Full Tilt Account Hacked

wachinpntdry

wachinpntdry

Visionary
Silver Level
Joined
Feb 20, 2007
Total posts
591
Chips
0
btw....glad to hear you got your money back...very rare occurrance indeed
 
ckingriches

ckingriches

Lucky Multiple League MVP
Silver Level
Joined
Jul 27, 2009
Total posts
2,315
Awards
9
Chips
1
Well, just to play devil's advoquate here, how does kmixer know that FTP didn't have a security breach of their own that resulted in his (and possibly all of ours) login and/or personal information being stolen and/or otherwise compromised?
 
buckster436

buckster436

Cardschat Hall of Famer - RIP Buck
Silver Level
Joined
Mar 25, 2005
Total posts
15,125
Awards
2
Chips
0
I agree with all of you that FT went the extra mile here to get my funds back to me.

I am also glad that this little experience has made everyone more aware of their password and security situations. We take these for granted all the time until. something like this happens.

I for you will be making sure my money is as secure as can be onine.

Buck that is good advice if I can ever get up to 150 I will get it out of there. How does that play into your BR strategy though? Do you consider the money that you took off to still be in play? Or do you just continue to play at levels that are inclusive of the 150 bankroll? This may need it's own new topic ;)
dont really have a BR strategy, when i get up to around say, 150. ill withdraw 100. of it, i mostly play Guaranteed MTT`s with a buyin of between 5 to 30 dollars,, its worked out ok for me, last month at bodog i went into a $12+1 MTT, came in 2nd. so that bought me up to about $ 490., withdrew the 400 the next day and left the 90 there, i dont play cash games so i dont need to much $$ at any site,, been doin it for 4 years like that, im really glad for you getting your money back,,gl,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,, buck:)
 
NineLions

NineLions

Advanced beginner
Silver Level
Joined
Sep 20, 2006
Total posts
4,979
Chips
0
glad your getting your money back kmixer,, this is why i have Never keep no more than 100. to 150. bucks at any site, when i get above that i withdraw


Yeah, def food for thought. Makes participating in a redeposit bonus much easier since you've already taken the money out, and if I know the money came from/is set aside as bankroll, then I can treat it as bankroll even if it's sitting in my own bank account ...
 
NineLions

NineLions

Advanced beginner
Silver Level
Joined
Sep 20, 2006
Total posts
4,979
Chips
0
They could have discovered the guy who did it had more than one account and still had enough cash for them to recover his loss.

That would seem logical, though pretty stupid on the guy's part.

I am glad to have the money back. Thy know I am a losing player and will lose it to them anyway. :D


Well, maybe it's good customer service on their part then. But either way, we're happy for ya.
 
Debi

Debi

Forum Admin
Administrator
Joined
Oct 13, 2006
Total posts
74,733
Awards
20
Chips
1,357
There are a lot of people who travel and play from multiple locations. Like me. This year alone I have played from ireland, Georgia, England, Nevada, and you can add Kansas and California before the year ends. I am probably missing some places too. I play in airports sometimes when I have layovers. And now I hear you can actually access the internet on a lot of domestic flights.

They can't just block your account every time it is logged into from a place other than your home. :eek:
 
BuggyX

BuggyX

Rock Star
Silver Level
Joined
Nov 16, 2008
Total posts
163
Chips
0
Good hint with the Additional Authentication, thanks hillbilly, damn hackers!
 
kmixer

kmixer

Legend
Silver Level
Joined
Jul 11, 2008
Total posts
2,936
Chips
0
Buck congrats on the 2nd place win. Nice cash!
 
wachinpntdry

wachinpntdry

Visionary
Silver Level
Joined
Feb 20, 2007
Total posts
591
Chips
0
.....They can't just block your account every time it is logged into from a place other than your home........

why not......

make it an optional thing.... players could choose whether or not to have the added protection

for people who play from many locations, they could either go through some kind of authentication process, ........
or choose to exclude their acct from foriegn log-in authentication if they think it's too much of a hassle (but they'd then be accepting the poss of losing $ if they were hacked)

the overwhelming majority of players play from same location (home)....or same 2 locations (work and home) all, or nearly all the time.....
logic follows that having a foreign log-in authentication process in place would prevent the overwhelming majority of these types of "joy rides" and theft attempts from happening in the first place

the new 3 card authentication thing should help stop this kind of thing for those that choose to use it (at least until some hacker figures a way around it).... add in foriegn log-in blocking option and it would be even better
 
ihtennis

ihtennis

Rock Star
Silver Level
Joined
May 23, 2009
Total posts
233
Chips
0
u can cancel the transfer and you can also check your transfer history and see where it went. Your password must have been easy to figure out, is it the same as ur username or something?
 
