The world is currently online!


Welcome to Emps-World!

Register now to gain access to all of our forum features. Once registered and logged in, you will be able to create topics, post replies, send private messages, manage your profile, chat with other players in the shoutbox and much more. Once you sign in, this message will disappear.



Pages: 1
0 Members and 1 Guest are viewing this topic.

Offline Crusher123

  • *
  • 240
  • Liked: 428 times
  • +0/-0
    • View Profile
Do you save our passwords in plain text or what?
« on: September 22, 2016, 10:06:55 pm »
Recently got email from "no-reply@emps-world.net" (not sure if that legit email or not) but its saying that "there has been a potential security breach for a small amount of accounts on our side." I thought that passwords are hashed and can't really get cracked but idk.

Offline Zeepleeuw

  • *
  • 598
  • Liked: 251 times
  • +0/-0
  • Master Assassin
    • View Profile
Master of the order of the Doge.

www.youtube.com/watch?v=wavh47RpLz4&

player moderator since 22/12/2015
game moderator since 11/03/2016

Offline Thomy

  • *
  • 3555
  • Liked: 3326 times
  • +5/-0
    • View Profile
Re: Do you save our passwords in plain text or what?
« Reply #2 on: September 22, 2016, 10:35:16 pm »
Passwords are safely encrypted with bcrypt (https://en.wikipedia.org/wiki/Bcrypt). The reason why 'only' some accounts were hacked, is because of perfect security in our database. The attackers were only able to steal some passwords by injecting malicious software at the code where you login. This part of the code still contains your password (that is safely sent and encrypted over HTTPS). Protecting yourself from attacks where the attacker has access to the actual code is actually pretty much impossible. The security breaches have been fixed though.
The following users liked this post: Icedrags, Cjkinsey6, Reporter007
Pages: 1