2022 our 25th year online!

Welcome to the Piano World Piano Forums
Over 3 million posts about pianos, digital pianos, and all types of keyboard instruments.
Over 100,000 members from around the world.
Join the World's Largest Community of Piano Lovers (it's free)
It's Fun to Play the Piano ... Please Pass It On!

SEARCH
Piano Forums & Piano World
(ad)
Who's Online Now
35 members (David B, AlkansBookcase, Bruce Sato, dh371, APianistHasNoName, BillS728, bcalvanese, 10 invisible), 1,199 guests, and 297 robots.
Key: Admin, Global Mod, Mod
Previous Thread
Next Thread
Print Thread
Hop To
Page 1 of 2 1 2
Joined: May 2007
Posts: 1,645
D
1000 Post Club Member
OP Offline
1000 Post Club Member
D
Joined: May 2007
Posts: 1,645
After years of relative safety on the internet, I finally got hacked.

I was working on a customer's Boston grand, when I got a call from a client saying, "Hey, Dave, you got hacked. You'd better get on it and change your password!" The problem was that my internet was down while I was between services that required an exterior hardware upgrade. Then I got another call, saying the same thing. Then another, and another.

According to the e-mail the hacker sent out to all of my contacts, I was in England and had lost my wallet. Could you please send me $1800?

It went on all day. My wife tried to change my password from her work, but was unable to: my ISP had been sold a couple of times since I first opened the account, and I couldn't even access that setting.

I finally got home, got on the phone with ATT tech support and eventually was able to change the password for that account. I also managed to close the Yahoo account that the hacker was using to siphon off a day's worth of incoming mail, 2 years worth of sent mail, and all of my e-mail contacts.

Sorry if anyone here got spammed. Don't forget to change passwords once in a while.

Last edited by Dave Stahl; 05/16/12 11:55 PM.

Promote Harmony in the Universe...Tune your piano!

Dave Stahl, RPT
Piano Technician's Guild
San Jose, CA
http://www.youtube.com/watch?v=JAniw3m7L2I
http://dstahlpiano.net
Joined: Sep 2006
Posts: 3,983
3000 Post Club Member
Offline
3000 Post Club Member
Joined: Sep 2006
Posts: 3,983
You were hacked?!!! Does that mean you didn't get the money I sent to you through PayPal to England???
What did you change your password to?

grin


I hope you have it all under control again now. thumb


JG
Joined: May 2007
Posts: 1,645
D
1000 Post Club Member
OP Offline
1000 Post Club Member
D
Joined: May 2007
Posts: 1,645
I have an offshore account set up in Nigeria. Thanks for the cash, Jurgen.


Promote Harmony in the Universe...Tune your piano!

Dave Stahl, RPT
Piano Technician's Guild
San Jose, CA
http://www.youtube.com/watch?v=JAniw3m7L2I
http://dstahlpiano.net
Joined: Nov 2009
Posts: 24,600
Yikes! 10000 Post Club Member
Offline
Yikes! 10000 Post Club Member
Joined: Nov 2009
Posts: 24,600
Originally Posted by Dave Stahl
....According to the e-mail the hacker sent out to all of my contacts, I was in England and had lost my wallet. Could you please send me $1800?....

Just about exactly the same thing happened yesterday with a friend of mine -- and I was one of the people who got contacted.

Here's what the e-mail said (eerily similar to yours):

Good Morning,

I'm writing this with tears in my eyes,but i really need your help at the moment,I came down here to Mallorca Spain for a short vacation,unfortunately i got mugged at the park of the hotel i staying ,everything i had on me was stolen including,cash,credit cards and cell phone....I've been to the embassy and the Police here but they're not helping issues at all,I need help to settle the bills and flying back home,I'll surely pay back as soon as we get back home.

Thanks
[friend's first name]



Immediately there were suspicious things about it, like the slightly-incorrect typing, which my friend wouldn't have done quite that way, even under stress, plus the capitalization of "Police" which I thought he never would have done at all. Still, if not for all the publicity about scams like this (including the warnings that have been posted by our members here from time to time), I might not have suspected enough, and even as it was, my first instant thought was that this was real. I replied, and asked if there was a phone number where I could speak to him directly. If the person did answer with a phone number, besides making sure that the person sounded like my actual friend I would have asked some things that only he would have known. But the next e-mail just said there wasn't a phone where he could be reached, and could I please immediately wire him $2500 via Western Union.

Yeah right. grin

I then did what I probably should have done right away: I called my friend's home phone number in New York, and was glad when he himself picked up the phone.

Hopefully and presumably none of your contacts got fooled to the point of sending money. I would like to think I wouldn't have, even if not for the publicity and warnings I'd seen. But I might have.

Joined: May 2007
Posts: 1,645
D
1000 Post Club Member
OP Offline
1000 Post Club Member
D
Joined: May 2007
Posts: 1,645
Mark,

I was truly grateful for the amount of phone calls I got from clients and friends. Most of them just wanted to let me know what was going on, but some of the people were really concerned and ready to send money!



