Forum Discussion

MarkJFine's avatar
MarkJFine
Professor
7 years ago

Hackers are using people's email addresses

Received three emails in succession from a peer-to-peer energy transfer site: account notification, account verification, and a welcome email all in a matter of seconds of each other.

 

I quickly went to the site and reset whatever password was set to make sure it doesn't get used, and so they can't just recreate a new account with the same email.

 

Upon re-logging in after establishing the new password, they asked to resend an email verification, which I guess they never initially received - and that's a good thing.

 

Hackers have been targeting automated signup routines in websites for a long time, but this is the first time I've actually caught one using my email address and a phony password in the process.

 

This is truly scary stuff.

  • GabeU's avatar
    GabeU
    Distinguished Professor IV

    I had my email hacked a few years back.  It was my own fault, as I was using a weak password.  Now, even though I change the password on a regular basis and to something that would probably take the greatest password cracker in the world weeks to figure out, if not months, my email address is still spoofed, and sometimes back to me.  

     

    There's nothing I can do about it now, and the only option I really have if I ever want to truly not deal with it anymore is create a new email address.  And, in reality, I should.  It just stinks as I've had my email address since 1998.  :(  

    • maratsade's avatar
      maratsade
      Distinguished Professor IV

      "something that would probably take the greatest password cracker in the world weeks to figure out, if not months, "

       

      What if they use brute force?  I was told once that there are tools that can crack any password. 

      • GabeU's avatar
        GabeU
        Distinguished Professor IV

        maratsade wrote:

        "something that would probably take the greatest password cracker in the world weeks to figure out, if not months, "

         

        What if they use brute force?  I was told once that there are tools that can crack any password. 


        They probably can, but the longer and more complex it is the harder it is.  Mine's presently 16 characters and uses upper case and lower case letters, numbers and symbols in no discernible order.  

         

        Granted, my statement about how long it would take is an exaggeration, but my password is a bit more complex than "Password12345".  :p