For the first time in over 15 years of internet use my account has been hacked

wack61

I've got an itchy hatch
Messages
7,344
Edit My Images
No
I was just sat here watching TV when the ipad pinged to say I had an email

some **** has just bought 2 items on my ebay account for over $1200

one was reversed almost immediately so I assume the seller of the blackberry realised it was a scam but the other is being investigated

what ****es me off most is the money has been taken from my bank account but is now on hold by paypal who say it can take 10 days to sort out

I've changed all my passwords, is there anything else I should do

I've also notified the US Police of the address they were intended to be shipped to so hopefully the SWAT team are on their way there:razz:
 
I suppose keep pushing paypal and get onto your bank and ask them to reverse the charges etc.

But I'd be mad as hell too! You go through life trying to be decent with people and hoping that it works both ways, but then some ba****d comes along and proves you wrong.

It will get sorted and I'm sure you'll get the money back, but that doesn't make the sour taste go away.

cheers
 
Why is the world so full of low lifes!:shrug:

I'm sure you will get your money back & everything will be sorted out, however payapal really do p**s me off at the best of times they are a law unto themselves while holding our money/restricting our accounts etc, but thats another story altogether:bonk:

Good luck with your case:thumbs:
 
speak to your bank and explain the situation, they may offer you a temporary overdraft facility while it gets sorted.

also, for those that dont.. change your passwords regularly. letters and numbers and special chars where they can be used. and dont use dictionary words.
 
do not reply to emails from pay pal or ebay
go direct to your messages on your ebay account
 
To add to neil's post...

The more letters in your password the harder it is to crack. Including symbols, case changes and numbers increases this complexity but also words (including reversed) and obvious things like pa55w0rd count as ONE letter in their complexity so avoid them.

I have 5 random chains of symbols, letters and numbers e.g. (these are not real ones)

ct23op@£
f6y&*(2j

and I know these by their first letter i.e. c, f etc and have MEMORISED them.

I then use 2 (or 3) of these chains for each password and remember them by a 2 (or 3) letter code like cc, cf, ff which I store in a password protected application on the iPhone!

I have about 50 passwords to remember and about 30 of them change each month with a memory stopping me re-using them for 16 times!!

This works for me but might be a bit OTT for others.
 
Thanks for the advice, I've changed all my passwords and paypal have credited my account so hopefully that's it done with

I googled the address they'd changed mine to , it was somewhere in Florida so I contacted the local police by email at around 2am, at 1 pm I got a reply from a detective requesting more details which I provided

This morning I get an update, he's been to the address which is a post office box receiving address, unfortunately there was nothing in the box and it was registered in an overseas name so there's not much he can do


The thing I'm most impressed with is how seriously they've taken it

I'm not sure I would have got more than a crime number if I'd reported in in the uk

So a big :thumbs: for the Florida police
 
..........which I store in a password protected application on the iPhone!


does that not render your million and one randomly complicated password system, a million and one times less complicated..:)
 
does that not render your million and one randomly complicated password system, a million and one times less complicated..:)

No absolutely not, you try guessing a 16 or 24 digit alpha numeric (plus caps and symbol) password!

The file simply indicates to me (by way of 2 characters) which of the lists of characters to use and these are stored in my head not on the application.
 
bloody hell darren :lol:

we've got 30 day password expiries at work, however they wont let me turn on complex and i know for a fact people are using password01, password 02 etc

It sounds FAR more complicated that it really is to be honest!

I just remember 5 eight character codes and the phone reminds me which pair of these codes to use :D

SDad2$%h WAS one of them ages ago but it was compromised when I was typing my password in and I typed it into the user name field in front of 30 people watching on a projector :lol: I don't have a brilliant memory but it's not too difficult to remember something like that 5 times if you are using them every day.
 
A while back I delivered some goods to a truck company I hadn't been too for a couple of years

In that time they'd installed a very expensive electric gate with a keypad entry system but no intercom

I stood there wondering how to get in when I noticed oily fingerprints on 5678

So I pressed 5678 and it opened
 
bloody hell darren :lol:

we've got 30 day password expiries at work, however they wont let me turn on complex and i know for a fact people are using password01, password 02 etc

Neil. If you have an external accreditor, i'd ask them to insist on a decent ITHC. If you don't I'd get your board to sign up to an ITHC and then get one done.

Back on track, it is upsetting when you have an account hacked - remember it is easy to loose accounts if you have a key logger especially if you use cyber cafes. No password is secure to a logger.
 
Tulipone said:
Neil. If you have an external accreditor, i'd ask them to insist on a decent ITHC. If you don't I'd get your board to sign up to an ITHC and then get one done.

we have an external audit however I don't think they impose requirements, I think it's more a list of suggestions.

But unfortunately it's not my call either way..
 
Neil. If you have an external accreditor, i'd ask them to insist on a decent ITHC. If you don't I'd get your board to sign up to an ITHC and then get one done.

I insisted on one where I am - and (with the exception of the chief exec) I just get a little moaning every time someone has to change their password.

It helps that Clients come in and do Due Diligence on us every time they are going to invest, so I can just say "its what the clients expect".
 
