safe and discussing the common question people think of when thinking about using LP, 'What if Lastpass gets hacked?' I am sure there are many other articles on the internet as well supporting all of this.

Lastpass: https://lastpass.com/
Lifehacker's Article: http://lifehacker.com/is-lastpass-secure-what-happens-if-it-gets-hacked-1555511389

I used DoNotTrackMe and MaskMe, but apparently these became an extension called "Blur" that I don't yet understand.

MaskMe is still functional here. It's responsible for this service.

Point is, they it generated disguised email addresses that allowed content to be directly sent to my inbox, but didn't actually reveal my identity. (i.e. my true email address.)
Last edited by Edgy Opinions on Tue Mar 03, 2015 9:09 pm, edited 1 time in total.
Kotturheim's contagious despair.
100% self-impressed 20-year-old cadoneutrois-pangender imprigender genderblur fluidflux bi-pan/gray-ace/gray-aro Brazilian.
Into: your gender, anarchism/communism, obliteration of kyriarchy, environment, other obvious '-10.00, -9.13 in political compass' stuff
Anti: your gender (undo it interacting with me), Born This Way (also medicalism/pathologization/eugenics), outer space, abuse/predation, owners, power, hierarchy, internalization/privilege goggles (essential to the continuity of identity with power/hierarchy systems), essentialism/determinism, nihilism/defeatism

User avatar
Neplandia
Political Columnist
 
Posts: 2
Founded: Feb 19, 2015
Ex-Nation

Postby Neplandia » Tue Mar 03, 2015 9:01 pm

ow
wowwww

User avatar
Dakran
Minister
 
Posts: 2506
Founded: Dec 06, 2012
Civil Rights Lovefest

Postby Dakran » Wed Mar 04, 2015 12:50 am

I'll be honest, I thought the news bit was a hacker trying to get our accounts. Glad to see I was just being paranoid.
Trans flag here She/Her
01_EMBASSY_PROPOSE
WHAT WAS WILL BE, WHAT WILL BE WAS, WHAT WAS WILL BE, WHAT WILL BE WAS, WHAT WAS WILL BE, WHAT WILL BE WAS
Baltenstein wrote:Source:
The Turkish minister of Turkishness, Öztürk Türkuglu.

User avatar
The Blaatschapen
Technical Moderator
 
Posts: 63226
Founded: Antiquity
Anarchy

Postby The Blaatschapen » Wed Mar 04, 2015 3:23 pm

Deian salazar wrote:So is this thread going to be a permanent data leak thread or will this be deleted soon?
Just wondering, thanks!


This will eventually be removed from the top of the forums. It won't be deleted. Maybe moved around a bit, or slowly sink to the bottom of the Technical forum.
The Blaatschapen should resign

User avatar
[violet]
Executive Director
 
Posts: 16205
Founded: Antiquity

Postby [violet] » Wed Mar 04, 2015 9:25 pm

Changing thread from a Global Announcement to a regular topic. It's linked from the News post.

User avatar
Idzequitch
Post Marshal
 
Posts: 17033
Founded: Apr 22, 2014
Scandinavian Liberal Paradise

Postby Idzequitch » Thu Mar 05, 2015 3:17 am

Hi, I filed a GHR about a concern I had concerning the leak. It's been over 24 hours now with no response. I realize that you all are busy, and that you have lives outside of NS, and I certainly don't want to sound impatient or ungrateful for all that you do. I appreciate how transparent and diligent you all have been through this fiasco, and I would just like to confirm that my GHR has been received and will be addressed sometime fairly soon. Thank you.
Twenty-something, male, heterosexual, Protestant Christian. Politically unaffiliated libertarian-ish centrist.
Meyers-Briggs INFP.
Enneagram Type 9.
Political Compass Left/Right 0.13
Libertarian/Authoritarian -5.38
9Axes Results

I once believed in causes too, I had my pointless point of view, and life went on no matter who was wrong or right. - Billy Joel

User avatar
[violet]
Executive Director
 
Posts: 16205
Founded: Antiquity

Re: Data leak

Postby [violet] » Thu Mar 05, 2015 4:37 am

Idzequitch wrote:Hi, I filed a GHR about a concern I had concerning the leak. It's been over 24 hours now with no response. I realize that you all are busy, and that you have lives outside of NS, and I certainly don't want to sound impatient or ungrateful for all that you do. I appreciate how transparent and diligent you all have been through this fiasco, and I would just like to confirm that my GHR has been received and will be addressed sometime fairly soon. Thank you.

No, I don't have a GHR from you. Can you submit again? We have been keeping up with all inquiries.

User avatar
Idzequitch
Post Marshal
 
Posts: 17033
Founded: Apr 22, 2014
Scandinavian Liberal Paradise

Postby Idzequitch » Thu Mar 05, 2015 4:52 am

[violet] wrote:
Idzequitch wrote:Hi, I filed a GHR about a concern I had concerning the leak. It's been over 24 hours now with no response. I realize that you all are busy, and that you have lives outside of NS, and I certainly don't want to sound impatient or ungrateful for all that you do. I appreciate how transparent and diligent you all have been through this fiasco, and I would just like to confirm that my GHR has been received and will be addressed sometime fairly soon. Thank you.

