What we collect!

 

Stamporama Discussion Board Logo
For People Who Love To Talk About Stamps
Discussion - Member to Member Sales - Research Center
Stamporama Discussion Board Logo
For People Who Love To Talk About Stamps
Discussion - Member to Member Sales - Research Center
Stamporama Discussion Board Logo
For People Who Love To Talk About Stamps



What we collect!
What we collect!


Club Business & Announcements/Tech Advice : The Stamporama website has been hacked. PLEASE READ NOW.

 

Author
Postings
auldstampguy
Members Picture


Tim
Collector/Webmaster

03 Oct 2015
09:11:47am
Hi Everyone,

We discovered over night that the Stamporama website has been hacked and data from the membership database has been taken. All of our emails, password and phone numbers were posted on a website called skymem.com on Sept 21. Arno found this after investigating Alyn's post re his password having been changed by someone. I have requested that the information be taken down from the skymem.com website, but it could well be posted there again. We have no knowledge about the stolen information being used apart from the fact that it was posted on the skymem site.

I believe that I have found where they got in and have closed the security hole. I apologize sincerely that the security hole existed and that I hadn't caught it before.

It is very important that you go onto the Members Area and change your password. Even more important than that, if you use the same password that you use on Stamporama on other websites, especially if you use the same email address on those other websites, you should go and change your password on those websites. This is especially important if you use your stamporama password for any banking websites etc.

To change your password on Stamporama, login and go to the Members Area and use the "Change Password" function, which is right underneath the Edit Profile function. Please let me know if you need help.

I have sent this message out to all active members, except those who have unsubscribed from the bulk emails.

Regards ... Tim.
Like 
4 Members
like this post.
Login to Like.

mncancels.org
musicman
Members Picture


APS #213005

03 Oct 2015
09:35:36am
re: The Stamporama website has been hacked. PLEASE READ NOW.

Thank you, Tim -

I'm sure I speak for others in saying we appreciate your prompt response in this.

...password changed!







Randy

Like 
3 Members
like this post.
Login to Like.
Stampaholic
Members Picture


03 Oct 2015
09:42:20am
re: The Stamporama website has been hacked. PLEASE READ NOW.

me2. thanks.Thumbs Up

Like
Login to Like
this post

" I have a burning love for stamps. Lord A'mighty ,feel my temperature risin'! "
Tregeor
Members Picture


03 Oct 2015
09:55:36am
re: The Stamporama website has been hacked. PLEASE READ NOW.

Makes you wonder what these idiots get out of doing stuff like that. They ought to get a job! Angry
Anyway, my p/w now changed. Thanks for the update.

Like
Login to Like
this post
bobstew617
Members Picture


03 Oct 2015
09:58:42am
re: The Stamporama website has been hacked. PLEASE READ NOW.

pw changed --thanks, Tim.

I am concerned that members who do not read the DB will not know of this. Is there any way to do a mass email?

BOB

Like
Login to Like
this post
auldstampguy
Members Picture


Tim
Collector/Webmaster

03 Oct 2015
10:03:13am
re: The Stamporama website has been hacked. PLEASE READ NOW.

Hi Bob,
There is an email going out to all active members right now (except to the members who have unsubscribed to the bulk emails). I have also posted the message on the SOR Facebook page.

Tim

Like
Login to Like
this post

mncancels.org
Rhinelander
Members Picture


Support the Hobby -- Join the American Philatelic Society

03 Oct 2015
10:05:35am
re: The Stamporama website has been hacked. PLEASE READ NOW.

If there had been any widespread abuse, I believe we would have become aware of this issue much earlier. Great. Tim, that you have figured out and fixed the vulnerability.

What are you going to do about such lowlifes? We could consider requiring mandatory password changes every couple of months, but that is probably not very popular with most users. So, I believe that falls into the realm of the internet being a scary place and to always be guarded, i.e., to use different passwords for different places and to change them once in a while. Of course, me too is guilty of not doing so at all times.

Like
Login to Like
this post
samliu

03 Oct 2015
10:19:35am
re: The Stamporama website has been hacked. PLEASE READ NOW.

Maybe we need to consider to encrypt password.

Nobody should be able to decrypt it, even users can only reset, not recover.

Sam

Like
Login to Like
this post
auldstampguy
Members Picture


Tim
Collector/Webmaster

03 Oct 2015
10:21:53am
re: The Stamporama website has been hacked. PLEASE READ NOW.

Sam,
You and I had the same thought. I'm looking into encrypting the passwords now.

Regards ... Tim.

