Postmortem Site compromised 10-Sep-2019

Status
Not open for further replies.
I lost the login to the throwaway email I used to make my account. Is there another way to change my password or do I make a new email and set it up so that I can just use that one instead?
Change your email to a new throwaway email with your current password, then use that email to confirm your new password. I think that should work.
 
The hottest of takes.

ABA8E6BA-7761-460A-9A93-8CCCFA199770.jpeg
 
- They can't do anything with that information unless they have a good legal grounds for isp subpoena
- Which 90% of the means nothing will happen.
- ISP geolocation tools are full of shit and are not even vaguely correct.
- Unless your email is MyRealName1992@ImExceptional.com nothing will happen.
There's a few caveats to this.

If you're browsing from a school or business then check your hostname as some can go as far as include the building you're in. There was also that time when O2 or whoever put peoples phone numbers in their hostname on 4G.

Geolocating IPs is surprisingly better than it was. For the UK everything used to be reported as London or Birmingham but now they can often get the closest big town. This could be close enough to confirm if a user is someone you already suspect.

In all other cases, if you have any kind of home DSL in the UK then you have a dynamic IP which is almost worthless to know because you can change it yourself at any time. Cable is dynamic too but is much sticker so to change it you might have to leave your modem off for a week or spoof the MAC address (or own multiple modems and swap between them).
 
  • Like
Reactions: Dork Of Ages
@Null I'm sure you probably know by now, but this wasn't done in a day. When I was poking at who was watching what threads to see if there was a Zoe Quinn connection, I noticed one of the files had the phrase
"There are multiple happenings, which is why I, a humble public servant, have
categorized them for you. "
This is the banner from at least a week ago if my memory serves me correctly. They've been in your account for a while.
 
So this is probably a stupid question, but someone mentioned that the only people who were compromised were the ones logged in yesterday. But here's the thing, which site address does it count? Because me and a few others had noticed that one could be logged in on .net but not on .is and the others
 
Status
Not open for further replies.
Back