[ 3 / biz / cgl / ck / diy / fa / ic / jp / lit / sci / vr / vt ] [ index / top / reports ] [ become a patron ] [ status ]
2023-11: Warosu is now out of extended maintenance.

/biz/ - Business & Finance


View post   

File: 640 KB, 530x717, Screenshot+2018-02-10+02.35.07.png [View same] [iqdb] [saucenao] [google]
7532251 No.7532251 [Reply] [Original]

Uh.....

https://twitter.com/poloniexhack/status/962288838692474880

>> No.7532279

If they seriously store passwords plaintext, they deserve to get hacked.

I'm betting this is fake, though.

>> No.7532285

Fuck, i have same password and email at everywhere

>> No.7532320

>>7532279
This. Only 14 year old script kiddies would ever consider storing passwords in plain text.

>> No.7532362

Tried one of those, can't get in. Fake.

>> No.7532366

Fuck, I used my work email and my password is ih8niggers

>> No.7532381

Anyone tried one to see if it is legit?

>> No.7532387

>>7532366
nice one

>> No.7532413

>>7532320
Or doe a single round of SHA256 w/ no salt

>> No.7532424

>>7532251
>https://twitter.com/poloniexhack/status/962288838692474880

I just tried some of the logins. Only one worked, but they had 2fa enabled.

big if true

>> No.7532437

>>7532424
OH SHIIIIIIIIIIIIT

>> No.7532462

>>7532381
99dent but he has 2fa

>> No.7532463

>>7532424
Could be just one they created

>> No.7532485

>>7532424
Yeah, some of those work

FUCK

>> No.7532520

Haven't used poloniex in years though

>> No.7532523
File: 612 KB, 808x805, 1515469032729.png [View same] [iqdb] [saucenao] [google]
7532523

>>7532251
YES YES this is the FUD we need to dirve btc down to 5k

>> No.7532539
File: 32 KB, 400x400, 1493124871295.jpg [View same] [iqdb] [saucenao] [google]
7532539

Do people unironically actually not use strong alphanumeric passwords?

>> No.7532540

Do I need to change password?

>> No.7532577

>>7532251
tried both @naver.com ones and they worked.... jesus fuck

>> No.7532580

nooo my linkies

>> No.7532599

>>7532577
They could’ve just made those accounts calm the fuck down

>> No.7532617

>>7532539
How do you think that would help in this case??

>> No.7532622

if only a couple work while most fail, it's overwhelmingly likely that's his own accounts

>> No.7532627

>>7532599
doesn't make sense though, why not create every account on the screenshot in that case?

>> No.7532652

>>7532577
welp, for once OP isnt LARPing

>> No.7532657

big if true

>> No.7532681

Come on baby, crash this market. NOW.

>> No.7532696

big if large

>> No.7532710

my email is my full name @ gmail and my password is "justinbieberownsmyasshole". Not a good day.

>> No.7532712

just some larper with shorts open. not a bad idea actually if it goes viral.

>> No.7532768

true if big

>> No.7532782

tethered up @8800,waiting for the crash.

and we just got the perfect scapegoat after bitgrail "hack"

>> No.7532800
File: 240 KB, 404x436, 1518043564631.png [View same] [iqdb] [saucenao] [google]
7532800

>>7532627
He probably didn't want to take the time to create 25 email accounts and polo accounts with 2FA enabled. Create a few and scatter them in the list.

>> No.7532816

big, therefore true

>> No.7532817

>>7532366
and now you've doxxed yourself as a 4chan poster, you've really gone dun it

>> No.7532849

>>7532251
poloniex can die in a fire. 7 month open ticket for 2000$

>> No.7532901

Holy fucking shit they work .

>> No.7532946

>>7532251
HOLY FUCK THE PASSWORDS WORK

>> No.7532952

Feels good having 2fa on absolutely everything

>> No.7532954

>>7532539
>using le stronk alphanumeric password in plaintext is somehow more secure
the absolute state of /biz/

>> No.7532967

Cool good thing I never used Poloniex because I always heard how shit it is.

