1
 |
Carreira   Peru. Apr 26 2012 15:42. Posts 154 | | | |
|
| Your a retarded taco eating bad fuckin poker player. lolololo | |
|
|
1
 |
Highcard   Canada. Apr 26 2012 15:48. Posts 5428 | | | |
|
| I have learned from poker that being at the table is not a grind, the grind is living and poker is how I pass the time | |
|
|
1
 |
Hasty Pond   Cook Islands. Apr 26 2012 16:08. Posts 25 | | |
For how valuable the user accounts are the measures 2p2 takes in making sure the dbs are inaccessible are simpy lol-worthy. They've been a flashing target for months now.
Now all you can hope they used proper encryption for user passes.  |
|
|
4
 |
Bigbobm   United States. Apr 26 2012 16:11. Posts 5513 | | |
a week ago somoene hacked my 2p2/skype acct and was using them to vouch for scammers in fake trades 
running out of good passwords to use that i will remember |
|
| Its time to stop thinking like a bitch and think smart like a poker player - ket | |
|
|
1
 |
taco   Iceland. Apr 26 2012 16:27. Posts 1793 | | |
Wow that is just so great, my main password was on that account.
Luckily it's not one shared with my e-mail address registered to it and I don't have that name anywhere else. 
Seriously though, what excuse do they have to not completely release the information
of how he indicated he could decrypt those passwords and to what extent the information he has is encrypted? |
|
|
1
 |
TalentedTom   Canada. Apr 26 2012 16:29. Posts 20070 | | |
pretty incredible how skilled hackers are these days |
|
| Our deepest fear is not that we are inadequate. Our deepest fear is that we are powerful beyond measure. It is our light not our darkness that most frightens us and as we let our own lights shine we unconsciously give other people permision to do the same | |
|
|
1
 |
Maynard!   United States. Apr 26 2012 17:03. Posts 4453 | | |
I use different pws for sites with tons of security (google) and different ones for sites like 2p2, lp, tl, etc. So when this happens I don't have to care |
|
| Now I really am a busto. Thanks FTP. | Last edit: 26/04/2012 17:04 |
|
|
4
 |
Roald   Tuvalu. Apr 26 2012 17:41. Posts 2683 | | |
HEM forums are down too. Maybe I need to patch my forum since I got a bunch of emails from vbulletin today lol |
|
| drugs, animals, children are welcome -Xavier | |
|
|
3
 |
PuertoRican   United States. Apr 26 2012 18:39. Posts 13257 | | |
I don't have an account at 2p2, but as far as passwords go, I started mentally lose track of passwords after 10 or so, so now I use the same 1 password for new sites I don't care about like 4 different clothing sites, 3 different shoe sites, Yelp account, etc. |
| |
|
|
1
 |
Ket   United Kingdom. Apr 26 2012 18:48. Posts 8665 | | |
stop being mongs and get keepass already, i mention it every time in these types of threads |
|
|
1
 |
DooMeR   United States. Apr 26 2012 19:49. Posts 8564 | | |
ket should i get keepass?
