Hi,
It has come to my attention that CF had a security loophole - it was an obscure one, but it was one that one or more hackers had taken advantage of. What it allowed was for a hacker to copy a member's cookie onto their own computer, and to log on as the member.
The hacker did not get the member's password since that is encrypted - all he got was the cookie. However, with this cookie, the hacker could log in as the member. In fact, this hacker got access to staff accounts as well.
I have spoken to the hacker himself, and though his identity will remain private, this is not something I've made up. It's real.
As such, I've made it so that all members are forced to change their passwords. Once you have changed your password, this will invalidate any old cookie, and would render the hacker unable to log in as another member anymore.
The security loophole has been removed since.
This only affects people who had their cookies stolen - not all members are affected. But to play it safe, all members must have their passwords changed just in case.
My apologies for the inconvenience. I am still in shock, and still in a phase of recovering from this.
Thank you for understanding.
It has come to my attention that CF had a security loophole - it was an obscure one, but it was one that one or more hackers had taken advantage of. What it allowed was for a hacker to copy a member's cookie onto their own computer, and to log on as the member.
The hacker did not get the member's password since that is encrypted - all he got was the cookie. However, with this cookie, the hacker could log in as the member. In fact, this hacker got access to staff accounts as well.
I have spoken to the hacker himself, and though his identity will remain private, this is not something I've made up. It's real.
As such, I've made it so that all members are forced to change their passwords. Once you have changed your password, this will invalidate any old cookie, and would render the hacker unable to log in as another member anymore.
The security loophole has been removed since.
This only affects people who had their cookies stolen - not all members are affected. But to play it safe, all members must have their passwords changed just in case.
My apologies for the inconvenience. I am still in shock, and still in a phase of recovering from this.
Thank you for understanding.