Visit the United States Poker Community | Visit the California Poker Community | Read more about the Launch of P5s Local
-
it has been vaguely discussed once in a while, but i still do not understand all the ways one can be hacked
just for sake of argument, if someone has a secure and different password and security questions on all of their accounts (email, sites, etc), and they never download any unknown links or files, how do they get hacked?
i may be the only idiot who doesn't fully comprehend how it works, but i think understanding where the risk comes from might help some to prevent it
edit: i always hear about keyloggers and all these hacker words, but what i don't understand is HOW hackers are able to use them on someone...and again, my real confusion is assuming you have strong pw and security questions, and do not dload links or files, can hackers STILL access your computer or accounts?? and if so, how??
let's face it, we're not talking about a few dollars...just from people on this site who have come forward about being hacked, it is prolly hundreds of thousands at a minimum...seems worthy of discussion/education/brainstorming -
Easy, just figure out what the people's answers to security questions are and break into the email account, once you have their email you can get their poker accounts passwords changed and AIM aswell. GG accounts.
-
Which get on other people's machines how? Are people really so stupid that someone could send them an executable file via AIM, and they'd click on the link and download to their PC?
Maybe I'm lucky I have unpredictable answers to my security questions.
I'm with inissint. I think it would incredibly valuable to the community if someone with any knowledge could put together some stories as to how they got hacked, so everyone would know what to avoid. -
this!
Originally Posted by grapsfan
Which get on other people's machines how? Are people really so stupid that someone could send them an executable file via AIM, and they'd click on the link and download to their PC?
Maybe I'm lucky I have unpredictable answers to my security questions.
I'm with inissint. I think it would incredibly valuable to the community if someone with any knowledge could put together some stories as to how they got hacked, so everyone would know what to avoid. -
i think thats why there is no info on the ppl who were hacked talking about it. no need to call them stupid and make them feel any worse than they already do. obv w/e they did was a mistake, seems like thats a given, but it would be nice if a couple of them that were hacked could swallow some pride and just let everyone know how the hack or potential hack went down
-
in order to reset your AIM password all you need to know is "Place of birth" so for many people this is easy to guess, since most everyone has their city listed on stars account and/or P5. Alot of people in casual conversation will let you know where they are from/grew up etc..
at this point if the user also has an aol account, this new password would grant access... within that email account may be registration emails to various poker sites and viola... -
see, that is enormously valuable info that i assume others besides me did not know...that is fng absurd...so my questions are...just cuz they can "reset" the password, how does the hacker GET the new password since i assume AIM would send a new pw to the real person's aol acct??????? surely you cannot just enter the person's city and then immediately enter a new pw, without even knowing the old pw?????????? that would seem insane, and why would ANYONE EVER use aim?
Originally Posted by -AG-
in order to reset your AIM password all you need to know is "Place of birth" so for many people this is easy to guess, since most everyone has their city listed on stars account and/or P5. Alot of people in casual conversation will let you know where they are from/grew up etc..
at this point if the user also has an aol account, this new password would grant access... within that email account may be registration emails to various poker sites and viola...
also, can you change a setting so someone would need more info than that? and also, is trillian any better than aim with respect to that?
tyvm -
get RSA token immediatly
-
the new password is not sent anywhere... by knowing the place of birth you actually reset it by typing in a new password... so the hacker has just locked you out of your own account...
i dont understand why trillion/pidgin are supposedly better it seems it all stays the same.. -
This is almost everything that is required to be safe from the type of hacking that is going on. Just a few more safety precations (some common sense, some not as much) and you are pretty much untouchable. What is amazing to me is the amount of people don't follow these basic rules for safety on the Internet, especially when we are talking about protecting tens, sometimes hundreds of thousands of dollars.
-
because people don't want to admit they got infected while browsing donkey pron. /thread
-
But see, this directly conflicts with what AG said on first page of this thread. She said if they know your birthplace, they can reset your AIM pw and access email etc etc. If that's the case, you are not safe at all, no?
Originally Posted by TwystedPair
This is almost everything that is required to be safe from the type of hacking that is going on. Just a few more safety precations (some common sense, some not as much) and you are pretty much untouchable. What is amazing to me is the amount of people don't follow these basic rules for safety on the Internet, especially when we are talking about protecting tens, sometimes hundreds of thousands of dollars. -
Other people have suggested this, and I think I will set it up today, but don't have your email that is connected with poker sites, connected to anything else. Just set up an gmail account for the sole purpose of having contact with stars, Tilt, UB, etc. and then when you talk to other players, use a different email.
Originally Posted by inissint
But see, this directly conflicts with what AG said on first page of this thread. She said if they know your birthplace, they can reset your AIM pw and access email etc etc. If that's the case, you are not safe at all, no?
-
Trillian and pidgin are just programs that allow you to use multiple chat apps (MSN, AIM, ICQ, etc) using the same interface. It doesn't change how you reset the password for each individual service.
-
It's been forever since I changed my AIM password, but there is a link to the page with instructions. It looks like you have to know a bit more than birthplace.
Originally Posted by inissint
But see, this directly conflicts with what AG said on first page of this thread. She said if they know your birthplace, they can reset your AIM pw and access email etc etc. If that's the case, you are not safe at all, no?
http://help.channels.aol.com/kjump.adp?articleId=218553 -
Another really solid suggestion. I actually have a different one for Tilt than I do for Stars.
Originally Posted by fly44
Just set up an gmail account for the sole purpose of having contact with stars, Tilt, UB, etc. and then when you talk to other players, use a different email.
-
Here's a link to an older article about the topic, but it still applies today.
Originally Posted by grapsfan
Which get on other people's machines how? Are people really so stupid that someone could send them an executable file via AIM, and they'd click on the link and download to their PC?
http://www.securityfocus.com/infocus/1829 -
just to check I went here:
https://account.login.aol.com/opr/_c...&locale=us
it asked my username and capcha thingy, next page asked place of birth and 1st and last name... then it allowed me to reset password.
so yeah you need to know first and lastname -
umm thats what i said... but everyone raves about how you supposedly wont get hacked if using these, thats what i dont understand. just cause you consolidate all your messengers how does that prevent your aim from being hacked? or are people saying viruses and such cannot be sent thru links using these???
-
I think there's a simple solution...if you decide to use AIM...just use AIM for chatting.
Do people really have there AIM email accounts linked to their poker accounts...
Just use a more trusted email connected to your poker account with a different password i.e (gmail...etc ??)
Am I missing something here? -
i went there, and it asked a different security question, because i chose a really odd one, like favorite childhood book...there is no way a hacker would guess it is Goodnight Moon, so i think it is fine...but the point is place of birth is only cuz you use that as your security question
Originally Posted by -AG-
just to check I went here:
https://account.login.aol.com/opr/_c...&locale=us
it asked my username and capcha thingy, next page asked place of birth and 1st and last name... then it allowed me to reset password.
so yeah you need to know first and lastname -
sry AG, wish i could respond, but p5 said i am prhibited from pming...very fair
Originally Posted by inissint
i went there, and it asked a different security question, because i chose a really odd one, like favorite childhood book...there is no way a hacker would guess it is Goodnight Moon, so i think it is fine...but the point is place of birth is only cuz you use that as your security question
Similar Threads
-
1 Replies
dfish217 account still hacked or hacked again
By MaravichLSU in Poker Discussion
Last Post: Aug 11th, 2010, 05:12 AM - 8 Replies
- 5 Replies
-
7 Replies
why do people keep getting hacked?
By audifan in Poker Discussion
Last Post: Sep 6th, 2007, 08:33 PM - 14 Replies