._. |
|
| I just saved a bunch of money on my car insurance, by running away from the scene of an accident. | |
|
|
1
 |
TheHuHu3   United States. Apr 26 2012 19:55. Posts 5544 | | | |
| |
|
|
1
 |
Target-x17   Canada. Apr 26 2012 20:29. Posts 1027 | | |
The smart people have a separate password for a site that has access to billions of player accounts and lolz security
erg I just went to the site clicked forums and a suspicious popup came to enter my info this might get some n00bs =[ |
|
| f u bw rock | Last edit: 26/04/2012 20:31 |
|
|
1
 |
TalentedTom   Canada. Apr 26 2012 20:30. Posts 20070 | | |
| | On April 26 2012 18:55 TheHuHu3 wrote:
Where I get keepass? |
|
|
| Our deepest fear is not that we are inadequate. Our deepest fear is that we are powerful beyond measure. It is our light not our darkness that most frightens us and as we let our own lights shine we unconsciously give other people permision to do the same | |
|
|
1
 |
Silver_nz   New Zealand. Apr 26 2012 23:18. Posts 5647 | | | |
|
|
1
|
1
 |
AndrewSong   United States. Apr 27 2012 01:50. Posts 2355 | | |
2p2 was my drug. i'm having pretty bad withdrawal |
|
|
1
 |
N1GhtFoX   Bulgaria. Apr 27 2012 02:35. Posts 413 | | |
i dunno, these days you can get like rsatoken for pretty much everything
gmail has one, ps has one etc ... and its not like its gonna cost you a fortune |
|
| | Last edit: 27/04/2012 02:46 |
|
|
1
 |
Target-x17   Canada. Apr 27 2012 02:48. Posts 1027 | | |
liquid poker should steal there traffic ASAP |
| |
|
|
0
 |
NeillyJQ   United States. Apr 27 2012 02:52. Posts 8947 | | |
| | On April 27 2012 01:48 Target-x17 wrote:
liquid poker should steal there traffic ASAP |
HERO style |
|
| Just remember you need to be god damn sure about their tendencies. -Artanis11 http://www.pocketfives.com/profiles/neillyaa/ | |
|
|
1
 |
ggplz   Sweden. Apr 27 2012 03:28. Posts 16784 | | |
| | On April 27 2012 01:35 N1GhtFoX wrote:
i dunno, these days you can get like rsatoken for pretty much everything
gmail has one, ps has one etc ... and its not like its gonna cost you a fortune |
gmail has a RSA token? :o |
|
| if poker is dangerous to them i would rank sports betting as a Kodiak grizzly bear who smells blood after you just threw a javelin into his cub - RaiNKhAN | Last edit: 27/04/2012 03:28 |
|
|
1
 |
N1GhtFoX   Bulgaria. Apr 27 2012 03:45. Posts 413 | | |
ye, they have an app for diff phones that is basicly a rsa token
I dont remember exactly where but it should around security in settings ...
I have an iphone and the app is called google authenticator and you could add several accounts to it and generates diff numbers every 20-30 secs |
|
|
1
 |
ggplz   Sweden. Apr 27 2012 03:56. Posts 16784 | | |
hmmm k, i'll take a look ty. what if you lose your phone btw?:o |
|
| if poker is dangerous to them i would rank sports betting as a Kodiak grizzly bear who smells blood after you just threw a javelin into his cub - RaiNKhAN | Last edit: 27/04/2012 03:56 |
|
|
1
 |
N1GhtFoX   Bulgaria. Apr 27 2012 04:55. Posts 413 | | |
They also give you like 8-10 one time passes i think |
|
|
1
 |
qwerty67890   New Zealand. Apr 27 2012 04:59. Posts 14026 | | |
like i can fucking remember what my pw was
brb login once "remember me" |
|
|
1
 |
bigredhoss   Cook Islands. Apr 27 2012 05:00. Posts 8649 | | |
| | On April 27 2012 03:59 byrnesam wrote:
like i can fucking remember what my pw was
brb login once "remember me" |
qft lol |
| |
|
|
0
| |
| | On April 27 2012 01:52 NeillyJQ wrote:
Show nested quote +
On April 27 2012 01:48 Target-x17 wrote:
liquid poker should steal there traffic ASAP |
HERO style
|
Pffffft. Idiots. Lol |
|
|
1
 |
Stim_Abuser   United States. Apr 27 2012 08:46. Posts 7499 | | |
lol they're still down?
That's some pretty legit ownage |
|
| Hey Im slinging mad volume and fat stackin benjies I dont got time for spellin n shit - skinny pete | |
|
|
1
 |
c4rnage   . Apr 27 2012 15:45. Posts 409 | | |
mehh, hate having multiple usernames/passwords -_______- |
|
|
1
 |
superfashion   United States. Apr 27 2012 15:57. Posts 918 | | |
| | On April 27 2012 04:00 bigredhoss wrote:
Show nested quote +
On April 27 2012 03:59 byrnesam wrote:
like i can fucking remember what my pw was
brb login once "remember me" |
qft lol
|
qftx2 |
|
| shoving here as a bluff at 50NL is like explaning calcalus to a 6 month old cat wtf are you thinking - TalentedTom | |
|
|
1
 |
uiCk   Canada. Apr 27 2012 16:23. Posts 3521 | | |
| | On April 27 2012 01:48 Target-x17 wrote:
liquid poker should steal there traffic ASAP |
add photoshop forum and gossip forum.