No, I don't have a GHR from you. Can you submit again? We have been keeping up with all inquiries.

Done.
Twenty-something, male, heterosexual, Protestant Christian. Politically unaffiliated libertarian-ish centrist.
Meyers-Briggs INFP.
Enneagram Type 9.
Political Compass Left/Right 0.13
Libertarian/Authoritarian -5.38
9Axes Results

I once believed in causes too, I had my pointless point of view, and life went on no matter who was wrong or right. - Billy Joel

User avatar
Idzequitch
Post Marshal
 
Posts: 17033
Founded: Apr 22, 2014
Scandinavian Liberal Paradise

Postby Idzequitch » Thu Mar 05, 2015 3:56 pm

Idzequitch wrote:
[violet] wrote:No, I don't have a GHR from you. Can you submit again? We have been keeping up with all inquiries.

Done.

Was my GHR received this time?
Twenty-something, male, heterosexual, Protestant Christian. Politically unaffiliated libertarian-ish centrist.
Meyers-Briggs INFP.
Enneagram Type 9.
Political Compass Left/Right 0.13
Libertarian/Authoritarian -5.38
9Axes Results

I once believed in causes too, I had my pointless point of view, and life went on no matter who was wrong or right. - Billy Joel

User avatar
[violet]
Executive Director
 
Posts: 16205
Founded: Antiquity

Postby [violet] » Thu Mar 05, 2015 5:38 pm

Idzequitch wrote:Was my GHR received this time?

I've replied to you via TG, yes. No nations you mentioned were affected.

User avatar
Ever-Wandering Souls
Negotiator
 
Posts: 7267
Founded: Jan 01, 2014
Father Knows Best State

Postby Ever-Wandering Souls » Thu Mar 05, 2015 6:15 pm

I've noticed the dates in question are absent from the Archives - is there any plan to restore uncorrupted versions of the files in question to the archives?

If you don't have the files on hand, they're all available for download here (one of Afforess' things, I think). As far as I can tell, the files on there were collected from the initial, proper, public releases.

I mean it's not a huge thing in the grand scheme :P
Last edited by [violet] on Thu Mar 05, 2015 10:50 pm, edited 1 time in total.
Proud Raider; General of The Black Hawks, Ret.
TG me anytime; I'm always happy to talk about anything!

The Alicorns (Equestria) wrote:Let them stay, no need to badmouth them...From our view a bunch of nations just came in, seized the delegate position, and changed a few superficial things...we play NationStates differently...there's really no reason for us to be butthurt.
http://www.nationstates.net/page=rmb/postid=8944227
http://www.nationstates.net/page=rmb/postid=8951258

Misley wrote:
Hobbesistan wrote:Don't think I understand the question.
The color or what?..

Jesus, Hobbes, it's 2015. You can't just call someone "the color".

Reploid Productions wrote:Raiders are endlessly creative

How Do I Telegram API?

Omnis delenda est.

User avatar
[violet]
Executive Director
 
Posts: 16205
Founded: Antiquity

Postby [violet] » Thu Mar 05, 2015 10:50 pm

Yep, thanks.

User avatar
Ever-Wandering Souls
Negotiator
 
Posts: 7267
Founded: Jan 01, 2014
Father Knows Best State

Postby Ever-Wandering Souls » Fri Mar 06, 2015 3:48 pm

No, Thank you :)
Proud Raider; General of The Black Hawks, Ret.
TG me anytime; I'm always happy to talk about anything!

The Alicorns (Equestria) wrote:Let them stay, no need to badmouth them...From our view a bunch of nations just came in, seized the delegate position, and changed a few superficial things...we play NationStates differently...there's really no reason for us to be butthurt.
http://www.nationstates.net/page=rmb/postid=8944227
http://www.nationstates.net/page=rmb/postid=8951258

Misley wrote:
Hobbesistan wrote:Don't think I understand the question.
The color or what?..

Jesus, Hobbes, it's 2015. You can't just call someone "the color".

Reploid Productions wrote:Raiders are endlessly creative

How Do I Telegram API?

Omnis delenda est.

User avatar
Tresmius
Secretary
 
Posts: 32
Founded: Sep 29, 2006
Iron Fist Consumerists

Postby Tresmius » Sat Mar 07, 2015 9:16 pm

Thanks for the notice, would've been much easier to just not mention it but the right thing was done and prudently so. Fortunately Tres wasn't affected.

User avatar
Seanchain
Civilian
 
Posts: 1
Founded: May 29, 2011
Ex-Nation

Postby Seanchain » Wed Mar 11, 2015 1:50 am

Nowhere have I seen an information leak handled as openly and as well as here in NS. The users were informed, the nature and amount of leaked information was clearly stated and the technical aspects were openly given.

After reading this news I still fully trust NS. I hope others will do the same. Thank you for excellent handling of this incident!

PreviousNext

Advertisement

Remove ads

Return to Technical

Who is online

Users browsing this forum: Aelyria, Ariesee, Battadia, Cambany, Doughworld, Gegia, James R Kennedy, Knothole and Brunswick, Mestovakia, Patriums, Roxium, Shattered Cascadia, Verderiesdre

Advertisement

Remove ads