Stamp Community Family of Web Sites
Thousands of stamps, consistently graded, competitively priced and hundreds of in-depth blog posts to read








Stamp Community Forum
 
Username:
Password:
Save Password
Forgot your Password?

This page may contain links that result in small commissions to keep this free site up and running.

Welcome Guest! Registering and/or logging in will remove the anchor (bottom) ads. It's Free!

Stamporama Website Hacked

Next Page    
 
To participate in the forum you must log in or register.
Author Previous TopicReplies: 28 / Views: 5,416Next Topic
Page: of 2
Pillar Of The Community
Learn More...
United States
3046 Posts
Posted 10/03/2015   3:02 pm  Show Profile Bookmark this topic Add apastuszak to your friends list Get a Link to this Message
I don't know if anyone here uses the Stamporama website, but I just an email from them that their website was hacked and the entire user database with email address and password was posted online.

Go change your passwords if you use the site, and, PLEASE use a password manager, so you don't have the same password on multiple sites.
Send note to Staff
Free Ukrainian Stamp Album and modified Mystic Stamp Album Pages - http://www.stamphacks.com
Ukrainian Philatelic and Numismatic Society Member #1212: http://www.upns.org
Eire Philatelic Association Member #2869: http://www.eirephilatelicassoc.org/

Pillar Of The Community
United States
1624 Posts
Posted 10/03/2015   3:36 pm  Show Profile Bookmark this reply Add sdtom to your friends list  Get a Link to this Reply
good advice. I don't use the site so I'm safe
Send note to Staff  Go to Top of Page
Moderator
Learn More...
United States
12330 Posts
Posted 10/03/2015   3:37 pm  Show Profile Bookmark this reply Add 51studebaker to your friends list  Get a Link to this Reply
Be careful, the email sounds a bit like a phishing email. Are you sure it came from Stamporama? If their email database was hacked (with email addresses) I am not sure they would emails to contact everyone. Has anyone else gotten an email?
Don
Send note to Staff  Go to Top of Page
Pillar Of The Community
621 Posts
Posted 10/03/2015   3:49 pm  Show Profile Bookmark this reply Add ThomasGalloway to your friends list  Get a Link to this Reply
I received 2, a couple hours apart. The Forum at the Stamporama has a post that states the same thing the emails contain. Lots of comments from users, but nothing like a "Wait, wait, we really haven't . . . " type post.
Send note to Staff  Go to Top of Page
Pillar Of The Community
Learn More...
United States
3046 Posts
Posted 10/03/2015   3:50 pm  Show Profile Bookmark this reply Add apastuszak to your friends list  Get a Link to this Reply
The only thing that makes me think the email is genuine is that it doesn't provide a link to click on to get to stamporama to reset your password.

The email is also plain text, and not HTML, so they can't put any links in it or send malicious javascript.
Send note to Staff  Go to Top of Page
Free Ukrainian Stamp Album and modified Mystic Stamp Album Pages - http://www.stamphacks.com
Ukrainian Philatelic and Numismatic Society Member #1212: http://www.upns.org
Eire Philatelic Association Member #2869: http://www.eirephilatelicassoc.org/
Valued Member
United States
202 Posts
Posted 10/03/2015   4:00 pm  Show Profile Bookmark this reply Add BradS to your friends list  Get a Link to this Reply
The email looks legit plus when you log onto the website and go to the forum there is a message about it.
Send note to Staff  Go to Top of Page
Pillar Of The Community
Canada
4648 Posts
Posted 10/03/2015   5:16 pm  Show Profile Bookmark this reply Add Bujutsu to your friends list  Get a Link to this Reply
I too got an email from SOR advising me of this problem.

Chimo

Bujutsu
Send note to Staff  Go to Top of Page
Pillar Of The Community
United States
772 Posts
Posted 10/03/2015   7:57 pm  Show Profile Bookmark this reply Add chris2015 to your friends list  Get a Link to this Reply
I too got the e-mail from SOR. I was also worried that it might be a phishing email, but what benefit can anyone get by you just changing your password. They were not asking for anything else other than go to the SOR site and change your password, which I did.
Send note to Staff  Go to Top of Page
Pillar Of The Community
United States
898 Posts
Posted 10/04/2015   4:20 pm  Show Profile Bookmark this reply Add Philatarium to your friends list  Get a Link to this Reply
It is legit. They even announce it on the website now, and I was also in touch with their administrator.
Send note to Staff  Go to Top of Page
-- Japan, Korea, Trucial States & more on HipStamp: https://www.hipstamp.com/store/the-philatarium

long-term member: American Philatelic Society, Int'l Society for Japanese Philately, & others
Pillar Of The Community
Learn More...
United States
3046 Posts
Posted 10/04/2015   4:35 pm  Show Profile Bookmark this reply Add apastuszak to your friends list  Get a Link to this Reply
Ok, just to plug something here.