Make news on front Page of LP
Massive influx of 2+2'ers then
then we have massive amounts of new members we can troll and hate on ;D |
|
| I wish one of your guys had children if I could kick them in the fucking head or stomp on their testicles so you can feel my pain because thats the pain I have waking up everyday -- Mike Tyson | |
|
|
1
 |
killmepl   Poland. Apr 27 2012 16:47. Posts 82 | | |
| | On April 27 2012 15:23 uiCk wrote:
Show nested quote +
On April 27 2012 01:48 Target-x17 wrote:
liquid poker should steal there traffic ASAP |
add photoshop forum and gossip forum.
Make news on front Page of LP
Massive influx of 2+2'ers then
then we have massive amounts of new members we can troll and hate on ;D
|
hummm but hummm we still can hate them and do neither of these activities that require actually doing something. Pure hatred and lazyness  |
| |
|
|
1
 |
uiCk   Canada. Apr 27 2012 16:50. Posts 3521 | | |
| | On April 27 2012 15:47 killmepl wrote:
Show nested quote +
On April 27 2012 15:23 uiCk wrote:
| | On April 27 2012 01:48 Target-x17 wrote:
liquid poker should steal there traffic ASAP |
add photoshop forum and gossip forum.
Make news on front Page of LP
Massive influx of 2+2'ers then
then we have massive amounts of new members we can troll and hate on ;D
|
hummm but hummm we still can hate them and do neither of these activities that require actually doing something. Pure hatred and lazyness |
i don't hate em, just that there will be more newcomers to hate/troll on. LP Style. |
|
| I wish one of your guys had children if I could kick them in the fucking head or stomp on their testicles so you can feel my pain because thats the pain I have waking up everyday -- Mike Tyson | |
|
|
1
 |
waga   United Kingdom. Apr 27 2012 21:20. Posts 2375 | | | |
|
|
1
 |
intown   Belgium. Apr 27 2012 23:14. Posts 121 | | |
all the good players are from 2p2 lol |
|
|
1
 |
capaneo   Canada. Apr 28 2012 04:05. Posts 8465 | | |
How can you decrypt passwords? I assume they are using an md5 hash. How can a person who is hacking 2p2 of all places can decrypt that? I think that part is just bs.
Can someone who is a more computer savy confirm this one way or the other? |
|
| In US everyone is happy as long as all the prices are rising. Unless its crude oil - Marc Faber | Last edit: 28/04/2012 04:07 |
|
|
4
 |
TianYuan   Korea (South). Apr 28 2012 04:12. Posts 6817 | | |
Can't remember if the password I just changed to on their site was a really random horrible one or if I changed it to an actual good password hmhmhmhm
Annoying.
Keepass time. |
| |
|
|
5
 |
Meat   . Apr 28 2012 04:29. Posts 3386 | | |
| | On April 28 2012 03:05 capaneo wrote:
How can you decrypt passwords? I assume they are using an md5 hash. How can a person who is hacking 2p2 of all places can decrypt that? I think that part is just bs.
Can someone who is a more computer savy confirm this one way or the other? |
There are huge lists available in which you can look up the unencrypted version of a md5 encrypted pw, so called rainbow tables. If you don't have an extremely long pw it's likely that your pw appears in that md5 list. So for decent password security it's essential to use a salt, which means that you add an extra sequence before encrypting a pw. If you add something like '1a2a3a4a5a6a7a8a9a' to 'mypw' before encrypting it, you get '1a2a3a4a5a6a7a8a9amypw' which is much less likely to be found in such a list. |
|
| | Last edit: 28/04/2012 04:30 |
|
|
1
 |
Mortensen8   Chad. Apr 28 2012 05:49. Posts 1846 | | |
LOOOOOOOOOOOOOOL bnoooocjvkbs |
| |
|
|
1
 |
Highcard   Canada. Apr 28 2012 14:28. Posts 5428 | | |
| | On April 28 2012 03:29 Liquid`Meat wrote:
Show nested quote +
On April 28 2012 03:05 capaneo wrote:
How can you decrypt passwords? I assume they are using an md5 hash. How can a person who is hacking 2p2 of all places can decrypt that? I think that part is just bs.