TPC

TPC

Legend
Silver Level
Joined
Nov 5, 2008
Total posts
3,766
Chips
0
why not......

make it an optional thing.... players could choose whether or not to have the added protection

for people who play from many locations, they could either go through some kind of authentication process, ........
or choose to exclude their acct from foriegn log-in authentication if they think it's too much of a hassle (but they'd then be accepting the poss of losing $ if they were hacked)

the overwhelming majority of players play from same location (home)....or same 2 locations (work and home) all, or nearly all the time.....
logic follows that having a foreign log-in authentication process in place would prevent the overwhelming majority of these types of "joy rides" and theft attempts from happening in the first place

the new 3 card authentication thing should help stop this kind of thing for those that choose to use it (at least until some hacker figures a way around it).... add in foriegn log-in blocking option and it would be even better


I wouldn't say the majority of people play from work or home only. I travel quite a bit and play all over the place, just like Dakota. If you are the only one that uses your computer auto save the passwords and use the tree card pin. Hackers use key press recorders to gain a lot of the info they use to hack. So if you have your passwords auto saved and use the three card pin, it will be extremely hard to get hacked.
 
kmixer

kmixer

Legend
Silver Level
Joined
Jul 11, 2008
Total posts
2,936
Chips
0
I think making some option to have a cookie that would be plaed on PCs that you authorize is a good idea. Just be sure that cookie never gets copied off your PC and onto the hackers.
 
OzExorcist

OzExorcist

Broomcorn's uncle
Bronze Level
Joined
Aug 6, 2007
Total posts
8,586
Awards
1
Chips
1
There are a lot of people who travel and play from multiple locations. Like me. This year alone I have played from Ireland, Georgia, England, Nevada, and you can add Kansas and California before the year ends. I am probably missing some places too. I play in airports sometimes when I have layovers. And now I hear you can actually access the internet on a lot of domestic flights.

They can't just block your account every time it is logged into from a place other than your home. :eek:

^ this.

The Team Full Tilt pros would be the first ones to complain :p
 
kidkvno1

kidkvno1

Sarah's Pet
Bronze Level
Joined
Aug 20, 2008
Total posts
16,281
Awards
4
Chips
50
^^^This is the best piece of advice and you should seriously consider this kmixer.

As for someone taking your money for a "joy ride" as it was put, I would have to disagree, I think these players knew eachother and were all in on it or just one player with multiple accounts and a couple computers IMO.
Could have been time to consolidate the accounts into the ThorstenBuchler account.
If this was what has really happened then it would look more like legitimate plays and therefore would not set off any red flags.
Thanks shinedown.45, i am glad you see it my way.:cool:

I guess nobody ever loses their money in a casino. :eek:
Yeah they do, but it is easier to nail them on CCD, or the black domes you see in the casino..

Yeah, def food for thought. Makes participating in a redeposit bonus much easier since you've already taken the money out, and if I know the money came from/is set aside as bankroll, then I can treat it as bankroll even if it's sitting in my own bank account ...
+1
I some what like that idea....

There are a lot of people who travel and play from multiple locations. Like me. This year alone I have played from Ireland, Georgia, England, Nevada, and you can add Kansas and California before the year ends. I am probably missing some places too. I play in airports sometimes when I have layovers. And now I hear you can actually access the internet on a lot of domestic flights.

They can't just block your account every time it is logged into from a place other than your home. :eek:

^ this.

The Team Full Tilt pros would be the first ones to complain :p
LOL :p:p


Passwords, that you should be using should look like this....
K3a9U23auW5
^^^^^^ hard to crack
1720-Rose
^^^^^^ easy to crack.
And yes i know....
Also redo you password once a month..
 
