Important announcement from the AF team

Latest news in the Atari world

Moderator: Moderator Team

User avatar
Voice of AF
Atari Forever
Posts: 5
Joined: Thu May 08, 2025 7:37 am
Contact:

Important announcement from the AF team

Post by Voice of AF »

Recently the forum had a security breach. At first it was believed to have been contained, but we have now learned that whoever did this, may have downloaded a copy of our user database.

The database contains your username, your email address and a hash of your password.

While the version of the forum software (phpBB 3.3.13 at the time of the breach) that we use has a very strong encryption to try to protect the data, it is likely only a matter of time until the encryption is broken.

We have already upgraded the forum software (phpBB) to the latest version. And we intend on undertaking whatever steps we need to, to prevent this from happening again.

A compromised password for a member was a factor in the attack on the forum.

We strongly recommend that all our members, that haven't changed their password over the past month, to immediately change their password on Atari-Forum and also on any other sites where you may have used the same password. Further, we recommend that you use a strong password and that you don't reuse the same password for multiple sites or services.

We also recommend that you keep the email address that you have provided to us up to date.

Why did this happen?

Atari-forum started out small, and was small for a long time. During this time, things have been managed very informally and relaxed. While we will do our outmost to keep that atmosphere going forward, this shows that we need to take security much more seriously going forward.

We sincerely apologise for any inconvenience this might cause you, and for letting this happen to us.

Atari-Forum team
Questions? Post in the thread or contact the Atari-Forum team directly.
Atari-Forum contact form.
Chris23235
Captain Atari
Captain Atari
Posts: 336
Joined: Thu Aug 07, 2014 6:52 pm

Re: Important announcement from the AF team

Post by Chris23235 »

I just did the password reset. Maybe it would be a good idea to send everybody a password reset link.
User avatar
logronoide
Captain Atari
Captain Atari
Posts: 159
Joined: Fri Dec 23, 2022 7:10 pm
Location: Madrid
Contact:

Re: Important announcement from the AF team

Post by logronoide »

What version of phpBB was compromised? Was it version 3.0 or earlier?
User avatar
Voice of AF
Atari Forever
Posts: 5
Joined: Thu May 08, 2025 7:37 am
Contact:

Re: Important announcement from the AF team

Post by Voice of AF »

Chris23235 wrote: Fri May 09, 2025 10:25 pm I just did the password reset. Maybe it would be a good idea to send everybody a password reset link.
Normal users cannot do any harm to the forum. This announcement is to protect you.
logronoide wrote: Fri May 09, 2025 11:11 pm What version of phpBB was compromised? Was it version 3.0 or earlier?
No. 3.3.13.
Questions? Post in the thread or contact the Atari-Forum team directly.
Atari-Forum contact form.
User avatar
logronoide
Captain Atari
Captain Atari
Posts: 159
Joined: Fri Dec 23, 2022 7:10 pm
Location: Madrid
Contact:

Re: Important announcement from the AF team

Post by logronoide »

Great, good to know bcrypt is taking care of passwords
darwinmac
Captain Atari
Captain Atari
Posts: 450
Joined: Sat Aug 06, 2011 2:49 pm
Location: San Jose, USA

Re: Important announcement from the AF team

Post by darwinmac »

Thanks for letting us know. Unfortunately, security breaches happen. That’s especially true for hobbyist sites like this one where people have real jobs. Your transparency is appreciated.

Thankfully, I’ve been using a password manager even before setting up an account here in 2011. Therefore, I didn’t use my password anywhere else. However, I changed it out of caution.

Bob C
DanyPPC
Fuji Shaped Bastard
Fuji Shaped Bastard
Posts: 2085
Joined: Tue Feb 21, 2017 7:02 am

Re: Important announcement from the AF team

Post by DanyPPC »

Thanks for the advice
czietz
Hardware Guru
Hardware Guru
Posts: 2823
Joined: Tue May 24, 2016 6:47 pm

Re: Important announcement from the AF team

Post by czietz »

Thank you for letting us know.

One followup question, though: When did this happen? I had to reset my password on March 20th, when the forum had - for whatever reason - locked me out. Can you say whether the database breach happened before or after that?
User avatar
Voice of AF
Atari Forever
Posts: 5
Joined: Thu May 08, 2025 7:37 am
Contact:

Re: Important announcement from the AF team

Post by Voice of AF »

czietz wrote: Sat May 10, 2025 6:52 am Thank you for letting us know.