Can someone who is a more computer savy confirm this one way or the other? |
There are huge lists available in which you can look up the unencrypted version of a md5 encrypted pw, so called rainbow tables. If you don't have an extremely long pw it's likely that your pw appears in that md5 list. So for decent password security it's essential to use a salt, which means that you add an extra sequence before encrypting a pw. If you add something like '1a2a3a4a5a6a7a8a9a' to 'mypw' before encrypting it, you get '1a2a3a4a5a6a7a8a9amypw' which is much less likely to be found in such a list.
|
so you are saying they did not use salt at 2p2? |
|
| I have learned from poker that being at the table is not a grind, the grind is living and poker is how I pass the time | |
|
|
1
 |
taco   Iceland. Apr 28 2012 15:51. Posts 1793 | | |
| | On April 28 2012 13:28 Highcard wrote:
Show nested quote +
On April 28 2012 03:29 Liquid`Meat wrote:
| | On April 28 2012 03:05 capaneo wrote:
How can you decrypt passwords? I assume they are using an md5 hash. How can a person who is hacking 2p2 of all places can decrypt that? I think that part is just bs.
Can someone who is a more computer savy confirm this one way or the other? |
There are huge lists available in which you can look up the unencrypted version of a md5 encrypted pw, so called rainbow tables. If you don't have an extremely long pw it's likely that your pw appears in that md5 list. So for decent password security it's essential to use a salt, which means that you add an extra sequence before encrypting a pw. If you add something like '1a2a3a4a5a6a7a8a9a' to 'mypw' before encrypting it, you get '1a2a3a4a5a6a7a8a9amypw' which is much less likely to be found in such a list.
|
so you are saying they did not use salt at 2p2? |
Hmm? Liqui'dMeat was just responding to a general inquiry and said nothing at all about anything directly related to 2p2. |
|
|
5
 |
Meat   . Apr 29 2012 06:44. Posts 3386 | | |
| | On April 28 2012 14:51 taco wrote:
Show nested quote +
On April 28 2012 13:28 Highcard wrote:
| | On April 28 2012 03:29 Liquid`Meat wrote:
| | On April 28 2012 03:05 capaneo wrote:
How can you decrypt passwords? I assume they are using an md5 hash. How can a person who is hacking 2p2 of all places can decrypt that? I think that part is just bs.
Can someone who is a more computer savy confirm this one way or the other? |
There are huge lists available in which you can look up the unencrypted version of a md5 encrypted pw, so called rainbow tables. If you don't have an extremely long pw it's likely that your pw appears in that md5 list. So for decent password security it's essential to use a salt, which means that you add an extra sequence before encrypting a pw. If you add something like '1a2a3a4a5a6a7a8a9a' to 'mypw' before encrypting it, you get '1a2a3a4a5a6a7a8a9amypw' which is much less likely to be found in such a list.
|
so you are saying they did not use salt at 2p2? |
Hmm? Liqui'dMeat was just responding to a general inquiry and said nothing at all about anything directly related to 2p2. |
Exactly, I have no idea if they did use a proper salt. All I know is that it should not be possible to decrypt a md5 hash so 'decryption' is usually done by looking up the hash in a database.
| |
No. MD5 is not encryption (though it may be used as part of some encryption algorithms), it is a one way hash function. Much of the original data is actually "lost" as part of the transformation.
Think about this: An MD5 is always 128 bits long. That means that there are 2128 possible MD5 hashes. That is a reasonably large number, and yet it is most definitely finite. And yet, there are an infinite number of possible inputs to a given hash function (and most of them contain more than 128 bits, or a measly 16 bytes). So there are actually an infinite number of possibilities for data that would hash to the same value. The thing that makes hashes interesting is that it is incredibly difficult to find two pieces of data that hash to the same value, and the chances of it happening by accident are almost 0.
A simple example for a (very insecure) hash function (and this illustrates the general idea of it being one-way) would be to take all of the bits of a piece of data, and treat it as a large number. Next, perform integer division using some large (probably prime) number n and take the remainder (see: Modulus). You will be left with some number between 0 and n. If you were to perform the same calculation again (any time, on any computer, anywhere), using the exact same string, it will come up with the same value. And yet, there is no way to find out what the original value was, since there are an infinite number of numbers that have that exact remainder, when divided by n.
