_GOTOBOTTOM
User Support
Having a problem with the site? Post it here.
Has Armorama been hacked?
TankTalk
Visit this Community
Canada
Member Since: December 02, 2013
entire network: 39 Posts
KitMaker Network: 9 Posts
Posted: Sunday, February 10, 2019 - 12:05 PM UTC
I just got one of those slimy blackmail emails and the sender knew my Armorama password!! I've since changed it, but if they've hacked the site there should be more....
Namabiiru
Staff MemberAssociate Editor
MODEL SHIPWRIGHTS
#399
Visit this Community
Rhode Island, United States
Member Since: March 05, 2014
entire network: 2,888 Posts
KitMaker Network: 489 Posts
Posted: Sunday, February 10, 2019 - 12:19 PM UTC
That's a pretty common scam spam right now, and not unique to Armorama. It's not so much the site has been hacked, but the perpetrators have gotten their hands on old (not current) user lists. I've gotten a ton of those emails. Not one of them has a password for any account I'm particularly concerned about. If someone wants to hijack my KMN account, I'll be sad, but it won't be the end of the world.

TankTalk
Visit this Community
Canada
Member Since: December 02, 2013
entire network: 39 Posts
KitMaker Network: 9 Posts
Posted: Monday, February 11, 2019 - 03:52 AM UTC

Quoted Text

It's not so much the site has been hacked, but the perpetrators have gotten their hands on old (not current) user lists.[ ]



I'm a bit confused as to what form a user list is found and how it is obtained in the public domain containing my current password? Of course this isn't a critical site like banking, but Kit Maker Network is a very large platform. Just googling about this scam, it seems sites with weak security are vulnerable.
CMOT
Staff MemberEditor-in-Chief
ARMORAMA
Visit this Community
England - South West, United Kingdom
Member Since: May 14, 2006
entire network: 10,954 Posts
KitMaker Network: 1,873 Posts
Posted: Monday, February 11, 2019 - 06:42 AM UTC
Dean your password is encrypted on the site and so even a hack does not give that information. What they do get is a list of encrypted passwords that are then cracked as most people use words and dates that a system can figure out, Using random figures, symbols and upper and lower case letters will usually protect you against this issue, but nothing is 100% secure.
TankTalk
Visit this Community
Canada
Member Since: December 02, 2013
entire network: 39 Posts
KitMaker Network: 9 Posts
Posted: Monday, February 11, 2019 - 12:36 PM UTC
Fascinating. My MacOS has a password generator that would give such randomness. Of course I won't be able to remember them
CMOT
Staff MemberEditor-in-Chief
ARMORAMA
Visit this Community
England - South West, United Kingdom
Member Since: May 14, 2006
entire network: 10,954 Posts
KitMaker Network: 1,873 Posts
Posted: Monday, February 11, 2019 - 11:11 PM UTC
All I can say then Dean is that they are a pain the the A R S E
RobinNilsson
Staff MemberDirector of Member Services
KITMAKER NETWORK
Visit this Community
Stockholm, Sweden
Member Since: November 29, 2006
entire network: 6,693 Posts
KitMaker Network: 1,042 Posts
Posted: Tuesday, February 12, 2019 - 01:27 AM UTC
My password is really simple,
it is:
***************

lahi
Visit this Community
Aarhus, Denmark
Member Since: August 04, 2006
entire network: 1 Posts
KitMaker Network: 1 Posts
Posted: Monday, March 30, 2020 - 11:44 AM UTC
Hi. I just found this thread. Recently, I have been receiving spam from NetFlix - apparantly someone has used my email address to try to create an account at NetFlix. As the mail address used is one I used specifically for this account at kitmaker.net (quite a while ago, frankly I had forgotten about it), it must definitely have leaked from here. (An address of the form [email protected].)

As I can read from above, apparantly user data has been leaked from kitmaker.net in the past. I suppose that is how it happened. I don't recall seeing any message about this? Even if passwords are not compromised, the leakage of email adresses is bad enough.
Helly8800DK
Visit this Community
Denmark
Member Since: June 14, 2010
entire network: 1 Posts
KitMaker Network: 1 Posts
Posted: Tuesday, June 30, 2020 - 09:08 AM UTC

Quoted Text

Hi. I just found this thread. Recently, I have been receiving spam from NetFlix - apparantly someone has used my email address to try to create an account at NetFlix. As the mail address used is one I used specifically for this account at kitmaker.net (quite a while ago, frankly I had forgotten about it), it must definitely have leaked from here. (An address of the form [email protected].)

As I can read from above, apparantly user data has been leaked from kitmaker.net in the past. I suppose that is how it happened. I don't recall seeing any message about this? Even if passwords are not compromised, the leakage of email adresses is bad enough.



It's still a problem! I have done the same thing as you. My email adress to this site is the only site where I use it Kitmakernetwork@my_domainname. and they know my password as well. It was in the mail I got...
So don't leave a phone numer or an adress in your account profile...
brekinapez
Visit this Community
Georgia, United States
Member Since: July 26, 2013
entire network: 2,272 Posts
KitMaker Network: 134 Posts
Posted: Tuesday, June 30, 2020 - 11:59 AM UTC
Try this site to check all the email addresses you use and see how many are compromised.

https://haveibeenpwned.com/

The results may surprise/dishearten you.
 _GOTOTOP