Jump to content

Regarding Password Change Email


JoeW
 Share

Recommended Posts

Hey all, 

I am forcing password resets on accounts, so I figured I would let people know what was up. 

Earlier today we found a long time forum user post a spam link. When checking into a case of an apparent compromised account I noticed several others. At that point as a in an abundance of caution I forced password resets for most users while I investigated the cause. 

We didn't see anything else unusual and it appears to just be the regular old badguy fishing for weak accounts. 

I did make a change to require stronger passwords, not TOO strong because that's super annoying. But strong enough to avoid super weak passwords. (which I believe is what this badguy is doing)

Also, please make sure to use a unique password with a mix of letters and numbers. 

If you run into any issues, just hit us up on our support site at https://support.klei.com and we'll be happy to help you out. 

  • Like 11
  • Thanks 1
  • Health 4
Link to comment
Share on other sites

Thank you for taking care of this and letting us know!

My friend that's no longer active here asked me if I knew what was up with a password reset request they received. Now I can let them know.

  • Health 1
Link to comment
Share on other sites

how should i opt-out the klei account? at least want to delete klei forum account but there's no option for get out of here.

if this reset are for anti spambot purpose, hope to give some choice to users long time not active on Klei's game and forum.

(as far as i've known, keep saving not-activated customer account info on server more then 5 years or reject on dismiss account and force it to maintaining is illegal in most of OECD countries)

also there's no explanation of this event to user email.. considering send one more mail to customer's not shock or nervous about email.

Thx.

Edited by 1337bignose
Link to comment
Share on other sites

I was about to ask if there was a data breach, haven't been here in years and thought it was out of the blue, good to know there is no major incident

  • Like 1
Link to comment
Share on other sites

same here. made the account close to a decade ago and never did anything with it, didnt even remember i had it. cant find way to delete it either, which is sth i always do to my old accounts. havent even not-starved in over 8 years...

Link to comment
Share on other sites

As others have mentioned above, the process in which this was done was in a manner not becoming of a great company. For future reference, when requesting a password reset, the email needs a more detailed explanation giving the reason for the request. Because in this day and age of sp(c)am mail that inboxes are inundated with on a daily basis can seriously be overlooked and deleted due to suspicion, especially to those, like myself and the ones mentioned above, who have not been to the forums in a sufficient amount of time to have forgotten they had an account. An out of the blue "For security reasons, the administrator of Klei Entertainment Forums has required you to reset your password." email is very suspicious and most will delete it.

  • Like 2
Link to comment
Share on other sites

I haven't been here for years. Sorry for that! :D 

Anyways, just wanted to say that because of the password reset I noticed that I really missed being able to activate any multi factor authentication methods. Please add the option to do so. It makes it feel safer. Thanks!

Link to comment
Share on other sites

i was worried something big happened and came here to find this, but i'm glad it was a minor case. unfortunatly i agree that the way the email is written may make people wary of it and i dont expect everyone to come here and see whats going on like i did.

all in all thank you for looking out for us

  • Like 1
Link to comment
Share on other sites

Personally I was wondering if you were checking account info against something like Have I Been Pwned, since not everyone was getting the emails. I examined the sender address very closely and it sure looked legit, but I was still suspicious that it could have been spoofed, so instead I opened up the "forgot your password?" form and had it send me a reset email from there. (It came from the exact same email address, but I wasn't sure, and years of internet safety training taught me not to open links in emails that asked me to input or reset my password if I didn't request them.)

  • Like 1
Link to comment
Share on other sites

Ah, I was wondering what was going on. The email looked very suspicious due to how short and vague it was. Had it been anything else I would have just deleted it and moved on, but a Klei forum account seemed like a weird thing for a phishing attempt so I came to investigate.

Link to comment
Share on other sites

Yeah, I'm sorry it was such a pain for you all. 

Unfortunately I wasn't aware the forum was going to automatically send out the emails, I was going to send those out separately. In the 11 years we have operated these forums, this is the first time we had to reset passwords. 

I certainly would have sent a more clear message out. Sorry for the scare. 

  • Like 7
  • Thanks 1
Link to comment
Share on other sites

2 hours ago, Duck986 said:

I suppose they were reset only for "pure" accounts (created using an email)? Because I used Steam to register a Klei account, and I don't see any changes.

I didn't reset all passwords. And if you login with steam the forums won't have a password for you to reset. (Usually)

  • Thanks 2
Link to comment
Share on other sites

I have never received a legit email like that and thought for sure it was a phishing attempt. The link was also http instead of https which set off alarm bells for me.

But now I'm curious and maybe we can figure this out. My mail requires a hardware token to log into and I get alerts for every login on my phone. I have not seen any suspicious activity on my mail or on any other accounts my mail is linked to except for these forums (which doesn't mean much because not everyone informs their users when stuff like this happens).

However that's still a hell of a coincidence for all of this to happen here, with multiple users of these forums affected. I'm not 100% sure but I think my old password was a generated one and I used a vault to log in. I'll continue to check on my end for any weak points but I suggest people at klei take another close look at their security.

Link to comment
Share on other sites

14 minutes ago, isam2k said:

I have never received a legit email like that and thought for sure it was a phishing attempt. The link was also http instead of https which set off alarm bells for me.

But now I'm curious and maybe we can figure this out. My mail requires a hardware token to log into and I get alerts for every login on my phone. I have not seen any suspicious activity on my mail or on any other accounts my mail is linked to except for these forums (which doesn't mean much because not everyone informs their users when stuff like this happens).

However that's still a hell of a coincidence for all of this to happen here, with multiple users of these forums affected. I'm not 100% sure but I think my old password was a generated one and I used a vault to log in. I'll continue to check on my end for any weak points but I suggest people at klei take another close look at their security.

I reset passwords across the board, not just accounts with suspicious activity. Basically, I hit the nuke button a bit too early. 

Normally, I think most of us are used to getting an email after the situation has fully been investigated. Generally, so they can avoid having to make a mess if they don't need too. At the time, I thought it was better to be safe than sorry. 

This definitely inconvenienced some people and I am sorry for that, but it was done to minimize any sort of damage. 

It's actually not abnormal to reset passwords for various reasons and it's a generally good thing to do anyway - however, the email that went out freaked a lot of people out (for obvious reasons). And as noted previously, I was unaware the forum was going to do that. I am going to be sending out a ticket to Invision about that. 

  • Like 3
  • Big Ups 1
Link to comment
Share on other sites

Quote

I reset passwords across the board, not just accounts with suspicious activity.

 

I completely misread what you've written and I thought my account was among the spammers. Sorry for that.

Edited by isam2k
  • Big Ups 1
Link to comment
Share on other sites

sorry to be a party pooper, but so is there a way to delete my data? been lookin for a while and havent been successful. dont starve was great for the semester that i wasted, but thinking about it mostly makes me sad these days, so i'd like to finally end that chapter for me

ps: great forum function btw, remembered this whole ash comment eventhough i closed the browser, navigated away and almost a week later it's still here.

  • Sad Dupe 1
Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
 Share

×
×
  • Create New...