Chat
RecommendedRecommended

RafaelRapidos

6 Likes
Newbie
Chat
Follow
6
RafaelRapidos
@Hellishjam, thank you for sharing the information about leak. I do understand your frustration with the situation and I hope I will be able to ease your mind a bit. About the database: The database remained open to the public for 23 days. During that time, an outside actor could have potentially taken a copy of the database. It has not been verified that the database has been leaked other than to the white hat hacker who reported it to GrowDiaries. About the passwords: The passwords were not in plaintext, and while MD5 is not recommended to be used, retrieving the passwords from MD5 hashes is still not that easy. If you'd like to get technical, read more about decrypting MD5 hashes here: https://stackoverflow.com/questions/1240852/is-it-possible-to-decrypt-md5-hashes. I recommend using a password management tool to create unique and strong passwords for all websites. Also, a couple of weeks ago while I was trying to log in to GD, I received a notification that my password had expired and I needed to create a new one. Usually when a website upgrades the password hashing algorithm on the database, users will need to create a new password the next time they log in. I don't know if this has happened to all users or only those found on the leaked database or to just me. Did anybody else get the same notification? About the usernames and IP addresses: Usernames are usually logged with IP addresses on all websites, unless stated otherwise. That is how website administrators are able to ban misbehaving users effectively, so it is not possible for the banned user to create a new account from the same computer. You should not grow cannabis and run an online diary about it in a country where it is illegal to grow cannabis. If you still decide to do so, security is at your responsibility. I will not give you any advice on that, but people on the internet always say "use a VPN to remain private on the internet".