The Student Room – security breach

Hear the latest site news, get help with using TSR or share your suggests to improve the site.

Announcements Posted on
Ask me ANYTHING - Andrew O'Neill - Buzzcocks comedian, amateur occultist, vegan... 22-05-2013
IMPORTANT: You must wait until midnight (morning exams)/4.30AM (afternoon exams) to discuss Edexcel exams and until 1pm/6pm the following day for STEP and IB exams. Please read before posting, including for rules for practical and oral exams. 28-04-2013
READ BEFORE POSTING: Some frequently asked questions 16-06-2010
Sign in to Reply
  1. Mad Vlad's Avatar
    • Section Leader
    • Wiki Support Team
    • Section Leader
    • Location: Death Star
    Re: TSR Usernames/Passwords
    (Original post by rmhumphries)
    I am still wondering how/why this happened. Why was the data not secure enough?
    I doubt the how and why will be made public, unfortunately.
  2. cfizzle's Avatar
    • Exalted Member
    Re: TSR Usernames/Passwords
    (Original post by Chrosson)
    Well yes now that you've posted that information here. Probably want to change those passwords.
    *facepalm*


  3. Repressor's Avatar
    • Exalted and Worshipped Member
    • Posts: 1,341
    Re: TSR Usernames/Passwords
    So, have you changed how you're storing passwords and fixed the vulnerability? ... If you haven't there's no point changing passwords.....
  4. Hype en Ecosse's Avatar
    • Section Moderator
    • PS Helper
    • TSR Demigod
    • Location: Scotland
    • Posts: 5,283
    Re: TSR Usernames/Passwords
    My new password now has an insane character length.

    (Original post by Deyesy)
    The joys of my bank using numbers and not letters for it's passwords. I am safe on the bank account front

    I think I'll just change everything that uses old TSR password to my new one Though my password is different for YT and other places. I don't think hackers could do that much damage to me to be honest My Amazon password needs changing I think though >.>
    I thought, for example, an 8 digit string of numbers was easier to obtain than an 8 digit string of letters? I started reading about cryptology a while ago, but never got past the basics. I guess this is a good incentive for me to go get some further reading done, even though it's not the main security issue.

    I'm just glad TSR came out and said it instead of farting about for ages like Sony did.
  5. ChrisN's Avatar
    • TSR Group Staff
    • TSR's Owner
    • Location: Brighton
    • Posts: 1,352
    (Original post by Metrobeans)
    I've changed my password as suggested, but I was wondering - do you guys know if details have been taken for everyone on the site or just a certain number? When did this happen?
    We can only see evidence of 100k being taken.


    Posted from TSR Android App
  6. ChrisN's Avatar
    • TSR Group Staff
    • TSR's Owner
    • Location: Brighton
    • Posts: 1,352
    (Original post by Sgt.Incontro)
    Oh deary me...

    Why on earth weren't the passwords and data stored more securely??!!

    Seems that even an A-Level computing student could have hacked this then. :rolleyes:

    This was posted from The Student Room's Android App on my HTC Sensation Z710e
    We just used what vbulletin gave us unfortunately. As we do with many things. We dont store much personal data really so never thought to do more. With hindsight...

    Posted from TSR Android App
  7. Care-Free's Avatar
    • Overlord in Training
    • Location: England, West Midlands :)
    • Posts: 3,069
    Re: TSR Usernames/Passwords
    changed all my passwords on everything, now (a) i cant remeber half of the passwords or (b) With the passwords i can remember i cant remember what site they're for.

    But hey, if i cant get into my bank account neither can they muahaha
  8. ChrisN's Avatar
    • TSR Group Staff
    • TSR's Owner
    • Location: Brighton
    • Posts: 1,352
    The nasty man got in originally through a compromised password.

    All (hopefully) vulnerabilities were fixed quickly. Our hosting partner in canada has worked all night locking everything down. (thanks guys). Our mods and staff have also done their part over night.

    We have some more secondary tasks to do today.

    We will be changing password storage shortly and have put in place a range of security features that would prevent this occurring again. Hopefully.

    I hate to add those caveats, but we have to be realistic and it wouldnt make sense to start implementing bank like security considering how little personal or financial data we store on users.

    Sorry for the inconvenience though. It is a right pain.

    Posted from TSR Android App
  9. ChrisN's Avatar
    • TSR Group Staff
    • TSR's Owner
    • Location: Brighton
    • Posts: 1,352
    (Original post by estel)
    Are changes being made at the moment, or are the instances of people being repeatedly logged out and needing to reset their passwords examples of cracked passwords being exploited?
    Please can you expand on this issue

    Posted from TSR Android App
  10. ChrisN's Avatar
    • TSR Group Staff
    • TSR's Owner
    • Location: Brighton
    • Posts: 1,352
    (Original post by pinkangelgirl)
    i dont get it!! if ive changed my password will i be ok now?
    Yup


    Posted from TSR Android App
  11. ChrisN's Avatar
    • TSR Group Staff
    • TSR's Owner
    • Location: Brighton
    • Posts: 1,352
    (Original post by pinkangelgirl)
    Also, do they only have our current password or will they have all the passwords weve ever used.
    Just the current one