Promote Harmony in the Universe...Tune your piano!

Dave Stahl, RPT
Piano Technician's Guild
San Jose, CA
http://www.youtube.com/watch?v=JAniw3m7L2I
http://dstahlpiano.net
Joined: Aug 2011
Posts: 184
M

Bronze Supporter until Jan 01 2013
Full Member
Offline

Bronze Supporter until Jan 01 2013
Full Member
M
Joined: Aug 2011
Posts: 184
Things like this cause the worst problems when people are in actual difficulty.

I could rant on this subject. But I'll summarize it as this: if you know a close family member is on vacation, and they contact you to say "HELP!!!! Call American Express's concierge service and help me find a hotel! I'll pay for it, I just need their help finding one. I'm in [this city] in [this developing country] where there's a huge international conference (which I never knew about before), every hotel is booked, no one speaks my language, the place is famous for corruption, and I've been awake for 3 days strait."
Do not, under any condition, reply "why don't you try Travelocity.com?"
It's a developing country, they don't use Travelocity, and the 2 hotels that are listed have been full for weeks and never bother to update their status. I tried that long ago.
For those that don't know, American Express's concierge service can work wonders and find hotels or rooms that otherwise don't exist. They are also very good at conveying the critical information before a cellphone battery dies.

Joined: Jul 2009
Posts: 543
500 Post Club Member
Offline
500 Post Club Member
Joined: Jul 2009
Posts: 543
Good reminder Dave. Recently our church email got hacked. The hacker sent out pornographic pictures to the entire congregation!!!! Come to find out, our password had not been changed in 10 years and was a very simple word to figure out.

Folks, as our tech guy instructs us at my school, your password needs to contain the following: a capital letter, a symbol and a number. Even though most of us use the same password for everything, it's really not a good idea. We're instructed to have separate passwords for school and home, so if one get's hacked, the other is not in jeopardy. Just a few things to think about.



Ryan G. Hassell
Hassell's Piano Tuning
Farmington, MO
www.hassellspianotuning.com
http://www.facebook.com/pages/Hassells-Piano-Tuning/163155880804
ryanhassell@hotmail.com
Joined: Mar 2008
Posts: 4,263
4000 Post Club Member
Offline
4000 Post Club Member
Joined: Mar 2008
Posts: 4,263

Type your password into the box at the top, then hit enter to check the strength.

http://www.passwordscan.com/

Joined: Jun 2010
Posts: 2,671
L
2000 Post Club Member
Offline
2000 Post Club Member
L
Joined: Jun 2010
Posts: 2,671
Originally Posted by Silverwood Pianos

Type your password into the box at the top, then hit enter to check the strength.

http://www.passwordscan.com/


If I were a sniffer/hacker/phisher, I would set up such a link to "test" password strength. No thanks, Dan!

edit: Think about it....a site performs a password strength test by associating the password you enter with your ip address. Don't do it!

Last edited by Loren D; 05/17/12 08:55 AM.

DiGiorgi Piano Service
http://www.digiorgipiano.com
Joined: Mar 2008
Posts: 4,263
4000 Post Club Member
Offline
4000 Post Club Member
Joined: Mar 2008
Posts: 4,263

Someone on the internet has to have your password so as to allow you into things. How paranoid does one have to be?

Testing a password strength does not indicate you are using that password.

Joined: Jun 2010
Posts: 2,671
L
2000 Post Club Member
Offline
2000 Post Club Member
L
Joined: Jun 2010
Posts: 2,671
No, but trying a tested pw would be a logical place to start. Not paranoid at all, but we ARE talking security and hacking here. And after all, tricking people into entering information is how phisers operate.


DiGiorgi Piano Service
http://www.digiorgipiano.com
Joined: Mar 2008
Posts: 4,263
4000 Post Club Member
Offline
4000 Post Club Member
Joined: Mar 2008
Posts: 4,263

Well, don’t have any fun with the password checker if you believe everyone is out to get you.
If you have concerns about password security keep in mind these simple rules;
Change your password once a month.
Insure your password has all the components, upper/ lower case, special characters and numbers.
The last one is keystrokes. I never type them in, but use cut/paste. This way if I have a keystroke logger the characters are not read.

Joined: Mar 2011
Posts: 807
P
500 Post Club Member
Offline
500 Post Club Member
P
Joined: Mar 2011
Posts: 807
Thanks for the reminder!

On a lighter note, I have to share how ridiculous this is: at work (federal gov.), we are required to change our password every 6 months...to get into...REQUIRED local continuing education "programs".

Unbelievable! OH no, someone ELSE is trying to do my CE, yikes!
leave it to the government....oh, and the requirements for the password are UNREAL. Most of us can't get in and end up on the phone with IT, wasting time.
See how your tax dollars are spent?

ooooops, I digress, sorry.