>> No.7532969

>>7532577
hotmail ones didnt work

>> No.7532972

fuck

>> No.7532980

huge if big

>> No.7532984

>>7532251
can someone explain to me why anyone uses any exchange that's not Bittrex or Binance? What's the point of using Bitgrail or Poloniex or AbuCoins or any of that? It all just seems so sketchy to me

>> No.7532995

first of all Poloniex definitely uses a hash algo like bcrypt
second of all, you don't have "usernames" on poloniex so you can already know this isn't their database

>> No.7532998
File: 480 KB, 1200x675, 1517129612846.png [View same] [iqdb] [saucenao] [google]
7532998

Friendly reminder to sell now. This is the perfect storm with the Binance and Bitgrail bullshit flying

>> No.7532999

>>7532984
shitcoins my dude. shitcoins.

>> No.7533000
File: 116 KB, 336x592, P3Ozgbs.png [View same] [iqdb] [saucenao] [google]
7533000

>>7532251
who is this and why does he follow

>> No.7533008

>>7532320
you would be surprised how many incompetent retards are calling themselves software developers

>> No.7533011

>>7532984
Anyone whos been in this space for more than 6-7 months has at some point had a polo account. Polo was the bittrex or binance before they took off.

>> No.7533031

>>7532999
Binance has so many though

>>7533011
this makes sense

also checked my dudes

>> No.7533038

>>7533011
Good thing I came in July lel
Bittrex and Binance are secure af

>> No.7533039

I bet people that shit their pants right now, will loose their own info on his super secret website he's prepping.
what a day!

>> No.7533041
File: 64 KB, 262x289, 1518152813873.png [View same] [iqdb] [saucenao] [google]
7533041

>>7532984

>Abucoins

>> No.7533084

>>7532952
now's the part where you backup the 2fa keys
/data/data/com.google.android.apps.authenticator2/databases/databases

>> No.7533085

>>7532251
>unhashed passwords
That's really bad.

>> No.7533093

honestly, do they work? Still hackers can't withdrawl without email acces. API key's might be a problem

>> No.7533098

OMFG
Try to log in with these accounts, shit works only need 2fa ofc and the other i tried had email code send -_-

>> No.7533114
File: 11 KB, 645x773, 1516914726538.png [View same] [iqdb] [saucenao] [google]
7533114

>>7533031
They want the tier 3 shitcoins like nano and turtle

>> No.7533130

>>7532984
Newfag spotted
>up to 300 BTC payments required to list coins
>less than a year old
Binance is a exit scam waiting to happen
Bittrex is a dinosaur in deep shit
And both don't have all the promising coins listed

>> No.7533132

OH NO!!! MY PRECIOUS 80 DOLLAR WORTH OF ADA I STILL MIGHT HAVE ON POLO!!! AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAHHHHHHHHHH!!!!! good thing polo decided to be turbo faggots to its legacy holders and i moved them all to bittrex months ago

>> No.7533139
File: 1.84 MB, 475x277, 1515793219234.gif [View same] [iqdb] [saucenao] [google]
7533139

>Oh crap
>Login into Poloniex account from years years ago
>Oh right i don't have any funds in here anymore
>Enable 2FA just because

>> No.7533175

Poloshit is really fucking shitty for having password in clear text, this is actually illegal where I live.

>> No.7533177

Tried all of them. fake.

>> No.7533187
File: 185 KB, 643x577, gdsgfdsg.jpg [View same] [iqdb] [saucenao] [google]
7533187

also

>> No.7533207

>>7533187
this is from some stupid phishing site he created that steals credentials
must be a mimic of poloniex domain..

how people on /biz/ this stupid ffs

>> No.7533218

>>7533175
kazakhstan?

>> No.7533220
File: 535 KB, 1000x946, 1508653247194.png [View same] [iqdb] [saucenao] [google]
7533220

some of these mails are used on normiebook and dont look lie bots/fresh accounts.

>> No.7533221

Maybe he made those accounts? Full list or larp.

>> No.7533227

>>7533177
the vova@ukr.net works

>> No.7533228

>>7532251
what does this imply?

>> No.7533237

>>7533187
These idiots always have blatant typos. The fake stellar blog post that spelled it 'steller" was great.

>> No.7533241

>>7532599
This. Digits confirm. It could be an attempt to extort money from Poloniex.