Deco

Deco

Legend
Silver Level
Joined
May 7, 2009
Total posts
2,544
Chips
0
Last Year I had my roll robbed from me.

I logged into my gmail account from an internet cafe.
They keylogged or the browser saved my password (the browser was in a forign language so the pop-ups it came up could have been for password remembrance.

After getting into my gmail account they had access to all my passwords (as so many sites including this one send you your full username and password).
I was silly enough to enter my DOB and FTP username into the forum I vacated.

They didn't get through to FTP as I kept a different password for it.
However they emailed Moneybookers support with my username and security question answers (facebook reveals all) and moneybookers allowed them to change the address and bank account were they withdrew $550.

Moneybookers refused to give me the address or bankaccount details until I had emailed identity documents using me comprimised email which of course I was unprepared to do.

Eventually after I risked identity theft by emailing them the documents they took back the $400 left of my money.





Expensive Lesson learnt.
Keep a casual passsword/email and a financial password/email.
Don't use dodgy internet cafes that have browsers in a different language.
Don't keep cash in your moneybookers account for longer than 24hours.
 
regd87

regd87

Rock Star
Silver Level
Joined
Jan 12, 2008
Total posts
345
Chips
0
Wow, glad to hear that you've gotten the money back. However please keep us updated if they tell you how they were able to recover the funds because now I'm just purely interested.

I wanted to add however that if FTP wanted to they could simply ban the IP from logging onto FTP.
 
A

asmartone

Rising Star
Bronze Level
Joined
Aug 23, 2009
Total posts
6
Chips
0
Can they somehow connect your MAC address with your account ? (if you play from a Laptop for example)
 
kmixer

kmixer

Legend
Silver Level
Joined
Jul 11, 2008
Total posts
2,936
Chips
0
Wow, glad to hear that you've gotten the money back. However please keep us updated if they tell you how they were able to recover the funds because now I'm just purely interested.


I wanted to add however that if FTP wanted to they could simply ban the IP from logging onto FTP.

They never told me how they recovered the funds.

Can they somehow connect your MAC address with your account ? (if you play from a Laptop for example)

That's an ok idea. They also use key vobs for security which I think is awesome. Too bad they charge way too many FT points for them.
 
kmixer

kmixer

Legend
Silver Level
Joined
Jul 11, 2008
Total posts
2,936
Chips
0
I think they should make it optional. I also think this is something that you should be able to toggle in some sort of security setting. Locked down to my home computer when i am playing at home with the ability to unlock it if I know I will be playing elsewhere. At least it will protect me most of the time.

why not......

make it an optional thing.... players could choose whether or not to have the added protection

for people who play from many locations, they could either go through some kind of authentication process, ........
or choose to exclude their acct from foriegn log-in authentication if they think it's too much of a hassle (but they'd then be accepting the poss of losing $ if they were hacked)

the overwhelming majority of players play from same location (home)....or same 2 locations (work and home) all, or nearly all the time.....
logic follows that having a foreign log-in authentication process in place would prevent the overwhelming majority of these types of "joy rides" and theft attempts from happening in the first place

the new 3 card authentication thing should help stop this kind of thing for those that choose to use it (at least until some hacker figures a way around it).... add in foriegn log-in blocking option and it would be even better
 
pdutty

pdutty

Rock Star
Silver Level
Joined
May 4, 2008
Total posts
137
Chips
0
Sadly in these cases generally you never get your $$ back. The latest FTP update added a PIN feature that I urge everyone to take advantage of. It makes keylogging hacks less likely to succeed. Most likely your hacker gained access to your ftp email account and had the password reset allowing them access.

The PIN is enabled under Security > Additional Authentication

It looks like this:
View attachment 22943

WOW This is nice, I haven't seen this yet. I would surely create a PIN for myself.. Thanks for the info.
 
S

skullstomp

Rising Star
Bronze Level
Joined
Mar 24, 2009
Total posts
16
Chips
0
great to hear your getting the money back, thought for sure you wouldnt!
 
Related Full Tilt Reviews: English - Dutch - German - Spanish - Portuguese - FT Casino - Full Tilt Poker Mobile
Top