The Student Room – security breach

Hear the latest site news, get help with using TSR or share your suggests to improve the site.

Announcements Posted on
Please change your TSR password 23-05-2013
IMPORTANT: You must wait until midnight (morning exams)/4.30AM (afternoon exams) to discuss Edexcel exams and until 1pm/6pm the following day for STEP and IB exams. Please read before posting, including for rules for practical and oral exams. 28-04-2013
READ BEFORE POSTING: Some frequently asked questions 16-06-2010
Sign in to Reply
  1. TheSownRose's Avatar
    • PS Helper
    • TSR Royalty
    • Location: Alone up on the hills and snow
    Re: TSR Usernames/Passwords
    I'm thinking that, at the very least, your e-mail password and (if relevant) your bank password should be different to all others (and obviously not the same as each other)?

    I just went and changed all of my passwords on a 'just in case' basis; sad how few websites that is, really. :getmecoat:

    (I also found that the hardest part was trying to remember what I had as my original password. :sigh:)
    Last edited by TheSownRose; 22-06-2012 at 02:14.
  2. estel's Avatar
    • TSR Idol
    • Location: Bristol
    • Posts: 9,352
    Re: TSR Usernames/Passwords
    Are changes being made at the moment, or are the instances of people being repeatedly logged out and needing to reset their passwords examples of cracked passwords being exploited?
  3. Loz17's Avatar
    • Section Leader
    Re: TSR Usernames/Passwords
    (Original post by Mr Dangermouse)
    I have an email address that's only used to sign up to TSR but my old TSR password is used in other places. Should it still be changed everywhere?
    Yes, change everything which is the same as your previous TSR password.
  4. cfizzle's Avatar
    • Exalted Member
    Re: TSR Usernames/Passwords
    If I have my bank details on a shopping website, with the same email and password for TSR do you think it'll get hacked and will all my sweet sweet dollas go? :eek:
  5. Iqbal007's Avatar
    • TSR Legend
    • Posts: 13,379
    Re: TSR Usernames/Passwords
    (Original post by RyJ)
    I know, it's quite scary how this **** can happen...
    Especially those who have lost a lot and no ones willing to compensate
  6. judicious's Avatar
    • Benevolent Member
    • Location: My town
    • Posts: 810
    Re: TSR Usernames/Passwords
    Why have most of the flags changed??
  7. EierVonSatan's Avatar
    • PS Helper
    • TSR Royalty
    • Location: UK
    • Posts: 20,995
    Re: TSR Usernames/Passwords
    (Original post by judicious)
    Why have most of the flags changed??
    That's unrelated, clear your cache to fix that
  8. Chrosson's Avatar
    • PS Helper
    • Vengeful, Imperial Overlord of The Student Room
    • Posts: 4,215
    Re: TSR Usernames/Passwords
    (Original post by estel)
    Default vB hash is:

    Code:
    $password_hash = md5(md5($password_text) . $user_salt);
    With a per-user three character salt which is also stored in the database.
    What the actual ****. This is bull****. 5 days to crack any 7 character ascii password using a single half decent GPU :mad:
  9. Chrosson's Avatar
    • PS Helper
    • Vengeful, Imperial Overlord of The Student Room
    • Posts: 4,215
    Re: TSR Usernames/Passwords
    (Original post by cfizzle)
    If I have my bank details on a shopping website, with the same email and password for TSR do you think it'll get hacked and will all my sweet sweet dollas go? :eek:
    Well yes now that you've posted that information here. Probably want to change those passwords.
  10. judicious's Avatar
    • Benevolent Member
    • Location: My town
    • Posts: 810
    Re: TSR Usernames/Passwords
    (Original post by EierVonSatan)
    That's unrelated, clear your cache to fix that
    Thanks, that worked. I thought it was related because of the timing and it has never happened before
  11. Mr Dangermouse's Avatar
    • Overlord in Training
    • Location: Scotland
    • Posts: 3,068
    Re: TSR Usernames/Passwords
    So has anyone had their bank account emptied yet?
  12. Billa Bong's Avatar
    • Overlord in Training
    • Location: Haribo Land
    • Posts: 3,272
    Re: TSR Usernames/Passwords
    changed my password...the password i have for this is different from any other account i have on internet but changed password just as a precaution
  13. Deyesy's Avatar
    • Overlord in Training
    • Location: Liverpool
    Re: TSR Usernames/Passwords
    The joys of my bank using numbers and not letters for it's passwords. I am safe on the bank account front

    I think I'll just change everything that uses old TSR password to my new one Though my password is different for YT and other places. I don't think hackers could do that much damage to me to be honest My Amazon password needs changing I think though >.>
  14. Loz17's Avatar
    • Section Leader
    Re: TSR Usernames/Passwords
    (Original post by Mr Dangermouse)
    So has anyone had their bank account emptied yet?
    Yea, it's called being a student....

    I think most banks use numbers rather than words, or use both at least so it's harder to crack and, even better even use number secure keys issued at the time of logging on now so fingers crossed bank passwords will be ok. But if anyone's worried, obviously change your password.
  15. R4INBOW's Avatar
    • Banned
    • Location: Mordor
    • Posts: 1,423
    • Warning points: 20
    Wtf is going on???!!? :confused:


    This was posted from The Student Room's iPhone/iPad App
  16. rmhumphries's Avatar
    • "Just like a hooker she said, Nothin's for free"
    • Location: Nottingham
    Re: TSR Usernames/Passwords
    I am still wondering how/why this happened. Why was the data not secure enough?
  17. tufc's Avatar
    • Vengeful, Imperial Overlord of The Student Room
    • Posts: 3,858
    Re: TSR Usernames/Passwords
    Probably wouldn't have happened if the staff spent more time working on security, instead of warning people for literally every pro-Israel post there is. Typical, farcical TSR really, and someone should be sacked over this.
  18. Loz17's Avatar
    • Section Leader
    Re: TSR Usernames/Passwords
    (Original post by R4INBOW)
    Wtf is going on???!!? :confused:


    This was posted from The Student Room's iPhone/iPad App
    It's come to TSR's attention that some usernames, passwords and email addresses have been compromised. The passwords are hashed and salted so if they are cracked it should take a while but it can't be guaranteed it won't so you need to change your TSR password and any other password which maybe the same as your TSR password ASAP.
  19. rmhumphries's Avatar
    • "Just like a hooker she said, Nothin's for free"
    • Location: Nottingham
    Re: TSR Usernames/Passwords
    (Original post by tufc)
    Probably wouldn't have happened if the staff spent more time working on security, instead of warning people for literally every pro-Israel post there is. Typical, farcical TSR really, and someone should be sacked over this.
    Yes, mod duties are to moderate the forums and test the security in every way...
  20. Mad Vlad's Avatar
    • Section Leader
    • Wiki Support Team
    • Section Leader
    • Location: Death Star
    Re: TSR Usernames/Passwords
    (Original post by tufc)
    Probably wouldn't have happened if the staff spent more time working on security, instead of warning people for literally every pro-Israel post there is. Typical, farcical TSR really, and someone should be sacked over this.
    tufc, the Administration team do not moderate users in the same way that the Moderators do not administrate the operation of the site.
Sign in to Reply
Share this discussion:  
Article updates
Moderators

We have a brilliant team of more than 60 volunteers looking after discussions on The Student Room, helping to make it a fun, safe and useful place to hang out.

Reputation gems:
The Reputation gems seen here indicate how well reputed the user is, red gem indicate negative reputation and green indicates a good rep.
Post rating score:
These scores show if a post has been positively or negatively rated by our members.