    Posted from TSR Android App
  12. alaska.'s Avatar
    • Exalted Member
    • Posts: 299
    Re: TSR Usernames/Passwords
    Is there an issue with my account? I fail to see many of the flags in the top right hand corner.... but that is the only problem I've noticed so far (might be a stupid thought, but I thought I better ask!).
  13. F1 fanatic's Avatar
    • PS Helper
    • Moderation in all things...
    • Posts: 33,214
    Re: TSR Usernames/Passwords
    (Original post by alaska.)
    Is there an issue with my account? I fail to see many of the flags in the top right hand corner.... but that is the only problem I've noticed so far (might be a stupid thought, but I thought I better ask!).
    That is unrelated and you can solve it by clearing your browser cache. You are unlikely to see any direct impact of the data hack and it is unlikely that anyone will try to access your account. However, as a precaution it is recommended that you change your password on this site and on any other site which uses the same password/email combination.
  14. electriic_ink's Avatar
    • TSR Demigod
    • Location: London
    • Posts: 5,637
    Re: TSR Usernames/Passwords
    One of the first things these people will do, once they've worked out your password, is search your email address on FB to find out who you are IRL. I would make sure you have this feature turned off if you haven't already.
    Last edited by electriic_ink; 22-06-2012 at 09:50.
  15. Tycho's Avatar
    • Exalted and Worshipped Member
    • Posts: 1,224
    Re: TSR Usernames/Passwords
    (Original post by pinkangelgirl)
    i dont get it!! if ive changed my password will i be ok now?

    Also, do they only have our current password or will they have all the passwords weve ever used.

    Ive just had to log in everywhere and change everything to brane new passwords
    I doubt they'll have every password that you've ever used on here. From my experiences of working with forums like these your new password overwrites your previous one and the previous one is no longer stored. It's obviously the most secured way of doing it to keep as few passwords stored as possibly possible.
  16. Tycho's Avatar
    • Exalted and Worshipped Member
    • Posts: 1,224
    Re: TSR Usernames/Passwords
    (Original post by Sgt.Incontro)
    Oh deary me...

    Why on earth weren't the passwords and data stored more securely??!!

    Seems that even an A-Level computing student could have hacked this then. :rolleyes:

    This was posted from The Student Room's Android App on my HTC Sensation Z710e
    The trouble is that the more secure you make the site the less convenient it becomes. You can't have the best of both worlds. Considering TSR doesn't store any particularly sensitive data, I don't think bank-level security is really needed. Having said that, this should now clearly call for a re-think of their security mechanism.

    As far as I know A-Level computing doesn't teach how to break a hashed password? Correct me if I'm wrong... ?
  17. madders94's Avatar
    • PS Helper
    • TSR Demigod
    • Location: Wrexham
    • Posts: 6,741
    Re: TSR Usernames/Passwords
    Did they get our email addresses or will they be able to hack every site we're on just with our username and password :lolwut: because TSR is virtually the only thing I use this email address for, so I've changed my password on here but do I need to change it everywhere else too?
  18. Tycho's Avatar
    • Exalted and Worshipped Member
    • Posts: 1,224
    Re: So TSR has been compromised!
    (Original post by tehforum)
    . Although the passwords were hashed/salted, they were unfortunately not secured to a level which would prevent them being cracked with modern approaches.

    Why not?

    Is TSR not a modern website? Is TSR benevolent towards the threat of cyber-hacking? Evidently so.

    Does it not care about the millions of users personal information?

    Please do not lecture me with cries of "oh, all you have to do is change your password", it is a case of principle and the mere reality that this has occurred.

    I have changed my password.
    Since we don't know that this is really you speaking, I'll wait for you to supply a fingerprint and blood sample before responding properly. It's the only secure way of doing it, however inconvenient it is.
  19. Tycho's Avatar
    • Exalted and Worshipped Member
    • Posts: 1,224
    Re: TSR Usernames/Passwords
    (Original post by madders94)
    Did they get our email addresses or will they be able to hack every site we're on just with our username and password :lolwut: because TSR is virtually the only thing I use this email address for, so I've changed my password on here but do I need to change it everywhere else too?
    Anyone who has access to your password from this site will also have access to your email address. Any websites where you have used the same password as here you should change your password. You should also change the password of your email account.
  20. madders94's Avatar
    • PS Helper
    • TSR Demigod
    • Location: Wrexham
    • Posts: 6,741
    Re: TSR Usernames/Passwords
    Oh, and just seen the posts above - thanks ChrisN and the TSR staff (and people in Canada) and everyone giving advice for working through the night to fix it we don't appreciate you guys enough :ta::adore:
Sign in to Reply
Share this discussion:  
Article updates
Moderators

We have a brilliant team of more than 60 volunteers looking after discussions on The Student Room, helping to make it a fun, safe and useful place to hang out.

Reputation gems:
The Reputation gems seen here indicate how well reputed the user is, red gem indicate negative reputation and green indicates a good rep.
Post rating score:
These scores show if a post has been positively or negatively rated by our members.