Data Leak

If you are having problems with the forum or have any questions regarding anything on the forum post them here.
Post Reply
paulsw2
Past 250!
Posts: 258
Joined: Sun Dec 12, 2010 11:40 pm
Trainz Version: TRS22
Trainz Build: 123801
Author KUID: 234086

Data Leak

Post by paulsw2 »

Just noticed an alert on my iPad notifying me that, "due to a data leak" my password on British Trainz is compromised and should be changed. I have changed it, but wondered if anyone else has had this notification or there has been a data leak from this website? Just thought I'd ask!

Paul
User avatar
Marky7890
Site Admin
Posts: 1471
Joined: Sun Dec 12, 2010 1:57 pm
Trainz Version: TRS2019
Trainz Build: 90945
Author KUID: 179051
Location: Near Penryn, Cornwall
Contact:

Re: Data Leak

Post by Marky7890 »

This is the first I've heard about it.

Mark
clam1952
Forum Veteran
Posts: 1528
Joined: Sun Dec 12, 2010 3:16 pm
Trainz Version: TRS22
Trainz Build: 116243
Author KUID: 425700
Location: Crewe, Cheshire, UK

Re: Data Leak

Post by clam1952 »

No sign of anything wrong at my end, no popups on Windows.
Cheers

Malc

Member of Trainz Carriage and Wagon Works
http://www.trainz-carriage-wagon-works.com/
paulsw2
Past 250!
Posts: 258
Joined: Sun Dec 12, 2010 11:40 pm
Trainz Version: TRS22
Trainz Build: 123801
Author KUID: 234086

Re: Data Leak

Post by paulsw2 »

Thanks for response, don't want to unnecessarily alarm you Mark. As I explained elsewhere to Malc, the background is that there is a 'passwords' menu in iPad settings which features a 'Security Recommendations' setting with a 'Detect Compromised Passwords' toggle (which I think is default enabled). This issues a warning that, "british-trainz.co.uk - this password has appeared in a data leak, which puts this account at high risk of compromise.' Apple’s password monitoring, “matches passwords stored in the user’s Password AutoFill keychain against a continuously updated and curated list of passwords known to have been exposed in leaks.” If users have this functionality switched on, password monitor will always be seeking matches between the passwords you use and those that are leaked online and alert you when there’s a problem.

I don't think British Trainz has been compromised here, I suspect the password I was using had been leaked elsewhere as I had (foolishly) reused it across several sites. However, it might be worth members who access this site on their iPad or iPhone checking to see if they have a notification.

Apologies for the false alarm!

Paul
Post Reply