One followup question, though: When did this happen? I had to reset my password on March 20th, when the forum had - for whatever reason - locked me out. Can you say whether the database breach happened before or after that?
That was the date this happened, yes.
Questions? Post in the thread or contact the Atari-Forum team directly.
Atari-Forum contact form.
User avatar
aktiv8
Atari God
Atari God
Posts: 1504
Joined: Tue Mar 04, 2003 4:31 pm
Location: Cardiff, South Wales

Re: Important announcement from the AF team

Post by aktiv8 »

Thanks for the update. I note this warning is being passed around on social media (well X at least), so hopefully be a good position.

Been a long while since I've dabbled with the admin side of the board software, but can a "enforce password change" be activated?
>>> Trust me, I'm a Research Chemist.... <<<
CiH
Atari God
Atari God
Posts: 1266
Joined: Wed Feb 11, 2004 4:34 pm
Location: Middle Earth (Npton) UK
Contact:

Re: Important announcement from the AF team

Post by CiH »

Noted and updated, thank you.
"Where teh feck is teh Hash key on this Mac?!"
User avatar
rondc
Obsessive compulsive Atari behavior
Obsessive compulsive Atari behavior
Posts: 131
Joined: Tue Apr 30, 2019 9:59 pm
Location: Spain
Contact:

Re: Important announcement from the AF team

Post by rondc »

Noted, updated, Thanks very much.
User avatar
logronoide
Captain Atari
Captain Atari
Posts: 159
Joined: Fri Dec 23, 2022 7:10 pm
Location: Madrid
Contact:

Re: Important announcement from the AF team

Post by logronoide »

logronoide wrote: Fri May 09, 2025 11:19 pm Great, good to know bcrypt is taking care of passwords
I was half-asleep when I read your message and totally missed saying the most important thing: thank you, and you have all my support.

#hugeops
stormy
Atari God
Atari God
Posts: 1771
Joined: Tue Jan 26, 2016 12:39 pm

Re: Important announcement from the AF team

Post by stormy »

Please someone let me know how to change my password... I can't find it anywhere! Perhaps the board admins should force a 'change password' for all members.
simonsunnyboy
Forum Administrator
Forum Administrator
Posts: 5836
Joined: Wed Oct 23, 2002 4:36 pm
Location: Friedrichshafen, Germany
Contact:

Re: Important announcement from the AF team

Post by simonsunnyboy »

stormy wrote: Sat May 10, 2025 5:38 pm Please someone let me know how to change my password... I can't find it anywhere! Perhaps the board admins should force a 'change password' for all members.
Try this section in your profile:
https://www.atari-forum.com/ucp.php?i=u ... eg_details

CLick on your username top right and select "User control panel" for various settings including changing passwords and account details.
Simon Sunnyboy/Paradize - http://paradize.atari.org/

Stay cool, stay Atari!

1x2600jr, 1x1040STFm, 1x1040STE 4MB+TOS2.06+SatanDisk, 1xF030 14MB+FPU+NetUS-Bee
stormy
Atari God
Atari God
Posts: 1771
Joined: Tue Jan 26, 2016 12:39 pm

Re: Important announcement from the AF team

Post by stormy »

Thanks Simon, done it now.
User avatar
1024MAK
Atari Super Hero
Atari Super Hero
Posts: 732
Joined: Sat Aug 01, 2009 2:58 am
Location: Further outside Bristol than spiny… Sunny Somerset, UK
Contact:

Re: Important announcement from the AF team

Post by 1024MAK »

How to change your password

The following assumes you are using a PC or other device with a large screen.

On the top right, click your username (under the search box). It should produce a drop down menu. Click on “User Control Panel”.

On the new page, click the “Profile” tab.

On the next page, on the left hand menu, click on “Edit account settings”.

You shown now be on the page that displays your user name, your email address and empty boxes for your new password, conformation of your new password and your current password.

Please check that the email address is correct, then enter your new password, confirm your new password and enter your current password. Then click the Submit button.

Mark
Falcon, Atari 520ST, 520STFM, 1040STE, Mega, TT and more PC's than I care to count and an assortment of 8 bit micros (nearly forgot the Psion's).
Visit the Atari-Forum Wiki. Lots of technical info at DrCoolZic Atari ST Site :D
User avatar
viking272
Atari Super Hero
Atari Super Hero
Posts: 960
Joined: Mon Oct 13, 2008 12:50 pm
Location: west of London, UK

Re: Important announcement from the AF team

Post by viking272 »

simonsunnyboy wrote: Sat May 10, 2025 5:49 pm
stormy wrote: Sat May 10, 2025 5:38 pm Please someone let me know how to change my password... I can't find it anywhere! Perhaps the board admins should force a 'change password' for all members.
Try this section in your profile:
https://www.atari-forum.com/ucp.php?i=u ... eg_details

CLick on your username top right and select "User control panel" for various settings including changing passwords and account details.
Thanks, I couldn't see it for looking.

