The Student Room – security breach

Hear the latest site news, get help with using TSR or share your suggests to improve the site.

Announcements Posted on
Please change your TSR password 23-05-2013
Enter our travel-writing competition for the chance to win a Nikon 1 J3 camera 20-05-2013
IMPORTANT: You must wait until midnight (morning exams)/4.30AM (afternoon exams) to discuss Edexcel exams and until 1pm/6pm the following day for STEP and IB exams. Please read before posting, including for rules for practical and oral exams. 28-04-2013
READ BEFORE POSTING: Some frequently asked questions 16-06-2010
Sign in to Reply
  1. Tycho's Avatar
    • Exalted and Worshipped Member
    • Posts: 1,224
    Re: TSR Usernames/Passwords
    I think it'll take quite some computational power to actually brute force crack every hashed password on this site. Time is on the side of the users of this site to secure themselves up, unless the hacker has the power of Google's servers at their disposal (which they won't have).
  2. madders94's Avatar
    • PS Helper
    • TSR Demigod
    • Location: Wrexham
    • Posts: 6,761
    Re: TSR Usernames/Passwords
    (Original post by Tycho)
    Anyone who has access to your password from this site will also have access to your email address. Any websites where you have used the same password as here you should change your password. You should also change the password of your email account.
    Thanks Tycho
  3. TheHansa's Avatar
    • Exalted and Worshipped Member
    • Location: The moral high ground
    • Posts: 1,354
    Re: TSR Usernames/Passwords
    OK I've changed this thing, but still have the message, has it happened again?
  4. fluteflute's Avatar
    • Section Moderator
    • Vengeful, Imperial Overlord of The Student Room
    • Posts: 4,411
    Re: TSR Usernames/Passwords
    (Original post by TheHansa)
    OK I've changed this thing, but still have the message, has it happened again?
    Click the X in the top right corner of the message.
  5. Tycho's Avatar
    • Exalted and Worshipped Member
    • Posts: 1,224
    Re: TSR Usernames/Passwords
    (Original post by TheHansa)
    OK I've changed this thing, but still have the message, has it happened again?
    Not to my knowledge. The message on the top of the site is a generic message which isn't specifically tied to your account.
  6. TheHansa's Avatar
    • Exalted and Worshipped Member
    • Location: The moral high ground
    • Posts: 1,354
    Re: TSR Usernames/Passwords
    (Original post by ChrisN)
    Just the current one

    Posted from TSR Android App
    If we've used multiple email addresses in the past on our TSR account do they have them all?
    Last edited by TheHansa; 22-06-2012 at 14:12.
  7. Tycho's Avatar
    • Exalted and Worshipped Member
    • Posts: 1,224
    Re: TSR Usernames/Passwords
    (Original post by TheHansa)
    If we've used multiple email addresses in the past do they have them all?
    No, they won't have.
  8. TheHansa's Avatar
    • Exalted and Worshipped Member
    • Location: The moral high ground
    • Posts: 1,354
    Re: TSR Usernames/Passwords
    (Original post by Tycho)
    No, they won't have.
    You know an awful lot about this :sly:

    suspicious
    Last edited by TheHansa; 22-06-2012 at 10:35.
  9. Tycho's Avatar
    • Exalted and Worshipped Member
    • Posts: 1,224
    Re: TSR Usernames/Passwords
    (Original post by TheHansa)
    You know an awful lot about this :sly:

    suspicious
    I'm a web developer.
  10. Mr Dangermouse's Avatar
    • Overlord in Training
    • Location: Scotland
    • Posts: 3,068
    Re: TSR Usernames/Passwords
    Should we continue to change passwords regularly over the next 24-48 hours?
  11. Tycho's Avatar
    • Exalted and Worshipped Member
    • Posts: 1,224
    Re: TSR Usernames/Passwords
    (Original post by Mr Dangermouse)
    Should we continue to change passwords regularly over the next 24-48 hours?
    No, this is taking it a bit far. Just change all your passwords everywhere and make your password on here different to your other ones. This means that any subsequent cracks on here will result in them only being able to access your account here, which isn't such a huge problem. What they gonna do - login and post a message?
  12. GenerationX's Avatar
    • Full Member
    • Posts: 77
    Sloppy security
    Its pretty sloppy of web site owners and developers to rely on hashing paswords as some idea of security. Hashing is not encryption and the site should have used proper encryption in the first place instead of something that many websotes can decode for you in a minute or two.