I don't care too much for money. For money can't buy me love.
-the Beatles



Joined: Aug 2005
Posts: 18,356

Platinum Supporter until Dec 31 2012
Yikes! 10000 Post Club Member
Offline

Platinum Supporter until Dec 31 2012
Yikes! 10000 Post Club Member
Joined: Aug 2005
Posts: 18,356
xkcd has the best stance on password strength:

[Linked Image]

Joined: Mar 2008
Posts: 9,230
O
9000 Post Club Member
Offline
9000 Post Club Member
O
Joined: Mar 2008
Posts: 9,230
Nice one ! I take that password !

(but many sites today ask for different characters to be used and will not accept that)


Professional of the profession.
Foo Foo specialist
I wish to add some kind and sensitive phrase but nothing comes to mind.!
Joined: Sep 2006
Posts: 3,983
3000 Post Club Member
Offline
3000 Post Club Member
Joined: Sep 2006
Posts: 3,983
Why would it be harder for hacker to discover my password, let's use Tr0ub4dor&3, if I have changed to it from Tr0mbo^ne%7 three months ago?

Will hackers really spend months and months working on trying to find out one lowly person's email password?


JG
Joined: Mar 2008
Posts: 9,230
O
9000 Post Club Member
Offline
9000 Post Club Member
O
Joined: Mar 2008
Posts: 9,230
Remind me of a friend who worked in computer security for the military. The zone where missiles where hidden was so secret that no telephone was able to reach the outside normal phone net.

So he had to discuss of the computer security question in a public phone at the nearest village !!


Professional of the profession.
Foo Foo specialist
I wish to add some kind and sensitive phrase but nothing comes to mind.!
Joined: Jun 2003
Posts: 32,060
B
BDB Offline
Yikes! 10000 Post Club Member
Offline
Yikes! 10000 Post Club Member
B
Joined: Jun 2003
Posts: 32,060
It may not be your password that was hacked. Have you seen one of the emails? The return address is probably not yours.

What probably happened is that either your address book was hacked, which can happen if you keep it on a server like AOL, or that someone got addresses from a carelessly addressed email.

You should use CC sparingly. If you are sending a message to a large group, use BCC instead.


Semipro Tech
Joined: Jun 2010
Posts: 2,671
L
2000 Post Club Member
Offline
2000 Post Club Member
L
Joined: Jun 2010
Posts: 2,671
Originally Posted by Supply
Why would it be harder for hacker to discover my password, let's use Tr0ub4dor&3, if I have changed to it from Tr0mbo^ne%7 three months ago?

Will hackers really spend months and months working on trying to find out one lowly person's email password?


Not at all! They just set up a password checker and lo and behold, you type it in for them. laugh


DiGiorgi Piano Service
http://www.digiorgipiano.com
Joined: Jun 2010
Posts: 2,671
L
2000 Post Club Member
Offline
2000 Post Club Member
L
Joined: Jun 2010
Posts: 2,671
Originally Posted by BDB
It may not be your password that was hacked. Have you seen one of the emails? The return address is probably not yours.

What probably happened is that either your address book was hacked, which can happen if you keep it on a server like AOL, or that someone got addresses from a carelessly addressed email.

You should use CC sparingly. If you are sending a message to a large group, use BCC instead.


Absolutely. Are you sure it was your account that was hacked? Lots of times, a random address from the person who was hacked's address book is put into the "from" line to throw people off. The fact that the mail is "from" you doesn't necessarily mean you're the one who was compromised.


DiGiorgi Piano Service
http://www.digiorgipiano.com
Page 1 of 2 1 2

Moderated by  Piano World, platuser 

Link Copied to Clipboard
What's Hot!!
Piano World Has Been Sold!
--------------------
Forums RULES, Terms of Service & HELP
(updated 06/06/2022)
---------------------
Posting Pictures on the Forums
(ad)
(ad)
New Topics - Multiple Forums
How Much to Sell For?
by TexasMom1 - 04/15/24 10:23 PM
Song lyrics have become simpler and more repetitive
by FrankCox - 04/15/24 07:42 PM
New bass strings sound tubby
by Emery Wang - 04/15/24 06:54 PM
Pianodisc PDS-128+ calibration
by Dalem01 - 04/15/24 04:50 PM
Forum Statistics
Forums43
Topics223,384
Posts3,349,159
Members111,630
Most Online15,252
Mar 21st, 2010

Our Piano Related Classified Ads
| Dealers | Tuners | Lessons | Movers | Restorations |

Advertise on Piano World
| Piano World | PianoSupplies.com | Advertise on Piano World |
| |Contact | Privacy | Legal | About Us | Site Map


Copyright © VerticalScope Inc. All Rights Reserved.
No part of this site may be reproduced without prior written permission
Powered by UBB.threads™ PHP Forum Software 7.7.5
When you purchase through links on our site, we may earn an affiliate commission, which supports our community.