That said, MD5 has been found to have some weaknesses, such that with some complex mathematics, it may be possible to find a collision without trying out 2128 possible input strings. And the fact that most passwords are short, and people often use common values (like "password" or "secret") means that in some cases, you can make a reasonably good guess at someone's password by Googling for the hash or using a Rainbow table. That is one reason why you should always "salt" hashed passwords, so that two identical values, when hashed, will not hash to the same value.
Once a piece of data has been run through a hash function, there is no going back. |
|
|
|
4
 |
TianYuan   Korea (South). Apr 29 2012 10:31. Posts 6817 | | |
On NoahSD's blog he said the salts used had been compromised as well o.o
| | The hacker has gained access to a list of usernames, e-mails, hashed passwords, and password salts. While hashed passwords and plaintext passwords aren’t quite the same thing, the combination of the hashed password together with the salt makes it possible for the hacker to find plaintext passwords. (This is preventable, but vBulletin’s default hashing algorithm is md5, which is completely insecure against this sort of thing–and other things.) |
|
| |
|
|
1
 |
capaneo   Canada. Apr 29 2012 22:05. Posts 8465 | | |
| | On April 28 2012 03:29 Liquid`Meat wrote:
Show nested quote +
On April 28 2012 03:05 capaneo wrote:
How can you decrypt passwords? I assume they are using an md5 hash. How can a person who is hacking 2p2 of all places can decrypt that? I think that part is just bs.
Can someone who is a more computer savy confirm this one way or the other? |
There are huge lists available in which you can look up the unencrypted version of a md5 encrypted pw, so called rainbow tables. If you don't have an extremely long pw it's likely that your pw appears in that md5 list. So for decent password security it's essential to use a salt, which means that you add an extra sequence before encrypting a pw. If you add something like '1a2a3a4a5a6a7a8a9a' to 'mypw' before encrypting it, you get '1a2a3a4a5a6a7a8a9amypw' which is much less likely to be found in such a list.
|
thanks meat, that was very informative. |
|
| In US everyone is happy as long as all the prices are rising. Unless its crude oil - Marc Faber | |
|
|
1
 |
50bani   Romania. Apr 30 2012 03:37. Posts 4 | | |
| | On April 29 2012 09:31 TianYuan wrote:
On NoahSD's blog he said the salts used had been compromised as well o.o
Show nested quote +
The hacker has gained access to a list of usernames, e-mails, hashed passwords, and password salts. While hashed passwords and plaintext passwords aren’t quite the same thing, the combination of the hashed password together with the salt makes it possible for the hacker to find plaintext passwords. (This is preventable, but vBulletin’s default hashing algorithm is md5, which is completely insecure against this sort of thing–and other things.) |
|
Wait a minute, the salt adds a bit of complexity to the password, "a bit more" than what the original password was.
The attack would involve Rainbow Tables, where you run all the common passwords through the hash function and compare the results with the hashes you stole. So all common ones are revealed. The salt makes the problem more difficult, since you would need a much larger rainbow table for all the password with all the salts. In a way all passwords become unique, and more difficult than what the account owner intended.
The only way salts are compromised is if they are reused for multiple accounts, having them in the same file with the hashed passwords is OK. |
|
|
5
 |
Meat   . Apr 30 2012 04:06. Posts 3386 | | |
| | On April 29 2012 09:31 TianYuan wrote:
On NoahSD's blog he said the salts used had been compromised as well o.o
Show nested quote +
The hacker has gained access to a list of usernames, e-mails, hashed passwords, and password salts. While hashed passwords and plaintext passwords aren’t quite the same thing, the combination of the hashed password together with the salt makes it possible for the hacker to find plaintext passwords. (This is preventable, but vBulletin’s default hashing algorithm is md5, which is completely insecure against this sort of thing–and other things.) |
|
Hmm that sucks, the traditional tables are still useless but then they can create a custom rainbow table for 2+2 much easier. |
|
|
1
 |
bigredhoss   Cook Islands. May 01 2012 15:13. Posts 8649 | | |
it looks like the hacker broke 2+2's will to live, gone forever RIP |
| |
|
|
4
 |
TianYuan   Korea (South). May 02 2012 08:58. Posts 6817 | | |
Why scare me like that o.o
| | Update May 1st
After closer inspection, it’s now clear to us that the 2 + 2 Forums are more likely to come back to life next week rather than this week even though at this point in time we cannot give a definite date, and all efforts are being made to shorten the amount of downtime as much as possible. Mason will be on the next episode of the PokerCast (being recorded tonight) discussing this, and our May 2+2 Internet Magazine should be up before the weekend.
