Jump to content

The puush webserver was compromised and it made the user download an update (r94) that contained a malware, there's already an update that does fix that (r100).

More info on their twitter account or in this page they created:

http://puushstatus.tumblr.com/

https://twitter.com/puushme

Looks like all the passwords stored locally (saved in firefox/chrome, mail clients etc) could be compromised and they strongly suggest to change them.

I'm quite mad to be honest, I've already set up a 2 step-verification process when available but now I'll have to change ALL of my passwords and this grinds my gears quite a bit. I always used a couple of alphanumeric password, they all share the same base plus the name of the site I use it on, like for example: 78shyu3Linus, 78shyu3Facebook, etc. I use another alphanumeric set for my google account, a different one for my microsoft account and yet another one for steam, so I'll end up getting rid of 4 different sets of passwords >_>

Remembering a new password will be a pain in the ass, so I'll take the chance to ask, what kind of software could I use to keep track of my passwords? Lastpass? Anything else? Suggestions on a new password? Should I keep the alphanumeric style or just go for a simple long one (length over complexity)?

Link to comment
https://linustechtips.com/topic/338141-psa-puush-has-been-compromised/
Share on other sites

Link to post
Share on other sites

The best place to keep passwords is in your head if you can do it.  My ex-fiancee has a memory that is awesome and can do that.  As for me well I use sticky notes on pc and also create text files which I upload to email or various cloud storage services.  In regards to your password for your bank account I can recommend one for you so you can let me have all your money.

Too many ****ing games!  Back log 4 life! :S

Link to post
Share on other sites

The best place to keep passwords is in your head if you can do it.  My ex-fiancee has a memory that is awesome and can do that.  As for me well I use sticky notes on pc and also create text files which I upload to email or various cloud storage services.  In regards to your password for your bank account I can recommend one for you so you can let me have all your money.

 

That's what I did so far and I just kept a paper copy of the major ones. I guess I have a good memory I even remember the complete data of my credit card, I'm just a lil pissed and in "fuck that" mood, I'll probably end up memorizing them again in a few days, but still :I

 

@DeViLzzz

Link to post
Share on other sites

I think I saw someone report something about this company on a previous day but never heard of them before this.  I guess you can post screenshots really quick.  Eh ok.  So this site is popular?  Yes I enjoy sharing screenshots of games but a company that is just all about screenshots?  Please tell me they make money other ways.

Too many ****ing games!  Back log 4 life! :S

Link to post
Share on other sites

I think I saw someone report something about this company on a previous day but never heard of them before this. I guess you can post screenshots really quick. Eh ok. So this site is popular? Yes I enjoy sharing screenshots of games but a company that is just all about screenshots? Please tell me they make money other ways.

They make money offering premium accounts that gives you other features and more space on their servers. It was covered by a LTT video as well:

http://youtu.be/u92w6XlW9TU

Link to post
Share on other sites

i'm.....not going to bother changing my passwords. maybe it's a bad idea but anything that could be 'stolen' from me is very easy to recover.

credit/debit info being stolen? dispute the charges and request new cards, deactivate the old ones.

game passwords stolen? contact the company and provide the information necessary to recover your account (event history, purchase history, creation date & original email)

only thing i would worry about is my google account password being jacked (even then doesn't google encrypt saved passwords?), or my social security number being stolen (don't store that on pc..)

 

plus i'm 99% sure google has a suspicious login type prevention system.

 

tl;dr i'm not really worried.

at least puush has been very transparent about the issue and even freely suggested the idea to completely remove it from your computer if you feel violated/betrayed.

Abigail: Intel Core i7-4790k @ 4.5GHz 1.170v / EVGA Nvidia GeForce GTX 980 Ti Classified  / ASRock Z97 Extreme6 / Corsair H110i GT / 4x4Gb G.Skill Ares 1866MHz @ CAS9 / Samsung 840 EVO 250Gb SSD / Seagate Barracuda 1TB 7200RPM / NZXT H440 Blue / EVGA SuperNOVA 750w G2

Peripherals: BenQ XL2411z 24" 144hz 1080p / ASUS VG248QE 24" 144Hz 1080p / Corsair Vengeance K70 RGB / Logitech G502 / Sennheiser HD650 / Schiit Audio Modi 2 / Magni 2 / Blue Yeti Blackout
Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×