"And please, while I recognise that this is frustrating, let me remind everyone not to take this out on the smods or even the administration. Contrary to popular belief we have little control and say over security/servers/more complex developmental matters and additions/logs etc. We work with and deal with lots of front end forum and community matters and that's pretty much what we're limited to. :s "
So who does? I got a very short email from toribash three days ago. I've waited for more information, but I'm not seeing anything else about the breach. That's not acceptable.
:s
http://blog.eyewire.org/security-dat...on-2016-02-23/ <- this is how you handle a security breach. Not "Change your password, everywhere. We're looking into it, we promise. We hope nothing bad is happening!" Details about whether the passwords were encrypted, whether the encryption used salted hashes, what information might be compromised other than generic "privacy", etc. This isn't information that you keep to yourselves to further your "investigation," you can't keep it to yourself to catch the bad guy (if the police are requesting that you not release it, say so!) this is vital information for your user's own security. I gather passwords "may or may not" be compromised, but emails? Names? Birthdays? All of these things can be used to steal a person's identity and ruin their lives using other breached databases, and the only defense is rapid response from the individuals affected. Worst yet, game websites are often places kids congregate, kids that may not even know that something as innocuous as their birthday can be used to <i>destroy</i> them years later. Criminal negligence is a thing.
If you can pass this on to the people that have the information behind this breach, that would be appreciated. I really love your game, I think it should be on school computers for what it does to teach analytical thinking about motion, but if you don't understand how serious people's personally identifiable information is, I seriously question whether you should be collecting it.