Jump to content

Account Security Updates & Notice


Cipher

Recommended Posts

  • City Council

Hey everyone, we've been seeing an increase in the frequency of accounts being compromised using information from data breaches, so we felt it was important to provide some resources for keeping your accounts safe and update the community on what we're doing to help.

 

Firstly, over the past week or so we've seen a significant increase in unauthorized account access on the forums. The primary goal of this unauthorized access has been for the purpose of spamming, and some of the spam posts you've seen from older accounts fall within this category (although it is worth noting that the huge majority are from new registrations). Most of the time, this is done through automated scripts which associate email addresses and usernames shared across different services with passwords that have been breached and leaked to the public. Unfortunately, many people use a common / shared password for multiple services, so when a breach occurs, they'll often find that an attacker is able to gain access to their accounts on other services too.

 

While it may seem convenient to use a single password online, it puts you at risk when any service or website experiences a data breach. Instead, you should aim to use strong passwords, containing a mixture of uppercase and lowercase characters in addition to numbers and symbols, and use a unique password for each account or service. Alternatively, you can utilize a password manager such as 1Password to automatically generate and manage randomized passwords for you. If you believe that a service that you use has experienced a data breach and you use a shared password, then I would highly suggest changing your password for Homecoming. To manage your password for Homecoming, access your Account Settings in the user drop-down (see below) or click here.

 

Another thing you can take advantage of which should be offered by most websites, including our own, is multi-factor authentication (AKA 2-factor authentication). This helps secure your account by requiring an additional step after providing your password to verify your identity. This can include anything from TOTP apps such as Google Authenticator or Authy to receiving an SMS message or email with a code. To manage your multi-factor authentication for Homecoming, access your Account Settings in the user drop-down (see below) or click here.

 

image.png.4747594618291097ad4bea47356c4452.png

How to find Account Settings

 

Finally, in order to help combat unauthorized account access, we've created a new device authorization system which is layered over top of Invision's existing login and multi-factor authentication systems. As of the time of this post, any time you attempt to sign into your Homecoming account from a new device, you will be prompted to authorize your device via a link sent to your registered email address. Once you've authorized a device for your account, you will be able to sign out and back in without going through the authorization process again.

 

Here are some additional resources regarding account and cyber security I would recommend:

 

If you have any questions about anything, please feel free to reach out via support or even message me personally on the forums.

 

Thanks

  • Like 3
  • Thanks 10
  • Thumbs Up 6

Cipher

City Council

 

If you need help, please submit a support request here or use /petition in-game.

 

Got time to spare? Want to see Homecoming thrive? Consider volunteering as a Game Master!

Link to comment
Share on other sites

Thanks for posting this. I was looking for this before logging in because the log-in system had change, and I was suspicious of what was going on.

This should help other know that it is safe to use the new login system.

  • Thumbs Up 1

If someone posts a reply quoting me and I don't reply, they may be on ignore.

(It seems I'm involved with so much at this point that I may not be able to easily retrieve access to all the notifications)

Some players know that I have them on ignore and are likely to make posts knowing that is the case.

But the fact that I have them on ignore won't stop some of them from bullying and harassing people, because some of them love to do it. There is a group that have banded together to target forum posters they don't like. They think that this behavior is acceptable.

Ignore (in the forums) and /ignore (in-game) are tools to improve your gaming experience. Don't feel bad about using them.

Link to comment
Share on other sites

  • 3 weeks later

Another big tip about passwords that people tend to overlook: length of password, aka more characters... 8 characters is NOT enough... but having 15-18 or even more makes it exponentially harder to break (or brute-force as it is properly called).

And as super long passwords and massively complex mixes of symbols, letters and numbers are impossible for humans to remember without writing them down

 

==> use passphrases

 

that is 3-4 words with at least 15 characters in total(because "you & me" kinda defeats the purpose...)

like "Pacific Soccer 100%"

Pick words that you neither love nor hate (and cannot be guessed through your social media accounts: kid/pet names, holidays, childhood places)

 

If you speak multiple languages: mix it up 😎

If you feel comfortable with Freakshow lingo: us3 L33t b3c4u$3 1t'$ cººl & tr€ndy

 

For each single character you add to your passwords, you make the task exponentially more difficult for the criminals out there... 12 should be minimum... 15 is good... 20+ you're a BEAST 🥳

 

by the way @Homecoming Staff: what is the MAX length of passwords that the server/software can technically handle?

(and what happens if you use a password that's longer? 😇 hihi, no need to answer this second question 😉)

 

Edited by Spectral
  • Like 1
Link to comment
Share on other sites

4 hours ago, Spectral said:

that is 3-4 words with at least 15 characters in total(because "you & me" kinda defeats the purpose...)

like "Pacific Soccer 100%"

Pick words that you neither love nor hate (and cannot be guessed through your social media accounts: kid/pet names, holidays, childhood places)

 

Using words in password makes them less safe.