>> No.7533250

>>7532984
You don't understand. You have it backwards. Poloniex is the tried and true American exchange that we all used for altcoins, for years. Bittrex and Binance were and still are seen as sketchy shitcoin exchanges to buy complete garbage that just happened to explode over the past few months as more and more people were pressured to buy lower cap shitcoins. Poloniex was seen as something of a gatekeeper for which altcoins are "legit," for a long time. If they get hacked, you can be sure it will have massive effects on the entire crypto economy.

That being said, I think this is nothing at all because Poloniex was one of the most secure exchanges for years. Almost as secure as you'd expect something like Gemini, Gdax, Bitstamp to be. Not quite but up there but for altcoins.

>> No.7533253

>>7533207
this is probably the most true

>> No.7533275

>tfw don't even have a polo account and still just changed all my exchange passwords

>> No.7533283

>>7533227
no it doesn't

>>7533220
are you an expert on bot fresh account appearance you fucking dork

>> No.7533291

>>7533187
Ah, nice.

>> No.7533292

>>7532251
>plaintext passwords

Fake.

>> No.7533299

>>7533130
So what one are you supposed to use?

>> No.7533301

>>7533207
Prob this gay guy

>> No.7533321

>>7532251
They range from terrible passwords like "miner3033" to great ones like "c&%e3nC&%E3N" and yet it doesn't matter because they're all in plaintext.

I tried the 99dent@naver.com one and it works, just needed 2FA.

>> No.7533329

>>7533250
this guy fucks

>> No.7533401

>>7532816
what if false thefore small?
big if tru

>> No.7533442

Lol this is fake. He created those accounts himself.

>> No.7533456

>>7533283
>no it doesn't
It does work. I tested it too.
skupeyko-vova@urk.net
5800xm5800xm

Test it yourself.

>> No.7533479
File: 188 KB, 650x648, 1515291073825.jpg [View same] [iqdb] [saucenao] [google]
7533479

>>7533008
this
i've worked a bit as a freelance webdev in the past
nearly half of the websites i've done backend stuff for have stored sensitive information in plain text in an sql database
websites usually ranged between 500 and 25k registered users
this is the reason why you should use different emails and different passwords for every site you register on

>> No.7533495

This is truely the wild west era of digital assets
Its kind of humbling to witness the entire thing in my lifetime
I feel like we are in the equivalent to "not being able to call because you are using the internet" period but for crypto

>> No.7533507

>>7533442
or they were phished

>> No.7533514

>>7532617
>>7532954
>what is password reuse
The only real risk, you absolute fucking brainlets
Do you think poloniex won't reset every password after this is leaked?

>> No.7533534

>>7533495
aye cheers mum thanks for picking up the phone id only been trying to download that file for the last four hours

>> No.7533549

I will give you advice. Take your money. Tomorrow you will see very serious things.

>> No.7533561

>>7532279
>>7532320
There's already hundreds of modules/libaries that does password hashing for you. Don't need to do anything. This has got to be a troll

>> No.7533578

>>7533549
>>7532251

sounds just like a pajeet phisher who missed out on buying at $6k

>> No.7533603

>>7533549
whoaaaa scary.

>> No.7533612

>>7532285
prove it

>> No.7533647

>>7533549
oooh no, sold everything

>> No.7533648

>>7532320
Several billion worth of passwords and email addresses have been stolen because of this over the past 10 years. Only 14 year olds, really?

>> No.7533654

I think the duplicated entries and misspelled email (gmai.com) point to this being the results of a phishing attack rather than an actual hack

>> No.7533688

>>7532251
thanks just bought 100k accounts

then bought 100k xmr

thanks

>> No.7533691

>>7533648
Honestly bitcoin is based on cryptography. If as a bitcoin exchange that's been around for years you still didn't figure you have to hash your passwords. Which is bassically 10 lines of code. You deserve to be hacked

>> No.7533703

>>7533207
This.

It's why there are duplicate entries. Retards keep re-entering their details wondering why it's not working.

Source: had a phishing site like 7 years ago

>> No.7533745

>>7532362
They work actually.

This shit is big.