Like
Login to Like
this post

mncancels.org
cocollectibles

03 Oct 2015
11:05:49am
re: The Stamporama website has been hacked. PLEASE READ NOW.

"Makes you wonder what these idiots get out of doing stuff like that."



If anything, practice for the big money hack jobs later. Scumbags, nonetheless.
This a good reason to update passwords on a regular basis and to use different ones on different sites.

Peter
Like
Login to Like
this post

"TO ERR IS HUMAN; TO FORGIVE, CANINE."
biggeorge
Members Picture


03 Oct 2015
11:11:26am
re: The Stamporama website has been hacked. PLEASE READ NOW.

PW changed! Thanks for the warning!

biggeorge

Like
Login to Like
this post
ikeyPikey
Members Picture


03 Oct 2015
11:18:28am
re: The Stamporama website has been hacked. PLEASE READ NOW.

For all those sites that want a password but cannot hurt me - for example, a newspaper that requires a log-in but does not have my credit card - I use a single password.

At last count, there were dozens & dozens of such sites using that non-critical, non-financial, pretty-much-zero-impact password.

The very idea of making-up 50-100 different, secure passwords - for each credit card, retailer, etc - and changing them strikes me as ridiculous.

I've tried password-generating software but, frankly, did not like the results, as I have to save the whole password in a convenient electronic place, and having a document on my desktop with a long list of URLs and passwords does not appeal to me.

Without giving away your family jewels, how do you manage your flock of passwords?

Cheers,

/s/ ikeyPikey

Like 
1 Member
likes this post.
Login to Like.

"I collect stamps today precisely the way I collected stamps when I was ten years old."
KZCinWI

03 Oct 2015
11:25:00am
re: The Stamporama website has been hacked. PLEASE READ NOW.

Changed mine!
Thanks for the warning!

Like
Login to Like
this post
SeawayMa

03 Oct 2015
11:36:35am
re: The Stamporama website has been hacked. PLEASE READ NOW.

Thanks for keeping us all on our toes, Tim. Password(s) changed. We get too lax with changing them periodically.

Like
Login to Like
this post
cocollectibles

03 Oct 2015
11:54:00am
re: The Stamporama website has been hacked. PLEASE READ NOW.

"The very idea of making-up 50-100 different, secure passwords - for each credit card, retailer, etc - and changing them strikes me as ridiculous.
"



Famous last words.


Like
Login to Like
this post

"TO ERR IS HUMAN; TO FORGIVE, CANINE."
sponthetrona2
Members Picture


Keep Postal systems alive, buy stamps and mail often

03 Oct 2015
12:01:21pm
re: The Stamporama website has been hacked. PLEASE READ NOW.

Back from current trip....Thanks have changed PW

Like
Login to Like
this post
sheepshanks
Members Picture


03 Oct 2015
12:05:29pm
re: The Stamporama website has been hacked. PLEASE READ NOW.

Changed mine, thanks for the warning Tim.
If anyone is using Firefox, all your saved passwords are available to see. Go to Options in the menu (3 bars) icon, top right of screen. Click on security, passwords and view passwords.
Personally I keep mine in a book that is then hidden within other papers but mostly memory works well after a few entries.

Like
Login to Like
this post
TheStampCellar
Members Picture


03 Oct 2015
12:09:23pm
re: The Stamporama website has been hacked. PLEASE READ NOW.

Password changed - thanks for the info.

James

Like
Login to Like
this post

blog.thestampcellar.com/
pedroguy
Members Picture


03 Oct 2015
12:11:02pm
re: The Stamporama website has been hacked. PLEASE READ NOW.

Thanks Tim............I'm changed

Like
Login to Like
this post
keesindy
Members Picture


03 Oct 2015
12:21:24pm
re: The Stamporama website has been hacked. PLEASE READ NOW.

Changed mine, too!

Like
Login to Like
this post

"I no longer collect, but will never abandon the hobby"
2010ccg

03 Oct 2015
12:32:58pm
re: The Stamporama website has been hacked. PLEASE READ NOW.

Done!

Like
Login to Like
this post
grorod
Members Picture


03 Oct 2015
12:44:29pm
re: The Stamporama website has been hacked. PLEASE READ NOW.

Thank you for Tim
all changed now!!!

Like
Login to Like
this post

do not have one
philb
Members Picture


03 Oct 2015
12:48:58pm
re: The Stamporama website has been hacked. PLEASE READ NOW.

Done thanks !

Like
Login to Like
this post

"If a man would be anything, he must be himself."
Madbaker
Members Picture


03 Oct 2015
01:04:38pm
re: The Stamporama website has been hacked. PLEASE READ NOW.

Changed. Thanks for the email!

