I just received an email saying my email was changed to con02@nm.ru. Did this happen to anyone else ? Was their database somehow compromised or was my password compromised? HB just emailed me back that they are experiencing a high amount of emails sent to them and it might take a few days to email me back -_-.

Well i'm starting to use LastPass from today :D. Thank you for the help, after i tweeted them, they emailed me and asked me for some info. I'm now waiting for response.

Ok i just got back my account and the 4 games that were unredeemed are still there :D. Russians probably hijack HB accounts to download the DRM free versions for pirating... or at least that's my guess. Anyway now i'm using a 100 upper and lower case letters with numbers, so i doubt that will happen again :D.

1 decade ago*

Comment has been collapsed.

no clue about that but nothing out of the ordinary here

1 decade ago
Permalink

Comment has been collapsed.

your pass probably got stolen/phished/keylogged :> If there was a massive breach we'd be hearing about it already :>

1 decade ago
Permalink

Comment has been collapsed.

true :>

1 decade ago
Permalink

Comment has been collapsed.

Do you use twitter? If so contact their support account with your problem and the case # you'll find at the end of the auto-reply email you got from them (it's near the end of the email). They are usually faster at replying over there - due to the small team they are and tons of emails they are getting.

They will change the account back and force a password reset for you.

As far as I know their database has not been compromised, but they could make a few changes so that it would not be that "easy" to change the email-adress if you get access to someone elses HB-password.

And as usual. if you use the same password on other sites then go change them asap!

1 decade ago
Permalink

Comment has been collapsed.

Thank you i just twitted them with my problem. Their email change system is far too easy... they dont even want confirmation from the email that is being changed -_- ...

1 decade ago
Permalink

Comment has been collapsed.

Try not using shit password idek

1 decade ago
Permalink

Comment has been collapsed.

Not helpful at all... even if you use 100 digit password if you get key logged it doesn't matter... As far as i know i wasn't key logged and my password isn't something you can just guess (it has 6 letters 5 numbers and lower and upper case letters). I would guess the password was stolen from another site/forum.

1 decade ago
Permalink

Comment has been collapsed.

Well then, don't use the same password. That's asking for trouble.

1 decade ago
Permalink

Comment has been collapsed.

Yeah i use that pass for sites i don't care if i get my account hijacked and when i was creating my HB account i didn't know if i would ever buy another bundle... and well i never changed it because i'm an idiot :D.

1 decade ago
Permalink

Comment has been collapsed.

I know, sorry I was a dick.

1 decade ago
Permalink

Comment has been collapsed.

DO NOT USE THE SAME PASSWORD ON MULTIPLE WEBSITES

Look into this

1 decade ago
Permalink

Comment has been collapsed.

I prefer Lastpass myself. Been using it for a long time and no issues.

1 decade ago
Permalink

Comment has been collapsed.

The main difference between the two is that KeePass stores everything locally where as LastPass sends encrypted passwords to store on their server.

I trust myself more than LastPass.

1 decade ago
Permalink

Comment has been collapsed.

And when you need it while away from PC? Lastpass on my android saves me a lot of trouble.

1 decade ago
Permalink

Comment has been collapsed.

Then I use the android version of KeePass.

1 decade ago
Permalink

Comment has been collapsed.

If your data is stored locally how do you access your stuff from an android?

1 decade ago
Permalink

Comment has been collapsed.

I have a backup of my Keepass file stored online, so I can access it everywhere (at least until the point where I made the backup).

Maybe Peroxide does the same.

1 decade ago
Permalink

Comment has been collapsed.

It's stored locally so I have the ability to access it? I don't change my passwords daily nor am I signing up to new sites so a simple copy of the database suffices.

Alternatively, you could do as Dopefish states and store it in a Dropbox or something similar. I personally don't as like I said, that's one of the reasons I don't use LastPass. I don't want my encrypted passwords on someone else's server!

1 decade ago
Permalink

Comment has been collapsed.

Hell, do you think ur friend pc is clear from spyware/keylogger?

1 decade ago
Permalink

Comment has been collapsed.

I just use Notepad, also with no issues. :P

1 decade ago
Permalink

Comment has been collapsed.

I use paper or brain HDD(tho things are getting lost there sometimes)

1 decade ago
Permalink

Comment has been collapsed.

Unfortunately, remembering 50+ different 20+ character passwords that use letters, numbers and punctuation is a lot easier said than done!

Not that everything needs to be 20+ characters, but when you have the ability to, why not?

1 decade ago
Permalink

Comment has been collapsed.

I used to memorize all my passwords, but that was when they were mostly the same password (or variations thereof) and all were 10 characters or less. As for paper, paper is the way of the past.

1 decade ago
Permalink

Comment has been collapsed.

I just tell all my passwords to my dog, he will remember them. They are encoded in bark sounds. No one will ever break that code, ha!

1 decade ago
Permalink

Comment has been collapsed.

Lol best way dont use same passwords on websites

1 decade ago
Permalink

Comment has been collapsed.

you forgot to put the letters ij in the word as it's "hijacked", not "hacked".

1 decade ago
Permalink

Comment has been collapsed.

dont blame them, for not knowing the difference.

1 decade ago
Permalink

Comment has been collapsed.

Yeah sorry i was searching for the word but couldn't think of it (English is not my first language). Changed it, thanks.

1 decade ago
Permalink

Comment has been collapsed.

no prob, glad i could give you a tip ;)

1 decade ago
Permalink

Comment has been collapsed.

That sucks. There are a couple of possibilites: 1. you have a keylogger, therefore, somebody got your data through it. 2. You have a simple password and somebody managed to guess it with checker.

1 decade ago
Permalink

Comment has been collapsed.

Nah it was my fault for using an old password i have used in forums. And i doubt i have a key logger i use Malwarebytes and from what i know it does protect from them.

1 decade ago
Permalink

Comment has been collapsed.

For what it's worth, no one anti-virus or anti-malware program protects from everything.

1 decade ago
Permalink

Comment has been collapsed.

After retrieving my account i asked them if they have ever thought of putting at least email confirmation on email changes and password changes. This is what they responded with:

"Hey there,
We are already working on more account security solutions so keep an eye out in the future.

AJ
Support Ninja
Humble Bundle"

This is nice to hear :D.

1 decade ago
Permalink

Comment has been collapsed.

I'm glad everything worked out and that you got your account back!

And yes, they are working on a few new things (security and other things) that will see it's light "soonish".

1 decade ago
Permalink

Comment has been collapsed.

good to hear.

1 decade ago
Permalink

Comment has been collapsed.

Woo!

Now get KeePass or LastPass and never let this happen again! (unless it was self inflicted)

1 decade ago
Permalink

Comment has been collapsed.

Dont log on russian pr0n sites with the same email/pass combo.

1 decade ago
Permalink

Comment has been collapsed.

Hey man, how long did it take you to get your account back? I'm in the same shit, someone changed my email, now idea how o-o

1 decade ago
Permalink

Comment has been collapsed.

" Russians probably hijack HB accounts to download the DRM free versions for pirating"
They're all on tpb or similar sites, what would the point in the extra step be?

1 decade ago
Permalink

Comment has been collapsed.

Hahahah so you guys remember how I was being a dick here 2+ months ago? Hahahahah yeah now the same thing happened to me, serves me well lol :(((

1 decade ago
Permalink

Comment has been collapsed.

1 decade ago
Permalink

Comment has been collapsed.

1 decade ago
Permalink

Comment has been collapsed.

Closed 1 decade ago by MiFOE.