Jun 19, 2011

Sega Hacked, 1.3M Accounts Stolen. How Long Before Steam?

http://www.ibtimes.com/articles/165499/20110619/sega-hacked-1-3-million-users-information-compromised.htm

And in a show of mass stupidity that explains just how disconnected mass media is from the entire situation - almost every article comments about how LulzSec wants to help track down the hackers. Apparently they all missed the sarcasm in the LulzSec twitter post they are referencing. What's really interesting - the LulzSec twitter post was made two days before Sega announced it was hacked...

How long before our Steam accounts are compromised? I recommend everyone make sure your steam password is NOT the same as your email password. With both logins the same, there's no strength behind the Steam two-factor authentication, because it relies on sending you an email. If your steam password gets hacked, and the password is the same on the email account attached to your steam account, you're done.

And don't think that "encrypting" passwords by the company does any good. I've seen someone demonstrate using four nVidia video cards to crack passwords to the tune of thousands of passwords decrypted per minute. You gotta figure with four nvidia 580 cards, you get 2048 CPU cores that can be used to crack passwords simultaneously - they fall like cards.

Oh, and the password you DO use for steam? I'd recommend at least 12 characters or longer. It's only a matter of time.

No comments:

Post a Comment