USE A PASSWORD MANAGER.

I use one, and the password on Stamporama was unique to only that site, so my damage foorprint was pretty much non-existent.
Send note to Staff  Go to Top of Page
Free Ukrainian Stamp Album and modified Mystic Stamp Album Pages - http://www.stamphacks.com
Ukrainian Philatelic and Numismatic Society Member #1212: http://www.upns.org
Eire Philatelic Association Member #2869: http://www.eirephilatelicassoc.org/
Rest in Peace
7742 Posts
Posted 10/04/2015   4:45 pm  Show Profile Bookmark this reply Add wert to your friends list  Get a Link to this Reply

Quote:
Be careful, the email sounds a bit like a phishing email. Are you sure it came from Stamporama?


Good advice...Be careful as Don says.

Robert
Send note to Staff  Go to Top of Page
Forum Dad
Learn More...
USA
2055 Posts
Posted 10/04/2015   5:18 pm  Show Profile Bookmark this reply Add bobby131313 to your friends list  Get a Link to this Reply

Quote:
USE A PASSWORD MANAGER.


Sorry but that's not good advice. If that gets hacked ALL your business is exposed.

http://www.forbes.com/sites/katevin...r-passwords/
Send note to Staff  Go to Top of Page
Pillar Of The Community
Learn More...
United States
3046 Posts
Posted 10/04/2015   5:26 pm  Show Profile Bookmark this reply Add apastuszak to your friends list  Get a Link to this Reply

Quote:


Sorry but that's not good advice. If that gets hacked ALL your business is exposed.

http://www.forbes.com/sites/katevin...r-passwords/


You can use a local password manager. You don't have to use a hosted one.
Send note to Staff  Go to Top of Page
Free Ukrainian Stamp Album and modified Mystic Stamp Album Pages - http://www.stamphacks.com
Ukrainian Philatelic and Numismatic Society Member #1212: http://www.upns.org
Eire Philatelic Association Member #2869: http://www.eirephilatelicassoc.org/
Forum Dad
Learn More...
USA
2055 Posts
Posted 10/04/2015   6:01 pm  Show Profile Bookmark this reply Add bobby131313 to your friends list  Get a Link to this Reply
You think a local one can't be hacked?
Send note to Staff  Go to Top of Page
Pillar Of The Community
Learn More...
United States
3046 Posts
Posted 10/04/2015   6:31 pm  Show Profile Bookmark this reply Add apastuszak to your friends list  Get a Link to this Reply

Quote:
You think a local one can't be hacked?


If someone manages to hack into your local PC and steals your password file, you've got far greater problems.

Local password files are encrypted. If you use a good strong password, they'd need to steal your file, and convince you to give up your password to them.

With the Lastpass hack you linked to, master passwords might have ben compromised. But those passwords were salted, peppered and hashed 1,000 times. Researchers estimated it would take YEARS to brute force a Lastpass master password.

That's why phishing scemes are so popular. It's a lot easier to trick people into revealing that password than to try and brute force something.

Unbreakable encryption exists. Password managers use good encryption. But you need to use a good strong master password.

You're are the weakest link, not the product you use.
Send note to Staff  Go to Top of Page
Free Ukrainian Stamp Album and modified Mystic Stamp Album Pages - http://www.stamphacks.com
Ukrainian Philatelic and Numismatic Society Member #1212: http://www.upns.org
Eire Philatelic Association Member #2869: http://www.eirephilatelicassoc.org/
Forum Dad
Learn More...
USA
2055 Posts
Posted 10/04/2015   6:45 pm  Show Profile Bookmark this reply Add bobby131313 to your friends list  Get a Link to this Reply
Lots of techno babble, all of which I know all about.

But here's the bottom line. If your browser password extension can show you your password, a browser hack can show the hacker your password. It's that simple. Your fooling yourself if you think it isn't.
Send note to Staff  Go to Top of Page
Page: of 2 Previous TopicReplies: 28 / Views: 5,416Next Topic  
Next Page
 
To participate in the forum you must log in or register.

Go to Top of Page

Disclaimer: While a tremendous amount of effort goes into ensuring the accuracy of the information contained in this site, Stamp Community assumes no liability for errors. Copyright 2005 - 2026 Stamp Community Family - All rights reserved worldwide. Use of any images or content on this website without prior written permission of Stamp Community or the original lender is strictly prohibited.
Privacy Policy / Terms of Use    Advertise Here
Stamp Community Forum © 2007 - 2026 Stamp Community Forums
It took 0.34 seconds to lick this stamp. Powered By: Snitz Forums 2000 Version 3.4.05