>> No.7533786

>>7533654
That's what we try to tell to scare pants

>> No.7533788

>>7532320
haven't there been countless database hacks of major corporations over the last decade where people found tons of customer data/passwords/personal info stored in plain text?

like when that Playstation Network was hacked and everyones credit card details/cvvs were in plain text? or the Equifax shit? many others like that

>> No.7533795

well we've got 2fa anyway

>> No.7533814
File: 113 KB, 250x250, lfpo.png [View same] [iqdb] [saucenao] [google]
7533814

fake news

holy shit guys, dont try to log in to any of these, they are taking your IPs

>> No.7533830
File: 417 KB, 1846x867, 1517767124046.png [View same] [iqdb] [saucenao] [google]
7533830

>>7533578
>hacker doesn't speak perfect english
>he must have missed the dip

okay

>> No.7533849

>>7532251
lmfao skiddy either:
makes a few accounts on poloniex
or
peppers a few phished accounts in there

seriously, crypto is so fucking easy to target. imagine this if you will. all these scam ICOs asking users to join their mailing list. how easy would it be for them to sell the goddamn list or spam out phishing emails to all the people on the mailing list? or someone writes a bot, sells it, installs a keylogger, or modifies the JS cache on the browser, steals their cookies for auth tokens, etc.

It's too easy. People are forgetting/not realizing that crypto is NOT intended for people inexperienced with computer security. Absolutely no liability or safeguards here.

>> No.7533884

KEEP IN MIND: This guy could have easily made these accounts himself. Not that much effort for very high quality FUD

>>7533187
good catch

>> No.7533925

>>7533654
Gimai.com is still valid email. But the duplicate ones probably confirm phishing

>> No.7533931

>>7533814
so? it's not my IP lol

>> No.7533949

>>7533849
Like a week ago I got spam about some BTC-e/wex refunding and shit with a beautiful link to reset password.
I bet my rock hard dick that 10% of people click on that and give their info.

>> No.7533953

>>7533139
Exact same situation.

>> No.7533991
File: 39 KB, 640x622, 1517246761128.jpg [View same] [iqdb] [saucenao] [google]
7533991

>tfw i had forgotten i had 7.5 ether on polo and discovered it late december

>> No.7533992

>poloniex db
>passwords in plaintext

if you faggots actually believe this is real burn your crypto and shoot yourself

>> No.7534006

>>7532485
do they have any funds left?

>> No.7534035

>>7533814
>implying that im not behind 1000 proxies

grow some balls faggit

>> No.7534036

>>7534006
they probably hit 2fa wall and can't do nothing more

>> No.7534064

>>7532984
some alts aren't on bittrex or binance yet

>> No.7534137

>>7534035

Enjoy licking men's assholes queer

>> No.7534165
File: 1.72 MB, 900x600, niceeee.gif [View same] [iqdb] [saucenao] [google]
7534165

>>7532251
>mfw I used Polo once but with a completely scrambled shit password like c3u7feozqyshzo75hdfs29im5gzh7vrm and a different email than the one I use for actual important shit

>> No.7534184

>>7533992
>passwords can be obtained only from the database

Found the brainlet

>> No.7534214

>2018
using shitty exchanges like this and bittrex

>> No.7534267

>>7534184
the twitter is literally "poloniexhack" are you telling me phishing is the eqv of hacking an exchange?

>> No.7534289

>>7534184
>Being this retarded

>> No.7534294

>>7534267
what?

>> No.7534296

>>7533479
You've done freelance webdev work in the past. Not an actual developer. What you are describing is not the norm in any way shape or form. Hashing passwords has been the norm for nearly 20 years at this point.

There is a zero percent chance that Poloniex was storing passwords plaintext. This guy created a bunch of bullshit accounts and took screenshots/made fake output from a DB. He then tells people to contact him if they don't want their account listed in the dump. I WONDER WHY? He's trying to trick idiots into giving him their username and password.

If you think this is legit in any way you are completely retarded.

>> No.7534313

>>7533992
You moronic brainlet you know there exist trillions of sha256 databases with most of the common passwords and string combinations out there.. if they simply hash the pw without taking userid or anythign else into consideration its easy to "reverse" the db hashes you fucking fuck

>> No.7534374

>>7534267
Look, brainlet: >>7533187.
It's from a phishing site at worst.

>> No.7534394

>>7534313
>thinking any large business' are using sha256 in 2018

>> No.7534427

>>7534313
>he doesn't know what bcrypt is
>he doesn't know what salt is
>he doesn't know what rounds are
wow you should probably stop posting. seriously.. why would you pretend you know what you're talking about? what kind of retard uses sha256 in a database?

