Leo en BGG de Scott Alden (es decir el boss de BGG):
http://boardgamegeek.com/thread/801384/please-read-security-breach-information
http://boardgamegeek.com/thread/801384/please-read-security-breach-information
CitarLast month we received a few reports from BGG users whose email address was targeted by phishing attempts. What made this a concern was that the email addresses targeted had only been used to register on BGG and for no other purpose. This suggested a potential hole in our security. For a while we couldn't find any evidence that such a breach was possible. However last week, after a thorough investigation, we were finally able to identify several weaknesses that could have been used to access private account information.
These security holes have now been patched. To date we are still only aware of the reported phishing attempts (scammers trying to steal WoW accounts), however we want to let you all know that any part of the database could have been compromised including the following personal info:
Name (if provided)
Address (if provided)
Encrypted password verification value
We can't say with any certainty what information was taken and who has been affected. All we know is that these are the areas that we have found that were vulnerable.
Regarding passwords, we DO NOT store your unencrypted password, so if passwords were accessed the hacker(s) only have an encrypted version. However there is always a chance that someone might be able to reverse engineer your actual password. Therefore we strongly recommend changing your password here and also changing your password on any other sites where your password is the same as the one you used here.
We have since improved our password storage system.
I'm sorry for any problems this may have caused. Hopefully it stays restricted to scammers trying to steal WoW accounts through phishing emails. If you notice any other suspicious activity that may have been related to this breach, please let us know at contact@boardgamegeek.com






?