    Sloppy sloppy sloppy to risk members passwords like that :mad:
  13. TheHansa's Avatar
    • Exalted and Worshipped Member
    • Location: The moral high ground
    • Posts: 1,354
    Re: TSR Usernames/Passwords
    (Original post by electriic_ink)
    One of the first things these people will do, once they've worked out your password, is search your email address on FB to find out who you are IRL. I would make sure you have this feature turned off if you haven't already.
    For identity theft or for the lulz?
  14. TheHansa's Avatar
    • Exalted and Worshipped Member
    • Location: The moral high ground
    • Posts: 1,354
    Re: TSR Usernames/Passwords
    (Original post by tufc)
    Probably wouldn't have happened if the staff spent more time working on security, instead of warning people for literally every pro-Israel post there is. Typical, farcical TSR really, and someone should be sacked over this.



    There's always one.

    Empire Total War people moaned they were releasing DLC when there were still bugs, not the same people dude, not the same people.
    Last edited by TheHansa; 22-06-2012 at 10:53.
  15. Flyteryder's Avatar
    • Exalted and Worshipped Member
    • Posts: 984
    Re: TSR Usernames/Passwords
    I use my TSR password for everything else on the internet. Do I really need to change all my passwords? Like do they know my ebay and Amazon user name and can use my password with it? I don't see how they could know my other user names for other sites, but the TSR message is telling me to change all my passwords for everything.
    Last edited by Flyteryder; 22-06-2012 at 10:54.
  16. Tycho's Avatar
    • Exalted and Worshipped Member
    • Posts: 1,224
    Re: TSR Usernames/Passwords
    (Original post by Flyteryder)
    I use my TSR password for everything else on the internet. Do I really need to change all my passwords? Like do they know my ebay and Amazon user name and can use my password with it? I don't see how they could know my other user names for other sites, but the TSR message is telling me to change all my passwords for everything.
    Do you really want to take the risk of not changing them? If I were you I'd change them all, but if you really don't want to then at least secure up sites like Amazon, Ebay, Paypal etc... and definately change your email account password.

    The inconvenience of changing your passwords is far less than the inconvenience if someone gains access to them.
  17. Flyteryder's Avatar
    • Exalted and Worshipped Member
    • Posts: 984
    Re: TSR Usernames/Passwords
    (Original post by Tycho)
    Do you really want to take the risk of not changing them? If I were you I'd change them all, but if you really don't want to then at least secure up sites like Amazon, Ebay, Paypal etc... and definately change your email account password.

    The inconvenience of changing your passwords is far less than the inconvenience if someone gains access to them.
    But how on Earth could they have my Amazon and Paypal usernames if they've only stolen information from this site?
  18. fluteflute's Avatar
    • Section Moderator
    • Vengeful, Imperial Overlord of The Student Room
    • Posts: 4,411
    Re: Sloppy security
    (Original post by GenerationX)
    Its pretty sloppy of web site owners and developers to rely on hashing paswords as some idea of security. Hashing is not encryption and the site should have used proper encryption in the first place instead of something that many websotes can decode for you in a minute or two.

    Sloppy sloppy sloppy to risk members passwords like that :mad:
    Encryption (by definition) guarantees that the passwords can be recovered.
  19. Tycho's Avatar
    • Exalted and Worshipped Member
    • Posts: 1,224
    Re: Sloppy security
    (Original post by GenerationX)
    Its pretty sloppy of web site owners and developers to rely on hashing paswords as some idea of security. Hashing is not encryption and the site should have used proper encryption in the first place instead of something that many websotes can decode for you in a minute or two.

    Sloppy sloppy sloppy to risk members passwords like that :mad:
    Hashing is a very common method of storing passwords, and it's not as easy to crack as you are suggesting. It's specifically designed to not be decrypted, and indeed can't be. To the best of my knowledge the only way to crack a password which is hashed using md5 is via a brute force method.
  20. fluteflute's Avatar
    • Section Moderator
    • Vengeful, Imperial Overlord of The Student Room
    • Posts: 4,411
    Re: TSR Usernames/Passwords
    (Original post by Flyteryder)
    But how on Earth could they have my Amazon and Paypal usernames if they've only stolen information from this site?
    If there is a link through your email addresses I guess.
Sign in to Reply
Share this discussion:  
Article updates
Moderators

We have a brilliant team of more than 60 volunteers looking after discussions on The Student Room, helping to make it a fun, safe and useful place to hang out.

Reputation gems:
The Reputation gems seen here indicate how well reputed the user is, red gem indicate negative reputation and green indicates a good rep.
Post rating score:
These scores show if a post has been positively or negatively rated by our members.