>> No.7534461

Withdrew all my funds from Polo when they said they'd begin clamping down on legacy accounts Q1 2018. Watching this though.

>> No.7534474

>>7532251
>>7532424
Thanks for the heads up. Just changed all my passwords, better safe than sorry. Don’t become a statistic acting like a badass who doesn’t care

>> No.7534498

>>7532251
This is fake. Sage this thread for goodness sake.

>> No.7534508

>>7534374
who gives a fuck if it's from a phishing site faggot it's being presented as if it's a database

>> No.7534634
File: 3.73 MB, 470x200, 1517449417969.gif [View same] [iqdb] [saucenao] [google]
7534634

>>7532251
>https://twitter.com/poloniexhack/status/962288838692474880

MFW I use different passwords that were generated by norton password generator for everything

>> No.7534636
File: 166 KB, 1992x800, Screen Shot 2018-02-10 at 1.49.47 PM.png [View same] [iqdb] [saucenao] [google]
7534636

>>7532251
it's fud lmao all the accounts have $0 already went through 5 they were recently made

>> No.7534671

>>7534634
>using norton
>not using keepass

lol noob

>> No.7534674

>>7534636
Have fun getting your own account locked now

>> No.7534683

>>7534374
this

>> No.7534704
File: 102 KB, 320x303, 1516469644398.png [View same] [iqdb] [saucenao] [google]
7534704

>>7534671

>> No.7534711

>>7534674
i don't use that shit site also so I don't care + I'm using a VM + tor + vpn

>> No.7534721

>keeping your money on exchanges

>> No.7534734

>>7534636
absolute madman

>> No.7534753

>>7532251
>toan91kt@gmai.com
Did Poloniex remove an L from this guy's email address? What did they mean by this?

>> No.7534755

As a hodler I admit this is impressive fud

>> No.7534800

>>7532800
crypto coding goddess pls bless us with gains

>> No.7534836

>>7534753
he messed up when he logged into the guys phishing site and that was recorded the guy prob had ppl login to the site --> enter email + pw ---> then had it redirect to the real polo login page to make it seem like it glitched out

>> No.7534848

>>7534508
>as if it's a database

It's a fucking hashmap you dump bastard. it could be obtained from everywhere. get some brain.

>> No.7535045

>>7534267
>>7534289

>Be rogue developer at polo. Call one liner log function on authentication step for a few days/hours. Collect a massive amount of user credentials then remove the logger and leave the company.

Profit?

>> No.7535201

Bitgrail ,Poloniex,...The end of the world incoming...

>> No.7535340

>>7533139
my dog loves to have the back of his head rubbed just like that. wonder if i got him something like that would he just use it 24/7.

>> No.7535369

>>7532279
it's his list of phished pw

>> No.7535374

>>7532800
Bitch! I;ve been waiting to get approved in that shitexchange for 6 months. How are you creating 20+ accounts in any reasonable timeframe?

>> No.7535381

>>7534704
keepass is the shit

>> No.7535475
File: 65 KB, 500x551, 163xpj[1].jpg [View same] [iqdb] [saucenao] [google]
7535475

>>7533884
>>7534636
>made these accounts himself.
>lets enable 2FA

lol hodlshits in denial

>> No.7535516

>tfw keeping my short open just in case

Opened at $8600

We're going sideways anyway, little chance of liquidation given it's at $9100

>> No.7535635

>>7534214
What's wrong with it? It works. I can exchange just fine. It doesn't go down like Binance shit.
My daily trading is doing just fine. Make a few k. And withdrew completely fine.

Also make sure you have 2fa enabled. That should go for any exchange really

>> No.7535691

>>7534165
>c3u7feozqyshzo75hdfs29im5gzh7vrm
>no special characters
It's like you want to get hacked

>> No.7535805

>>7535475
retard I said he phished them see >>7534836

>> No.7536359

>>7535691
yeah it has special characters, also caps, but my point was that I'm not going for "Ih6niggers" as my password with my work email like some retards do. It's just random crap that doesn't mean anything.

