LOGIN  .  SIGNUP   .  SUPPORT 
HOME / MESSAGE BOARDS / GENERAL DISCUSSIONS

General Discussions

Signup   Message Boards Home   Newest Posts   My Favorite Boards   My Threads
Page 1 of 1
Signup or Login to Post
NOTICE: Heartbleed and Cheat Happens
 
PWizard  posted on Apr 09, 2014 9:21:22 PM - Report post

Founder
Send a message to PWizard
FOUNDER
I just wanted to let everyone know that CHEAT HAPPENS servers are NOT AFFECTED by the recently announced Heart Bleed exploit. Our site does not support and actively blocks SSL traffic and so there is no way to utilize the exploit. Our servers also do not run any version of openSSL.

Please note that if you visited OTHER SITES which were vulnerable and you use the same login or password here on CH, then it's possible that your account could become compromised. We recommend changing your password once you have made sure that all of the sites you visit have been patched to fix the Heart Bleed bug. As always, we monitor very closely all account activity on our site and will quickly notice if any accounts have been compromised and the credentials spread to the Internet. If this becomes the case, the accounts will be deactivated until we can confirm the activity with the original account holder.

Please post here if you have any questions.

 
Wrythe1985  posted on Apr 09, 2014 11:17:30 PM - Report post

Current rank: 1.5 Stars. Next Rank at 500 Posts.
Send a message to Wrythe1985
ELITE
What encryption scheme do you use (out of curiosity because OpenSSL is by far the most popular and used to be thought of as pretty secure).

And now for the nuts and bolts. I hate to be asinine, but do you outsource any user data such as billing info or use a third-party payment processor? If so, which vendor do you use and what does your minimum security standard agreement with them look like as far as their encryption scheme for any of the data from CHU users they may store? If you do use an outside database vendor, do they use OpenSSL to store/validate data and have they implemented the fix if they do?

 
Wrythe1985  posted on Apr 09, 2014 11:23:08 PM - Report post

Current rank: 1.5 Stars. Next Rank at 500 Posts.
Send a message to Wrythe1985
ELITE
Oh, I forgot to ask this. If, on the off chance a CHU account is compromised, will you send the user an email or is it up to the account holder to contact you? If so, is there an email address we should use and what sort of documentation will you require? I've been an unlimited member for a fairly decent number of years and I know for a fact I do not have the receipt anywhere and if the account is compromised am I assured that my secret questions and answers are not compromised as well if those are required to prove ownership? Basically, short of having the purchase receipt, how is one to prove ownership? IP addresses, MAC addresses, hardware ID numbers, stuff like that?
 
ServiusTheBear  posted on Apr 10, 2014 3:42:55 AM - Report post

Current rank: 4 Stars. Next Rank at 10.000 Posts.
Send a message to ServiusTheBear
AUTHOR
This is new to me. Aint even had anything from any of the sites I use about this issue.

As to ownership. IP Addresses can not be really used as proof. Since not all ISP give users have a dedicated IP. Many users on that ISP can use the same IP. Mac address, I would not even give that to anyone except my ISP. If you have bought Unlimited or Lifer Membership. The recipt is the one thing that should be taken combined with the email you use for the account. As Proof. Generally am hoping it keeps records of pass emails used with the account so it can show what changes have happened.

[Edited by Toki, 4/10/2014 3:48:21 AM]

 
PWizard  posted on Apr 10, 2014 6:22:26 AM - Report post

Founder
Send a message to PWizard
FOUNDER
We do not employ any type of SSL encryption on our site. Our payments are processed by Authorize.net and PayPal.com. You can contact them directly for the status of their websites, but it's my understanding that they were not affected.

If we end up disabling any accounts, the original paid receipt or transaction ID may be necessary to prove original account holder details.

 
Wrythe1985  posted on Apr 10, 2014 1:20:18 PM - Report post

Current rank: 1.5 Stars. Next Rank at 500 Posts.
Send a message to Wrythe1985
ELITE
Ok, cool. Thank you.
Page 1 of 1
  Post Reply
 
All times are (GMT -06:00) Central Time (US & Canada). Current time is 11:32:49 AM
Cheat Happens Premium
 
* Access PC trainers and exclusive content
* Updated game trainers and cheats daily
* Get notified when new cheats are added
* Request which games get new trainers
* Priority support with any problem
Message Board Moderators
Neo7
Neo7
Latiosmaster47Latiosm.
forty-twoforty-two
HonestGamerHonestG.
dstatesdstates
Important Board Topics
Trending Topics