|
Does not sound like "gone forever".
I really, really wish I remembered what I had made my password for the site so I know if I should be worried --- already changed a few important ones just because, well, no reason not to. Pretty sure I had it set to a useless 2p2 only password tho. |
|
| Hm.. Off-suite socks.. | Last edit: 02/05/2012 08:59 |
|
|
1
 |
bigredhoss   Cook Islands. May 02 2012 23:00. Posts 8649 | | |
nah gone forever 93% sure |
| |
|
|
1
 |
intown   Belgium. May 02 2012 23:49. Posts 121 | | |
2p2 might've been stupid enough to "give away" their hosting account details. i feel that is what happened due to the length of downtime. who the hell has a giant ass site and lets it go offline for days if they properly backed shit up. |
|
|
4
 |
TianYuan   Korea (South). May 03 2012 00:27. Posts 6817 | | |
| | On May 02 2012 22:49 intown wrote:
2p2 might've been stupid enough to "give away" their hosting account details. i feel that is what happened due to the length of downtime. who the hell has a giant ass site and lets it go offline for days if they properly backed shit up. |
I thought the issue was security -.- |
| |
|
|
1
 |
intown   Belgium. May 03 2012 03:45. Posts 121 | | |
Probably is but still it's not hard to isolate and plug the problem once you're offline. Unless if the database was fucked up bad. |
|
|
1
 |
Skew   United States. May 07 2012 15:46. Posts 62 | | |
fwiw even if the site in question takes into account the most recent standards of securing passwords (2+2 didn't because vbulletin is pure shit software), that's still not even close to a guarantee that the attacker can't reveal your passwords. there's just too much computing power available these days. for all of you who use online banking, and poker sites with lots of money, use long mother fucking passwords, make them unique per-site, and if you have the option of using a physical authenticator, GET IT. |
|
|
4
 |
Roald   Tuvalu. May 08 2012 18:51. Posts 2683 | | |
This is causing me quite a bit of consternation since my own income has been directly impacted by this downtime  |
|
| drugs, animals, children are welcome -Xavier | |
|
|
1
| |
2+2 was to easy to hack, they should rebrand it to:

this should do it |
| |
|
|
1
 |
2c0ntent   Egypt. May 08 2012 21:45. Posts 1387 | | |
| | On May 08 2012 17:51 Roald wrote:
This is causing me quite a bit of consternation since my own income has been directly impacted by this downtime |
increase search engine rank ?_? |
| |
|
|
1
 |
TalentedTom   Canada. May 09 2012 15:33. Posts 20070 | | |
so is 2+2 finished? is anything being done |
|
| Our deepest fear is not that we are inadequate. Our deepest fear is that we are powerful beyond measure. It is our light not our darkness that most frightens us and as we let our own lights shine we unconsciously give other people permision to do the same | |
|
|
1
 |
intown   Belgium. May 09 2012 15:39. Posts 121 | | |
merge this with FTP threads more like |
|
|
1
 |
TheTrees   United States. May 12 2012 00:04. Posts 1592 | | | |
|
|
1
 |
bigredhoss   Cook Islands. May 12 2012 00:38. Posts 8649 | | |
i have 3 accounts for 2p2 and no longer have the e-mail addresses to any of them LOL gg |
| |
|
|
1
 |
Mortensen8   Chad. May 12 2012 00:54. Posts 1846 | | |
ITs back? wtf fucking slowfags |
| |
|
|
0
 |
dogmeat   Czech Republic. May 12 2012 09:35. Posts 6374 | | |
how long should i wait for pass email?  |
| |
|
|
|