>> No.7536891
File: 53 KB, 571x618, e43[1].png [View same] [iqdb] [saucenao] [google]
7536891

>>7535805
>phishing Goolag emails in 2018

you know what to do.

>> No.7536949

>>7534296
> Hashing passwords has been the norm for nearly 20 years at this point.
Doesn't matter, people cut corners and never go back and fix their mistakes, and it gets worse as the org structure expands

>> No.7537041
File: 86 KB, 640x960, 10470878_10203724492745165_4836348333542428769_n.jpg [View same] [iqdb] [saucenao] [google]
7537041

>>7532366

>> No.7537751

>>7532320

save mine all in a txt in some folder lol

>> No.7538510

>>7532539

No one would ever guess 'BigBootyHos6969YeahBoi'

>> No.7538610

>>7533011
>Anyone whos been in this space for more than 6-7 months has at some point had a polo account. Polo was the bittrex or binance before they took off.

And consider how many people use the exact same email-password across multiple sites...

If you're on poloniex, and you use the same login/pw combos elsewhere, you better change your shit because they WILL be trying those credentials elsewhere.

>> No.7538683

>>7532251
>https://twitter.com/poloniexhack/status/962288838692474880

Can somebody please mail the people their passwords? Badboy26!

>> No.7538882

>>7536891
Checking those sweet hidden dubs (9*9*11=891) and that killer meme! (saved)

>> No.7539058
File: 8 KB, 298x224, matt damon jr.jpg [View same] [iqdb] [saucenao] [google]
7539058

>>7532984
The easiest fucking way for a sure 2-3x is to find the popular chinkcoins that are on the top 100, but not listed on Binance.

They usually get listed within a few weeks, and it always does a 2x right away.

>> No.7539865

>>7537041
>9gag

kys

>> No.7539882

>>7538882
test

>> No.7539907
File: 194 KB, 353x429, ShutUpMegTrump.png [View same] [iqdb] [saucenao] [google]
7539907

test

>> No.7539958

>>7538882
>>7539882
>882
hmmmmm

>> No.7539959

>>7532251
Kek my old account in on there

>> No.7539995

I dont even give a heck, lets see them get passed 2fa.

>> No.7540025

>>7532413
Even then it can be decrypted using a rainbow table

>> No.7540085

>>7532251

I'm unironically sunnynite792.

believe it or don't, this is fucked.

>> No.7540139

>>7540085
holy shit so am i

believe it or not guys, somehow this other guy was me the whole time

>> No.7540744

>>7533299
poloniex is awesome, bitfinex is also a good one

>> No.7540818

If someone wanted to fake this, they could just have created the accounts in the screenshot themselves.

Just saying

>> No.7540883
File: 5 KB, 236x190, 8E8389B0-2985-4BA0-BE70-DFA19F76334B.jpg [View same] [iqdb] [saucenao] [google]
7540883

Fuck you, Bryce

>> No.7540887

>>7532251
Everything has 2fa feelsbadman

>> No.7540926

>>7532995
>second of all, you don't have "usernames" on poloniex

didnt they have usernames for their "trollbox"?

>> No.7541049

>>7532285
it doesnt even matter when you use 2fa

>> No.7541254

>>7532967
>tfw 2fa
>tfw 2k limit per day
good luck faggots

>> No.7542511

2fa lol. Don’t be a dumbass

>> No.7542584

This isn't happening

>> No.7542669

>>7536949
You are DE-LUSIONAL if you think an operation at the scale of Poloniex doesn't hash passwords.

I hate to just ad hominem the shit out of you, but there is no discussion to be had here. You are so outside of your depth if you think they could even run an operation at that scale with practices like that.

No one was hacked, and if you think Poloniex stores passwords clear you're retarded.

Here's a quick test - try to recover your password and tell me if they send it back to you in the clear or not. They won't. They'll have you set a new password because they DO NOT STORE your password in plain text.

>> No.7542691

>>7534313
I'll take WHAT IS SALTING FOR $400, ALEX.

Why do people that have no idea what they're talking about insist on spewing their half baked idiocy to others?

>> No.7542984

>>7532539
>Do people unironically actually not use strong alphanumeric passwords?
complexity isn't as important as length. Anything under 8 characters can be rainbow tabled. And if source is decrypted or *gasp* plain-text then it does matter for shit.