Message from @fuckthapolice

Discord ID: 393432379714437120


2017-12-21 15:51:54 UTC  

Emailed them

2017-12-21 15:52:16 UTC  

yay im not in there

2017-12-21 15:52:34 UTC  

oh shit lmao looks like my uni got pwned

2017-12-21 15:53:02 UTC  

Your uni uses goybest?

2017-12-21 15:53:15 UTC  

its unrelated

2017-12-21 15:53:36 UTC  

came up when i was searching for my email on epin haxor . net

2017-12-21 15:54:28 UTC  

people really need to step up their password game

2017-12-21 15:54:41 UTC  

i wonder how many of those are their email acc pw at the same time

2017-12-21 15:55:00 UTC  

my email acc has double auth and a completely random pw

2017-12-21 15:55:22 UTC  

last line of defence against russian/chink haxorz

2017-12-21 15:55:59 UTC  

i remember someone in this discord talking about how discord was unsecure af like 5 months ago

2017-12-21 15:57:19 UTC  

in what way?

2017-12-21 15:57:21 UTC  

was it only for goibest app?

2017-12-21 15:58:13 UTC  

there is a guy with Points: 677

2017-12-21 15:58:13 UTC  

dam

2017-12-21 15:59:16 UTC  

apparently that's how people got pwned, problem with the app since May

2017-12-21 15:59:29 UTC  

@Lefteris specifically, the API the app uses, not the app itself (though i think the details of the insecurities in the API where obtained mainly from decompiling the app?)

2017-12-21 15:59:30 UTC  

so this is ongoing or what

2017-12-21 15:59:37 UTC  

im not sure whether to go into panic mode

2017-12-21 15:59:40 UTC  

yeah they haven't fixed it

2017-12-21 15:59:48 UTC  

nuke china already

2017-12-21 16:00:16 UTC  

if you use the password you used on gearbest for any other purposes then your accounts were already at risk and you only have yourselves to blame tbh lads

2017-12-21 16:00:28 UTC  

s-stop

2017-12-21 16:00:40 UTC  

also what about your adress and full name

2017-12-21 16:00:44 UTC  

or do you fake that too

2017-12-21 16:01:06 UTC  

true

2017-12-21 16:01:19 UTC  

the bottom line is

2017-12-21 16:01:21 UTC  

nuke china

2017-12-21 16:01:24 UTC  

true

2017-12-21 16:01:26 UTC  

@Lefteris you can get that amount pretty easily if you get into the shill program

2017-12-21 16:01:29 UTC  

which is easy to do

2017-12-21 16:02:37 UTC  
2017-12-21 16:02:55 UTC  

yeah that was the first place i checked

2017-12-21 16:04:17 UTC  

one of my emails was compromised from services i used 12 (!) years ago.

2017-12-21 16:04:30 UTC  

it sounds like this full pastebin is floating around on private hacker discords

2017-12-21 16:04:42 UTC  

I think haveibeenpwned would need that list to update their site

2017-12-21 16:05:01 UTC  

so I would take it with a grain of salt and still change password/2-auth everything

2017-12-21 16:05:03 UTC  

yeah probably

2017-12-21 16:05:16 UTC  

im fairly safe anyways

2017-12-21 16:05:25 UTC  

all my shit is 2authed already

2017-12-21 16:05:35 UTC  

now if someone was to steal my phone