Mark

Like
Login to Like
this post
DavidG
Members Picture


APS member since 2004

03 Oct 2015
01:34:44pm
re: The Stamporama website has been hacked. PLEASE READ NOW.

Passord changed... thank-you for your diligence!

David

Like
Login to Like
this post

"President, The Society for Costa Rica Collectors"
khj
Members Picture


03 Oct 2015
01:52:48pm
re: The Stamporama website has been hacked. PLEASE READ NOW.

Thanks to SOR adminstrators for being open about this and addressing this so quickly!

I will add the following. I noticed an uptick in the number of spoofed emails from SoR members over the past 2 weeks. Oftentimes, the mailbox is actually correct but the domain name is different. The spoofing appears pretty convincing, otherwise, because they are using our full names rather than our username handles. I was concerned about this enough to contact at least one SoR member about this.

I think now I know why the uptick in the spoofed emails.

So please be advised to be extra careful to check the domain name in any emails you think you are receiving from SoR members. I'm not saying toss any emails from SOR members, but that you should check to make sure the domain name is the same as in the emails you received from them in the past.

Like
Login to Like
this post
Webpaper
Members Picture


03 Oct 2015
02:01:32pm
re: The Stamporama website has been hacked. PLEASE READ NOW.

Changed - thank you !!

Like
Login to Like
this post
Larryd
Members Picture


03 Oct 2015
02:03:31pm
re: The Stamporama website has been hacked. PLEASE READ NOW.

Like khj, I've also gotten e-mails that seemed to come from SOR members; however, unlike real messages these latest e-mails have been routed to my spam box rather than my inbox. I'm not sure how the Yahoo spam filters detect the difference, but I've made a note not to open any items in the spam box. The two I did open didn't appear to have any clickable links, but had nothing to do with stamps. I've also changed my password.

Like
Login to Like
this post

LPD4.blogspot.com
1973lindale

03 Oct 2015
02:26:13pm
re: The Stamporama website has been hacked. PLEASE READ NOW.

Thanks, Tim for catching this quickly and closing the entry hole the hackers accessed. Keep up the good work.

Got my p/w changed.

Like
Login to Like
this post
mbo1142
Members Picture


I thought I was wrong once, but I was mistaken.

03 Oct 2015
02:36:42pm
re: The Stamporama website has been hacked. PLEASE READ NOW.

Thanks, changed this one and 3 others that were minor.

Like 
1 Member
likes this post.
Login to Like.
         
(Page 1 of 3)

 

Author/Postings
Members Picture
auldstampguy

Tim
Collector/Webmaster
03 Oct 2015
09:11:47am

Hi Everyone,

We discovered over night that the Stamporama website has been hacked and data from the membership database has been taken. All of our emails, password and phone numbers were posted on a website called skymem.com on Sept 21. Arno found this after investigating Alyn's post re his password having been changed by someone. I have requested that the information be taken down from the skymem.com website, but it could well be posted there again. We have no knowledge about the stolen information being used apart from the fact that it was posted on the skymem site.

I believe that I have found where they got in and have closed the security hole. I apologize sincerely that the security hole existed and that I hadn't caught it before.

It is very important that you go onto the Members Area and change your password. Even more important than that, if you use the same password that you use on Stamporama on other websites, especially if you use the same email address on those other websites, you should go and change your password on those websites. This is especially important if you use your stamporama password for any banking websites etc.

To change your password on Stamporama, login and go to the Members Area and use the "Change Password" function, which is right underneath the Edit Profile function. Please let me know if you need help.

I have sent this message out to all active members, except those who have unsubscribed from the bulk emails.

Regards ... Tim.

Like 
4 Members
like this post.
Login to Like.

mncancels.org
Members Picture
musicman

APS #213005
03 Oct 2015
09:35:36am

re: The Stamporama website has been hacked. PLEASE READ NOW.

Thank you, Tim -

I'm sure I speak for others in saying we appreciate your prompt response in this.

...password changed!







Randy

Like 
3 Members
like this post.
Login to Like.
Members Picture
Stampaholic

03 Oct 2015
09:42:20am

re: The Stamporama website has been hacked. PLEASE READ NOW.

me2. thanks.Thumbs Up

Like
Login to Like
this post

" I have a burning love for stamps. Lord A'mighty ,feel my temperature risin'! "
Members Picture
Tregeor

03 Oct 2015
09:55:36am

re: The Stamporama website has been hacked. PLEASE READ NOW.

Makes you wonder what these idiots get out of doing stuff like that. They ought to get a job! Angry
Anyway, my p/w now changed. Thanks for the update.

