NeoGAF & ResetERA - The Hilarious N̶e̶v̶e̶r̶e̶n̶d̶i̶n̶g̶ Splintering "Gaming" Forum Circus

  • 🔧 At about Midnight EST I am going to completely fuck up the site trying to fix something.
Holy shit, way to kick the proverbial Hornets' nest. All the VIPs are joining the party too, seems i slept through this one as well. :(
 
  • Like
Reactions: lemmiwinks
Holy shit, way to kick the proverbial Hornets' nest. All the VIPs are joining the party too, seems i slept through this one as well. :(

Hecht has been drinking and being angry on Twitter at @sophnar0747 for a week or so now, it must be killing him inside yet again she's more responsible than the owner and admins of Resetera for telling the users of a breach.

IFBIKvo.png


I think you'll find most of Resetera comes to Kiwifarms to laugh at other users and the staff. It's not as if self-reflection or fun is allowed on your forum is it?

Many prominent Resetera members have Kiwifarms accounts. How do you think discord chatlogs leak all the time?

:cunningpepe:
 
Last edited:
Playing whack a mole with compromised accounts doesn't really scream security, dudes.

La46I5P.png


"We're just going to claim with absolutely no public evidence whatsoever that we think SOME of it was another websites fault and not ours".

Bullet-proof denial B-Dubs. Wouldn't want mass panic and members fleeing the forum that is already trending downwards when Isamu will be angry with you at the next New York financial meeting.

Cm6sO1Y.png


You should be blaming Resetera for that my furry friend...

Capture d’écran de 2020-03-06 19-06-14.png
 
Last edited:
did you forget to log out before taking the screenshot? :cunningpepe:
if not we really need some sauce on this one, where did you get the pic from?

That login is the CyberWolf account so it doesn't matter lol.

It's not me but I know of one source. There will be more to come

:semperfidelis:

B-Dubs and friends thinking they can just tell everyone it's the alt-right and Russia isn't going to fly. Not very nice how they spoke about Sophia Narwitz either! Have some manners Hecht and Larry.
 
View attachment 1176254

"We're just going to claim with absolutely no public evidence whatsoever that we think SOME of it was another websites fault and not ours".

Bullet-proof denial B-Dubs. Wouldn't want mass panic and members fleeing the forum that is already trending downwards when Isamu will be angry with you at the next New York financial meeting.

View attachment 1176263

You should be blaming Resetera for that my furry friend...

View attachment 1176262

1583526789215.png


Holy fuck, B-Dubs is handling this in the most possible exceptional way. What a great GENERAL MANAGER. LOL hello dear sheep please just believe us nothing has leaked we promise lol because reasons. Why not dox yourself some more with 2-factor though?? Also the alt-right did it!

Says the technically inept janitor who is handling this with North Korean levels of transparency. No respect whatsoever for the private information of his users. Even Null is a fucking shining star of security and technical knowledge compared to the REEE cunts.
 
myL2fLk.png

hdYOgs9.png

OMG everyone, @sophnar0747 and Russia are behind the breach and the discord pedo chatrooms were fake news! Even although the mods then went on to ban lots of Resetera users for sexualizing children

:thinking:

These could be appearing on Resetera soon, beware B-Dubs, Plagiarize, Jarmel and Volimar! PedoEra discord was fake? Staff aren't harboring pedophiles when there is pedophiles on staff? Hmmm.





GUssfyZ.png


Ah yes, better lock it down and make it go away, just like how NeoGAF handled Amir0x.

But will it go away?

:thinking:

In other news, racist creator of Halo, Stinkles (aka Frank O'Connor), is being unbanned soon


YcyDt7y.png


*sigh*

D66xexr.png


NPqMEbk.png




So they said the breach was over. B-Dubs claimed everything was under control and not to worry. Why does anyone believe these people?

But it's all okay, ignore the breach.
 
Last edited:
Whoever you are hackerman, you're doing God's work making Hecht drain another bottle of MD 20/20. :semperfidelis:
B-Dubs, playing whack-a-mole with a professional troll who's just getting started for the weekend is a losing proposition, you might as well tell the class just how hard you fucked up today.
 
  • Feels
Reactions: UnclePhil
I don't understand this "password leak". The passwords in the database should at least be salted and hashed. I'm pretty sure this is the default for XenForo. I don't know how you can screw that up. Brute-forced passwords is a lazy excuse for a sysadmin to give. Brute-forcing in reality, especially over the internet, is not very practical or likely.

Recommending 2FA in instances of a DB breach is not a real solution since the secret component is also stored in the DB. 2FA protects the users from leaking their own passwords, and does not protect users from DBs dumps.

Without seeing the leak myself it's hard to say what actually happened.

The real concern for a DB leak would be email addresses, IPs and non-public posts/messages. Due to ResetEra's registration policy leaking someone's registered email is effectively the equivalent to doxing. ResetEra can't do anything about this, other than change their registration policy (which they won't).

Here's some free technical advice.
1. reset all passwords
2. audit all server-side files for code that has been added post-vanilla XF
3. make sure everything is up to date
4. review logs, file timestamps (both of which can be faked, but check it anyways)

Cerium, I know you don't pay your staff, but make sure you pay your sysadmins.

Reminder that security breaches are a externality, they do not harm ResetEra LLC, they harm the users of ResetEra LLC's products. Ultimately it's just a PR issue, and if they can avoid the PR issue, they come out the other side untouched regardless of whether the breach actually happened or not.
 
So there is a data breach apparently? Well this should not be a surprise to anyone that actually knows shit about computers and cyber security as well and ResetEra requires users to have a paid, personal, school/business, or professional email account in order to even use their service anyway (for those that are living under a rock you can't use free email services like Gmail, Yahoo Mail, or even Protonmail to sign up for the website either).

Now as some words of advice; never, ever use an email that just reads 'yournamehere@thisiswhereIwork/study/theplaceIliveat.com' when you sign up for things such as social media, forums, and also other things related to entertainment (in this case it's video games) and it's really because the moment that these types of email usernames and even IP Addresses are obtained then you can considered yourself doxxed by that point.

The common sense route is just to use an email address that doesn't reveal who you really are in real life and also use something such as a VPN, Tor, or at least a proxy to hide your real IP Address but it's ResetEra so they are stupid and incompetent.

And as for the hackers (if they even obtained this sensitive information), they are not at fault here since ResetEra made it this easy for them to break in and then steal sensitive information such as email addresses, IP Addresses, and probably other things too.

It was only a matter of time until a vigilante hacker or a group of vigilante hackers had enough and decided to teach ResetEra a lesson and they have no one else to blame but themselves since they were asking for it for a long time.

Now the lesson here is that don't make yourself to be loathed by the rest of the Internet because eventually someone is going to put you in your place and no one is going to feel bad for you and no one is going to feel sorry for you either.
 
Last edited:
Back