**** Please enable 2FA on your OcUK forum account ****

Soldato
Joined
5 Mar 2010
Posts
12,305
There are loads of such examples on YouTube, for example. They get into one account (say, OcUK). From there, they find your mobile number and call your provider and blag your email address and/or home address. Then they link those to find your social networks, then (maybe using dumped data or known exploits or social engineering) get into those and your email accounts... and it's all downhill from there.

Here's one quick demo. Once you have a mobile number, and an email address, or a single account login that has some personal info (such as an email address in the profile/settings) it's game over. It's possible to basically ruin your life and get access to almost anything. Enable. MFA. Everywhere.


I would hope that most of the frequent posters on this forum wouldn't fall for most of those tricks. You'd have to be really lacking in any security practices to fall for all of those.

Either way it's very interesting / eye opening. I'm pretty confident everything i use online is heavily locked down, so would be interested to see how far someone would get trying to get access to my data.
 
Soldato
Joined
21 Jan 2010
Posts
21,949
I would hope that most of the frequent posters on this forum wouldn't fall for most of those tricks. You'd have to be really lacking in any security practices to fall for all of those.

Either way it's very interesting / eye opening. I'm pretty confident everything i use online is heavily locked down, so would be interested to see how far someone would get trying to get access to my data.
Post this on 4chan and see :D
 
Soldato
Joined
17 Jul 2007
Posts
24,529
Location
Solihull-Florida
Jeez, my 30 days just kicked in. I had to grab my phone and input a 6 digit code that took me like 10 seconds to do. It's such and inconvenience that I have to do this again in 30 days.:rolleyes:


I have to do it every time I sign in.
I make sure the 30 box is ticked.

Could it be I clear out my browser cookies?
 
Commissario
OP
Joined
16 Oct 2002
Posts
2,653
Location
In the radio shack
What the point of 2FA on forum for? I can understand if you using it for shopping account online but seriously do u really need it for forum?
How would you feel if someone managed to compromise your account, posted an MM thread and actually managed to get a member to pay them for some non existent items?

If that happened, we’d basically close the MM. There would be no trust in the system whatsoever.
 
Permabanned
Joined
9 Aug 2008
Posts
35,707
How would you feel if someone managed to compromise your account, posted an MM thread and actually managed to get a member to pay them for some non existent items?

If that happened, we’d basically close the MM. There would be no trust in the system whatsoever.

On a worse scale scenrio if it was the other way around and @bulldog147 was the one who got scammed, with no money to return from another user with a compromised account. Ouch!
 
Soldato
Joined
11 Sep 2013
Posts
2,732
Location
South Yorkshire
Saw this post a week or so ago and activated 2FA as advised. Just checked my emails and received an email saying my login activation code is XXXXXX (bearing in mind I'd already activated it) I've now updated my password as suggested in the email as it looks like whoever got the info is definitely trying to get into accounts.

Thanks for the heads up OCUK.
 
Soldato
Joined
12 Jan 2009
Posts
6,407
My phone has packed up and it had my MFA app on it. Luckily I have one PC that I clicked "remember for 30 days". However how can I "reset" my MFA to this forum so I can contribute from my new mobile?
 
Permabanned
Joined
9 Aug 2008
Posts
35,707
My phone has packed up and it had my MFA app on it. Luckily I have one PC that I clicked "remember for 30 days". However how can I "reset" my MFA to this forum so I can contribute from my new mobile?

What MFA app was it? If you used Authy then you could have logged into a PC with it and then also restore on a new mobile if you can no longer get into your current mobile.

MFA on here can be reset yeh, same way you set it up.
 
Commissario
OP
Joined
16 Oct 2002
Posts
2,653
Location
In the radio shack
My phone has packed up and it had my MFA app on it. Luckily I have one PC that I clicked "remember for 30 days". However how can I "reset" my MFA to this forum so I can contribute from my new mobile?

I believe that you can go into your account and disable MFA then re-enable it. If you have an issue doing that, please start a thread in FCD and we’ll help you through it.
 
Back
Top Bottom