Like
Login to Like
this post
Members Picture
bobstew617

03 Oct 2015
09:58:42am

re: The Stamporama website has been hacked. PLEASE READ NOW.

pw changed --thanks, Tim.

I am concerned that members who do not read the DB will not know of this. Is there any way to do a mass email?

BOB

Like
Login to Like
this post
Members Picture
auldstampguy

Tim
Collector/Webmaster
03 Oct 2015
10:03:13am

re: The Stamporama website has been hacked. PLEASE READ NOW.

Hi Bob,
There is an email going out to all active members right now (except to the members who have unsubscribed to the bulk emails). I have also posted the message on the SOR Facebook page.

Tim

Like
Login to Like
this post

mncancels.org
Members Picture
Rhinelander

Support the Hobby -- Join the American Philatelic Society
03 Oct 2015
10:05:35am

re: The Stamporama website has been hacked. PLEASE READ NOW.

If there had been any widespread abuse, I believe we would have become aware of this issue much earlier. Great. Tim, that you have figured out and fixed the vulnerability.

What are you going to do about such lowlifes? We could consider requiring mandatory password changes every couple of months, but that is probably not very popular with most users. So, I believe that falls into the realm of the internet being a scary place and to always be guarded, i.e., to use different passwords for different places and to change them once in a while. Of course, me too is guilty of not doing so at all times.

Like
Login to Like
this post
samliu

03 Oct 2015
10:19:35am

re: The Stamporama website has been hacked. PLEASE READ NOW.

Maybe we need to consider to encrypt password.

Nobody should be able to decrypt it, even users can only reset, not recover.

Sam

Like
Login to Like
this post
Members Picture
auldstampguy

Tim
Collector/Webmaster
03 Oct 2015
10:21:53am

re: The Stamporama website has been hacked. PLEASE READ NOW.

Sam,
You and I had the same thought. I'm looking into encrypting the passwords now.

Regards ... Tim.

Like
Login to Like
this post

mncancels.org
cocollectibles

03 Oct 2015
11:05:49am

re: The Stamporama website has been hacked. PLEASE READ NOW.

"Makes you wonder what these idiots get out of doing stuff like that."



If anything, practice for the big money hack jobs later. Scumbags, nonetheless.
This a good reason to update passwords on a regular basis and to use different ones on different sites.

Peter
Like
Login to Like
this post

"TO ERR IS HUMAN; TO FORGIVE, CANINE."
Members Picture
biggeorge

03 Oct 2015
11:11:26am

re: The Stamporama website has been hacked. PLEASE READ NOW.

PW changed! Thanks for the warning!

biggeorge

Like
Login to Like
this post
Members Picture
ikeyPikey

03 Oct 2015
11:18:28am

re: The Stamporama website has been hacked. PLEASE READ NOW.

For all those sites that want a password but cannot hurt me - for example, a newspaper that requires a log-in but does not have my credit card - I use a single password.

At last count, there were dozens & dozens of such sites using that non-critical, non-financial, pretty-much-zero-impact password.

The very idea of making-up 50-100 different, secure passwords - for each credit card, retailer, etc - and changing them strikes me as ridiculous.

I've tried password-generating software but, frankly, did not like the results, as I have to save the whole password in a convenient electronic place, and having a document on my desktop with a long list of URLs and passwords does not appeal to me.

Without giving away your family jewels, how do you manage your flock of passwords?

Cheers,

/s/ ikeyPikey

Like 
1 Member
likes this post.
Login to Like.

"I collect stamps today precisely the way I collected stamps when I was ten years old."
KZCinWI

03 Oct 2015
11:25:00am

re: The Stamporama website has been hacked. PLEASE READ NOW.

Changed mine!
Thanks for the warning!

Like
Login to Like
this post
SeawayMa

03 Oct 2015
11:36:35am

re: The Stamporama website has been hacked. PLEASE READ NOW.

Thanks for keeping us all on our toes, Tim. Password(s) changed. We get too lax with changing them periodically.

Like
Login to Like
this post
cocollectibles

03 Oct 2015
11:54:00am

re: The Stamporama website has been hacked. PLEASE READ NOW.

"The very idea of making-up 50-100 different, secure passwords - for each credit card, retailer, etc - and changing them strikes me as ridiculous.
"



Famous last words.


Like
Login to Like
this post

"TO ERR IS HUMAN; TO FORGIVE, CANINE."
Members Picture
sponthetrona2

Keep Postal systems alive, buy stamps and mail often
03 Oct 2015
12:01:21pm

re: The Stamporama website has been hacked. PLEASE READ NOW.