Thanks for being transparent on the issues, I've updated my password.
PeterS
Atari God
Atari God
Posts: 1014
Joined: Fri Nov 09, 2007 1:53 pm
Location: England, GB

Re: Important announcement from the AF team

Post by PeterS »

I couldn't find it using android.

Now updated.

Thanks for the info.
User avatar
ube
Obsessive compulsive Atari behavior
Obsessive compulsive Atari behavior
Posts: 134
Joined: Mon Jun 10, 2002 10:37 pm
Contact:

Re: Important announcement from the AF team

Post by ube »

1. Send an email to all users.
2. Reset all passwords older than now().
3. Read up on GDPR to check if you'll have to contact someone to disclose this information. (As I remember it, this board was started by a Swedish person, so maybe cert-se and/or PTS and/or IMY in that case).
4. Profit.
Atari STE w/ MicroCosmosex | Atari Falcon w/ CT60e| Falcon 030 | ubeswitch mk1 | ubeswitch mk2 | ubeswitch mk4 | ubeswitch mk5 | ubeswitch mk6 | ubeswitch mk6 v1.1b | ubeswitch mk7
User avatar
viking272
Atari Super Hero
Atari Super Hero
Posts: 960
Joined: Mon Oct 13, 2008 12:50 pm
Location: west of London, UK

Re: Important announcement from the AF team

Post by viking272 »

The main issue is that money or other data are stolen from users, as the email address, name, date of birth (if noted) and password are used elsewhere, say in their banking apps.

So users need to be aware where they used the password elsewhere and change that too.
User avatar
Greenious
Hardware Guru
Hardware Guru
Posts: 1942
Joined: Sat Apr 24, 2004 5:39 pm
Location: Sweden

Re: Important announcement from the AF team

Post by Greenious »

Well, we only require a forum name and email to join. There are fields for birthday and links to other sites you may fill in if you want, but most haven't.

So we don't have much, if any, in the way of sensitive data.

As for GDPR, I'll forward that to Dal, the server is located in the UK, so it's their rules that would apply I think.

But I would like to know how we could profit from this...
Check out the hardware preservation project: The hardware cartridge preservation project
And my old guide thread with various information: Greenious ATARI ST UPGRADE GUIDE'S & TIP'S
mlynn1974
Atari Super Hero
Atari Super Hero
Posts: 765
Joined: Mon Mar 03, 2008 10:33 pm
Contact:

Re: Important announcement from the AF team

Post by mlynn1974 »

In older versions of PHPBB the password was stored as an MD5 hash. The actual password could not be retrieved. Even with brute force or rainbow tables the best they could do is find a string that generates the same hash which might not be the same password. I think most people on here are tech savvy enough to use different passwords for different accounts and know that it is good practice to regularly change passwords. MD5 has been considered "weak" and broken since the early 2010s.

I don't know about PHPBB 3.x or how it stores passwords.
Thanks to the AF Team for updating us and keeping us safe.
Still got, still working: Atari 4Mb STe, MegaST 2, 520STFM (x2), 2.5Mb STF, Atari 2600JR, Flashback 8 Gold.
Hardware: PC720B, Cumana CSA 354, Ultimate Ripper, Discovery Cartridge, Blitz Turbo, Synchro Express II (US and UK Versions).
User avatar
troed
Atari God
Atari God
Posts: 1797
Joined: Mon Apr 30, 2012 6:20 pm
Location: Sweden

Re: Important announcement from the AF team

Post by troed »

I think most people on here are tech savvy enough to use different passwords for different accounts
Many people here probably know they should - but I can guarantee you that they don't

/cybersec professional
elliot
Captain Atari
Captain Atari
Posts: 396
Joined: Tue Mar 17, 2009 2:00 pm

Re: Important announcement from the AF team

Post by elliot »

that haven't changed their password over the past month
Yeah not done this in 16 years 8O , just done.
Falcon with CT60 in rack mountable case. Two STFMs, one upgraded lots. My original STE from when I was a teen with Switchable TOS, 1.44Mb drive, 4MB RAM, Supra Hard Drive and very very yellow case. Mega STE with (currently none working) Crazy Dots 2. Atari 2600 and a Jag. And a mountain of commercial software and lots of hardware addons.
Post Reply

Return to “News & Announcements”