Weak passwords: Easy to hack - Strong passwords: Harder to hack. There is no real way of stopping a hacker. Also its not down to you controlling your account but the site. If someone gains access to a site database etc... through scripts, injections etc.. they will gain access to your account and others.

But there is people out there who have easy passwords.
 
No absolutely not, you try guessing a 16 or 24 digit alpha numeric (plus caps and symbol) password!

The file simply indicates to me (by way of 2 characters) which of the lists of characters to use and these are stored in my head not on the application.

similar...
I have an access database with code worded passwords in lol.

I don't change my passwords very often but I'm just very careful about where I log in from, because of keyloggers etc.

My Work PC, home computer and my phone is really all I ever use.
 
Last edited:
we've got 30 day password expiries at work, however they wont let me turn on complex and i know for a fact people are using password01, password 02 etc

30 day expires are a good way to get people to write passwords down on a bit of paper and leave it on their desk / in the draw ;). Rules about not writing the password down or imposing complex passwords are a good way to increase the IT department's workload resetting them when people forget, which they will. Every day.

Fortunately we have no company IT security policy, audits or anything with acronyms :thumbs:
 
30 day expires are a good way to get people to write passwords down on a bit of paper and leave it on their desk / in the draw ;). .

this

also if you havbe a 30 day expire system most users will use the same password and just put 01, 02 etc according to the month.

personally i like to take an unusual word then misspell it and add a couple of punctuation marks and numbers

For example (and this isnt a real one)

I might choose Kilderkin (its an 18 gallon barrel if you're wondering)

then spell it Kliderkin

insert a puctuation mark

Kliderk/n

and a couple of numbers

Kl1derk/n8

not going to be easy to guess, means nothing that relates to me ( I just pick them randomly out of the OED) so social engineering isnt going to help, and I dont write it down ( I have a very good memory) so hard access won't help either

That only leaves keyloggers and we all know the precautions to take against them.

Of course its not hack proof as nothing ever is, but it makes life harder for the casual..
 
Last edited:
oh yeah and for numeric passwords dont use the first four numbers of pi (3142) and think you are bein cute - its the third most common code the two more common are 0000 and 1234 :bang:
 
Nothing wrong with writing down passwords - having more passwords for different things, and having them written down is better than having the same password for everything but just remembering it.

Of course it depends, if it's in your own house then writing down passwords can be fine. If you're in an office - not such a good idea to leave all your passwords on your desk, but nonetheless password managers are getting more popular.
 
.
Of course it depends, if it's in your own house then writing down passwords can be fine. .

so long as you are okay with the idea of your teenage son, his freinds, your cleaner, your wife's buisness collegues, randomn workmen , burgulars etc having access to your online accounts...

I'd suggest that it is irresponsible to write down passwords wherever you are (and btw the bank/credit card company will feel likewise if your accounts are misused)- if you really cant remember them its better to write down an aidememoir like saying " first dogs name and carols birth year " rather than the actual password, or if you really must keep the actual password writen down keep it well hidden or under lock and key.
 
Paypal is a load of s***t. I lost £40 on something that should have been a straight forward refund last year, still annoyed come to think of it.
Goodluck.
 
The trouble with those articles is that the basic premise is false

Companies should not ban employees from writing down their passwords because such bans force people to use the same weak term on many systems

It doesnt do any such thing

first pick two words you can remember - ideally not your wifes name or anything obvious but something personal to you. say for example your first car was a ford escort and the girl you lost your virginity with was called hellen

then mix the letters up, alternate cases, pick a punctuation mark say a colon and put it in the middle, then put the age you were when you first got laid around it

1EhSeCl:OlReTn4

Now no one is going to guess that , and you can write down the aide memoir
Car, shag, age - all you have to remember is that you alternated cases and that you put a colon in the middle and split the age (and you always do that but the actual words vary)

and you dont have to remember 68 passwords , you have one for all the nonpriority stuff
and one for each of your secure things so a handful max - and for each one you write down the aide memoir but not the actual password simples
 
How many people do you think actually do that? Because I assure you the majority of people will use the same password for everything.
 
How many people do you think actually do that? Because I assure you the majority of people will use the same password for everything.

Yeah I know most people are lazy - but the point is that having a don't write your password down policy doesnt force them to do it (because there are as explained above easy alternatives) they choose to do so through laziness and lack of application and should face the same consequences for violating IT security policy as they would for any other company policy violation

and saying "yerbut I'm a lazy *****" isnt going to be a defence in a disciplinary hearing

in people's personal lives its up to them, but I can assure you that a if a bank or credit card company finds out that the reason your account got defrauded was because you wrote your password down, they won't return your money - and saying "oh but microsoft engineer joe bloggs said it was okay" isnt going to change their minds
 
Nothing wrong with writing down passwords - having more passwords for different things, and having them written down is better than having the same password for everything but just remembering it.

Of course it depends, if it's in your own house then writing down passwords can be fine. If you're in an office - not such a good idea to leave all your passwords on your desk, but nonetheless password managers are getting more popular.

The idea would be that you protect your written passwords appropriately. You wouldn't leave money lying around nor would you leave your doors and windows unlocked. Put it all somewhere safe.
 
Back
Top