If someone posts a reply quoting me and I don't reply, they may be on ignore.

(It seems I'm involved with so much at this point that I may not be able to easily retrieve access to all the notifications)

Some players know that I have them on ignore and are likely to make posts knowing that is the case.

But the fact that I have them on ignore won't stop some of them from bullying and harassing people, because some of them love to do it. There is a group that have banded together to target forum posters they don't like. They think that this behavior is acceptable.

Ignore (in the forums) and /ignore (in-game) are tools to improve your gaming experience. Don't feel bad about using them.

Link to comment
Share on other sites

  • 2 weeks later

@UltraAlt

Using longer passwords with words is safer than shorter passwords with random letters+numbers+symbols that nobody can remember. Simply due to the exponential nature of that equation... https://xkcd.com/936/

image.png.4e0913f3406df6efb138f0bd8d5fa697.png

Hence why I insisted on 15 chars minimum. And why I suggested tricks like S->$ or E->€ ... Humans can remember these passwords

 

Of course 15 random letters+numbers+symbols would be best "in theory". In reality, they are a pain to type and users get frustrated with the entire password nightmare to begin with and "we" end up with passwords on post-it or in Excel/Word/... files that are not secured...

 

At least the post-it/files should be replaced with some Password Vault thing (https://en.wikipedia.org/wiki/List_of_password_managers).

 

With the Password Vault we go back to: you need at least one good and strong password... 8 chars is clearly known by all Cybersec people to be "not nearly enough"... 8 char can be broken in seconds via brute-force/rainbow tables/... Writing the password to the password vault on a post-it or file is equally unsafe...

 

 

It's about convincing users to have longer passwords and make those less painful... or (what the cybersec industry is currently pushing) passwordless MFA (Biometrics + Token). But password-less MFA means upgrading a long list of legacy software. And until then we'd want to convince users to be safe instead of being annoyed&lazy.

https://www.isaca.org/resources/isaca-journal/issues/2019/volume-1/nists-new-password-rule-book-updated-guidelines-offer-benefits-and-risk

  • Like 2
  • Thumbs Up 1
Link to comment
Share on other sites

Didn't realize we now had 2FA for the forums (which also protect our game accounts.

OG Server: Pinnacle  <||>  Current Primary Server: Torchbearer  ||  Also found on the others if desired


Installing CoX:  Windows  ||  MacOS  ||  MacOS for M1  <||>  Migrating Data from an Older Installation


Clubs: Mid's Hero Designer  ||  PC Builders  ||  HC Wiki  ||  Jerk Hackers


Old Forums  <||>  Titan Network  <||>  Heroica! (by @Shenanigunner)

 

Link to comment
Share on other sites

19 hours ago, WanderingAries said:

Didn't realize we now had 2FA for the forums (which also protect our game accounts.

 

There was a bot-invasion, forum-spamming attack.

The extra layer of protection for out game accounts was really just a side-effect or special effect ... I guess you could color customise it if you really wanted to.

If someone posts a reply quoting me and I don't reply, they may be on ignore.

(It seems I'm involved with so much at this point that I may not be able to easily retrieve access to all the notifications)

Some players know that I have them on ignore and are likely to make posts knowing that is the case.

But the fact that I have them on ignore won't stop some of them from bullying and harassing people, because some of them love to do it. There is a group that have banded together to target forum posters they don't like. They think that this behavior is acceptable.

Ignore (in the forums) and /ignore (in-game) are tools to improve your gaming experience. Don't feel bad about using them.

Link to comment
Share on other sites

On 3/5/2023 at 7:55 AM, Spectral said:

Humans can remember these passwords

 

I will not divulge my secrets.
Never take off your mask.

 

On 3/5/2023 at 7:55 AM, Spectral said:

users get frustrated with the entire password nightmare

 

I'm sure they would get much more frustrated if someone stole their game account or, even worse, their bank accounts or stock portfolios.

Increased password length, upper and lower characters, numbers, and special characters mixed are always suggested along with a different password for every account/website.

I think I heard someone say "no pain, no gain" If you think your password is a pain to type in then you are most likely gaining a greater degree of security. And something like "an ounce of prevention is worth a pound of cure". I'm sure there are more that are relevant.

To me, all of this is obvious, but so is using decent anti-virus and having a functional firewall  (or 2)

If someone posts a reply quoting me and I don't reply, they may be on ignore.

(It seems I'm involved with so much at this point that I may not be able to easily retrieve access to all the notifications)

Some players know that I have them on ignore and are likely to make posts knowing that is the case.

But the fact that I have them on ignore won't stop some of them from bullying and harassing people, because some of them love to do it. There is a group that have banded together to target forum posters they don't like. They think that this behavior is acceptable.

Ignore (in the forums) and /ignore (in-game) are tools to improve your gaming experience. Don't feel bad about using them.

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...