Twitch Reports Security Breach

HardOCP News

[H] News
Joined
Dec 31, 1969
Messages
0
Just so you know, if you have a Twitch account, you will need to update your password the next time you try to log into your account. :(

We are writing to let you know that there may have been unauthorized access to some Twitch user account information. For your protection, we have expired passwords and stream keys and have disconnected accounts from Twitter and YouTube. As a result, you will be prompted to create a new password the next time you attempt to log into your Twitch account.
 
Meanwhile, they indefinitely lock out users for TOS violations. That seems OK until your shit got hacked and account locked because of someone else streaming copyrighted content on your account.
Recourse? None. "Zero tolerance" per twitch.
 
i didnt even get a notification. i had to google for their twatter account where a link to their blog post as twatted. that's some garbage communication.
 
Why does Twitch even need security? It has nothing of value.
 
Ugh what a pain. As i stream from multiple devices that is a ton of reconfiguration with them killing not only passwords but stream keys.
 
Horrible new password requirements. I had to look up how they were calculating this crap.

Stupidly enough, "theydonttellyouwhatconstitutesagoodpassword" is still a bad password according to them because it's made up of 100% real words. No brute force attack is ever going to break that, and nobody is going to guess it. But a random group of eight characters, "A4v&y1;p" is fine. Just as implausible for a person to guess, but much easier for a computer to brute force. But it's impossible to remember.

I know some people will say, "use a password manager" but I don't really care about my twitch account. It has no important information in it. It doesn't need to be crazy secure.
 
Good to know it wasn't just my account that prompted for a passowrd change.
 
According to Reddit, some people's email notification contained this part, which wasn't present in my email message.
While we store passwords in a cryptographically protected form, we believe it’s possible that your password could have been captured in clear text by malicious code when you logged into our site on March 3rd.

Probably only those affected got that particular message. But it's kind of scary to think that now these hackers don't just steal data from the system, but they are able to install their own malicious tool to capture password as they come in.:eek:
 
Back
Top