Back from current trip....Thanks have changed PW

Like
Login to Like
this post
Members Picture
sheepshanks

03 Oct 2015
12:05:29pm

re: The Stamporama website has been hacked. PLEASE READ NOW.

Changed mine, thanks for the warning Tim.
If anyone is using Firefox, all your saved passwords are available to see. Go to Options in the menu (3 bars) icon, top right of screen. Click on security, passwords and view passwords.
Personally I keep mine in a book that is then hidden within other papers but mostly memory works well after a few entries.

Like
Login to Like
this post
Members Picture
TheStampCellar

03 Oct 2015
12:09:23pm

re: The Stamporama website has been hacked. PLEASE READ NOW.

Password changed - thanks for the info.

James

Like
Login to Like
this post

blog.thestampcellar. ...
Members Picture
pedroguy

03 Oct 2015
12:11:02pm

re: The Stamporama website has been hacked. PLEASE READ NOW.

Thanks Tim............I'm changed

Like
Login to Like
this post
Members Picture
keesindy

03 Oct 2015
12:21:24pm

re: The Stamporama website has been hacked. PLEASE READ NOW.

Changed mine, too!

Like
Login to Like
this post

"I no longer collect, but will never abandon the hobby"
2010ccg

03 Oct 2015
12:32:58pm

re: The Stamporama website has been hacked. PLEASE READ NOW.

Done!

Like
Login to Like
this post
Members Picture
grorod

03 Oct 2015
12:44:29pm

re: The Stamporama website has been hacked. PLEASE READ NOW.

Thank you for Tim
all changed now!!!

Like
Login to Like
this post

do not have one
Members Picture
philb

03 Oct 2015
12:48:58pm

re: The Stamporama website has been hacked. PLEASE READ NOW.

Done thanks !

Like
Login to Like
this post

"If a man would be anything, he must be himself."
Members Picture
Madbaker

03 Oct 2015
01:04:38pm

re: The Stamporama website has been hacked. PLEASE READ NOW.

Changed. Thanks for the email!

Mark

Like
Login to Like
this post
Members Picture
DavidG

APS member since 2004
03 Oct 2015
01:34:44pm

re: The Stamporama website has been hacked. PLEASE READ NOW.

Passord changed... thank-you for your diligence!

David

Like
Login to Like
this post

"President, The Society for Costa Rica Collectors"
Members Picture
khj

03 Oct 2015
01:52:48pm

re: The Stamporama website has been hacked. PLEASE READ NOW.

Thanks to SOR adminstrators for being open about this and addressing this so quickly!

I will add the following. I noticed an uptick in the number of spoofed emails from SoR members over the past 2 weeks. Oftentimes, the mailbox is actually correct but the domain name is different. The spoofing appears pretty convincing, otherwise, because they are using our full names rather than our username handles. I was concerned about this enough to contact at least one SoR member about this.

I think now I know why the uptick in the spoofed emails.

So please be advised to be extra careful to check the domain name in any emails you think you are receiving from SoR members. I'm not saying toss any emails from SOR members, but that you should check to make sure the domain name is the same as in the emails you received from them in the past.

Like
Login to Like
this post
Members Picture
Webpaper

03 Oct 2015
02:01:32pm

re: The Stamporama website has been hacked. PLEASE READ NOW.

Changed - thank you !!

Like
Login to Like
this post
Members Picture
Larryd

03 Oct 2015
02:03:31pm

re: The Stamporama website has been hacked. PLEASE READ NOW.

Like khj, I've also gotten e-mails that seemed to come from SOR members; however, unlike real messages these latest e-mails have been routed to my spam box rather than my inbox. I'm not sure how the Yahoo spam filters detect the difference, but I've made a note not to open any items in the spam box. The two I did open didn't appear to have any clickable links, but had nothing to do with stamps. I've also changed my password.

Like
Login to Like
this post

LPD4.blogspot.com
1973lindale

03 Oct 2015
02:26:13pm

re: The Stamporama website has been hacked. PLEASE READ NOW.

Thanks, Tim for catching this quickly and closing the entry hole the hackers accessed. Keep up the good work.

Got my p/w changed.

Like
Login to Like
this post
Members Picture
mbo1142

I thought I was wrong once, but I was mistaken.
03 Oct 2015
02:36:42pm

re: The Stamporama website has been hacked. PLEASE READ NOW.

Thanks, changed this one and 3 others that were minor.

Like 
1 Member
likes this post.
Login to Like.
         
(Page 1 of 3)

Contact Webmaster | Visitors Online | Unsubscribe Emails | Facebook


User Agreement

Copyright © 2025 Stamporama.com