The online racing simulator
More leaked passwords (from unknown source)
Hello LFS racers,

We have become aware of a user, based in Turkey, who has obtained control of quite a few LFS licenses and is selling them online.

We are aware of approximately 50 licenses that were compromised. In each case the user has logged in using the web password and usually changed the email to one of his own emails. We have written to the affected account owners and we have a few more to investigate. In each case we have reverted the email to the previous email and set completely random passwords.

Yesterday I improved the security of accounts and will continue to work on it.

Before yesterday afternoon, it was possible to change any aspect of your account after logging in. Email, web password and game password could be updated instantly.

Changes I have made so far:

- You now get a notification email if anyone logs in using your account.
- WEBpassword can only be changed via an email (like the "Forgot your password" system).
- Email address cannot be changed at all. This is temporary (see below for plans).
- You receive a notification email if GAMEpassword is changed. I intend to duplicate the system for changing WEBpassword.

So now it should be impossible for you to lose control of your account. Although if your password is known to this 'hacker' then they can obviously log in to your account and change various settings. At least you will receive an email if they do log in.

We do not know how the user has obtained passwords. We believe he may acquire the GAMEpassword somehow. If your WEBpassword is the same as your GAMEpassword then at that point he already can log in to your account. You should never use a GAMEpassword that is the same as your WEBpassword and it is extremely important not to use the same password as any other accounts you have that are important to you.

When writing to the people who had their accounts stolen, we have been asking them if they have any clue how their information could have got out, if they used LFS credentials anywhere or installed software that could be relevant. Unfortunately we get very few replies, which has also been the case in the past.

I could not find any evidence of "brute force" attacks (using thousands of attempts to guess passwords).

Even if it may sound repetitive:

- Please, DO NOT use a GAMEpassword that is the same as your WEBpassword
- Please, DO NOT use passwords that are the same as the passwords on any other accounts you care about


Current plans for changing email:

I think two methods must be implemented.

1) If you have access to the old email to receive a code there, it could be updated in a similar way to WEBpassword - via an email sent to your old email address.
2) If you do not have access to the old email but can log in using your password, I intend to send an email to the old email anyway (to warn the user, in case the logged-in user is really a hacker trying to gain control of your account) and after 1 week you will be allowed to change your email using the current system (that is temporarily disabled).
Might want to check the affected emails against https://haveibeenpwned.com/

Maybe someone is just trying email/pw combos from a data breach on some other site
Wouldn't two factor authentication stop a signficant portion of these incidents from reoccuring?
There are red in my email. Did I get too many trojans?
even 2-3 of my emails
I have ideas about this topic, can we connect on Discord?
: suicdff
Thanks!
TOTP would in fact be a good solution.
There are good amount of games that use it in fact.
Turkey is something else man... something always happens to them Omg omg omg
DİKKATLİ BAKIN BURAYA
Quote from Scawen :Hello LFS racers...

Ne yazıkki benim arkadaşlarımda böyle şeyleri konuşuyor sistem açığı bulunmuş girip oynuyolar diye.Bir diğer sürümüde bekleriz
Quote from Viperakecske :Turkey is something else man... something always happens to them Omg omg omg

This was a bit of a harsh message..
Quote from mcmustang :TOTP would in fact be a good solution.
There are good amount of games that use it in fact.

Not only games, but most communities and/or forums on the internet nowadays offers an option to enable TOTP. I was going to suggest this, but this is more of a task for Victor to tackle.
Quote from sensizim02 :The person who most likely stole and sold the account: Ali Ozcan...

Ali, my friend, said that he bought a group account recently. I don't think he would commit a crime like stealing.
Quote from suicdff_ :Ali, my friend, said that he bought a group account recently. I don't think he...

I can't blame anyone, but if he writes and posts this article, he creates doubts about himself.
We save our money, we get our accounts with our labor, it is stolen, LFS should take action against this.
Only way to lose your account if you give out your password , which u did. So its on u and dont expect LFS to take action because YOU messed up
Hello LFS family! I would like to clarify something.
I currently have around 100,000 LFS.net accounts in my possession, but I am not the one who stole them.
A foreign friend of mine from a hacking group sent them to me because I’m interested in LFS.
However, I realize my mistake and would like the authorities to contact me via Discord.
My Discord address is: pilotsxak
Quote from Viperakecske :Only way to lose your account if you give out your password , which u did. So...

This guy is right, even if your friend wants to use your account, don't give it to him. Your mistake is costing us too.
There is a difference between the hours and the message he sent
He has other things to do right now, he is not an idle man, he will take it
Quote from AL.OZCAN :Hello LFS family! I would like to clarify something...

lets say you did not steal them, selling them is still illegal. what type of an excuse is this bro 😭
Quote from AL.OZCAN :Hello LFS family! I would like to clarify something.
I currently have around 100,000 LFS.net accounts in my possession, but I am not the one who stole them.

I believe you have a lot of passwords for accounts.

We will not contact you on discord.

If you really want to help, please contact us via this link: https://www.lfs.net/contact

We need to know, from you or anyone else who knows, how these passwords were obtained.
Please can you stop using these accounts immediately?
There is no development on LFS while we have to continue dealing with this.
Quote from AL.OZCAN :Hello LFS family! I would like to clarify something...

also instead of selling those accounts, you could maybe try report your "hacker" friends? or no you thought this was a good idea to make profit or what Looney Face -> palm
This thread is closed

More leaked passwords (from unknown source)
(123 posts, closed, started )
FGED GREDG RDFGDR GSFDG