Something went wrong. Try again later

Giant Bomb News

124 Comments

Everyone Should Change Their Uplay Password

Ubisoft admits to security exploit, meaning it’s time to mix up letters and numbers.

No Caption Provided

Is it time to finally invest in 1Password? Maybe so. Ubisoft has revealed new details about a recent website exploit that exposed its account database, including “user names, email addresses and encrypted passwords.”

“We recently found that one of our Web sites was exploited to gain unauthorized access to some of our online systems,” said the company in a statement on its forums. “We instantly took steps to close off this access, to begin a thorough investigation with relevant authorities, internal and external security experts, and to start restoring the integrity of any compromised systems.”

Encrypted passwords means the passwords themselves were not exposed in their pure form, but if a particular password isn’t very strong, it wouldn’t take much trouble for it to be deciphered.

Ubisoft said payment information was not exposed, so your debit and credit card should be safe.

If your Uplay password is one shared among other web services, it’s time to change all of those, too.

Patrick Klepek on Google+

124 Comments

Avatar image for malphye
Malphye

414

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Glad I used a unique one off password for uplay. Little proud of myself here, moral +1.

Avatar image for starfoxa
StarFoxA

5262

Forum Posts

260822

Wiki Points

0

Followers

Reviews: 12

User Lists: 12

It is so, so, so important to use a password manager nowadays. I recommend KeePass, because it is open source, cross platform, and doesn't require an internet connection. This is the most important thing you can do when it comes to protecting your online security.

Avatar image for snail
Snail

8908

Forum Posts

16390

Wiki Points

0

Followers

Reviews: 1

User Lists: 9

Who_watches_the_Watch_Dogs?!?!

Quis custodiet ipsos puppies?

Avatar image for spraynardtatum
spraynardtatum

4384

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 1

@starfoxa: I don't even want that thing on my computer. Pen and paper.

Avatar image for bbqbram
BBQBram

2497

Forum Posts

88

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

Oh no, not my valued Ezio skin? Is that what people are thinking now?

Avatar image for bacongames
bacongames

4157

Forum Posts

5806

Wiki Points

0

Followers

Reviews: 2

User Lists: 8

Granted I had an account with them since ACII, having just downloaded Trials like a few days ago makes the timing on this rather quaint. Password changed, time to keep an eye on suspicious activity on my shit.

Avatar image for starfoxa
StarFoxA

5262

Forum Posts

260822

Wiki Points

0

Followers

Reviews: 12

User Lists: 12

@spraynardtatum: Pen and paper? Then someone could easily take that sheet and have your passwords. How about encrypting a flash drive with TrueCrypt to hold your database, with a separate password for TrueCrypt AND for KeePass. That's security paranoia.

Avatar image for dagbiker
Dagbiker

7057

Forum Posts

1019

Wiki Points

0

Followers

Reviews: 0

User Lists: 16

@starfoxa said:

It is so, so, so important to use a password manager nowadays. I recommend KeePass, because it is open source, cross platform, and doesn't require an internet connection. This is the most important thing you can do when it comes to protecting your online security.

This is not a bad Idea, but I would only use an open source Password Manager if I Looked at the code, understood it, and perhaps modifyed it. Because, being open source it is that much easer to create something that can open the files that it creates.

Avatar image for starfoxa
StarFoxA

5262

Forum Posts

260822

Wiki Points

0

Followers

Reviews: 12

User Lists: 12

Edited By StarFoxA

@dagbiker: KeePass is heavily documented. Thousands of incredibly talented programmers have scoured through its code. At some point there has to be a degree of trust, and as someone without programming experience, that's enough for me. I prefer it over LastPass and 1Password because I can store my databases locally.

Avatar image for vladgd
vladgd

10

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

I bought Farcry 3 on steam to try and avoid making another account on some other service, but nope, launch game through steam...to launch uplay to play Farcry 3.

Avatar image for kingsalo
KingSalo

64

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

so, if console Uplay is affected as well does that mean my PSN pw got stolen? i can't recall creating an account but i'm pretty sure i had to link my PSN account to Uplay for AC: Brotherhood's multiplayer...

Also, my PSN pw changed at least 2 times after that... i hope whoever got my information is as confused about that shit as i am.

Avatar image for eccentrix
eccentrix

3250

Forum Posts

12459

Wiki Points

0

Followers

Reviews: 4

User Lists: 15

@shevar said:

I find it always funny that when stuff like this happens, your payment information and credit card number always seem to be "unexposed".

Those must receive some added level of security than I guess. If that's the case, why can't they use that security to keep my password from being stolen/copied in the first place.

I just assume they're kept in different places.

I don't even know that I used Uplay on PC, which means I wouldn't have a password, right? Oh well, I can take the risk this once.

Avatar image for scratch
Scratch

647

Forum Posts

2520

Wiki Points

0

Followers

Reviews: 0

User Lists: 8

After reading this article and comments, checked my email and found nothing from Ubi. Checked again in the spam folder and there it was. I suggest other uPlay users just check your email for a link requesting you to change your password as well, because their website is understandably down for maintenance.

Avatar image for spraynardtatum
spraynardtatum

4384

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 1

Avatar image for gbrading
gbrading

3317

Forum Posts

10581

Wiki Points

0

Followers

Reviews: 34

User Lists: 5

Goog thing I've managed to boycott uPlay so long!

Avatar image for starfoxa
StarFoxA

5262

Forum Posts

260822

Wiki Points

0

Followers

Reviews: 12

User Lists: 12

@spraynardtatum: Insult? I was describing what I do to keep a backup of my passwords.

Avatar image for otterchaos
OtterChaos

413

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Site's down, can't change password.

Uplay, even when not playing games you find a way to be a complete piece of shit.

(update) got the e-mail and was able to reset the password that way, check your spam folders.

Thanks for the hint on spam folder, that is where my email landed.

Avatar image for otterchaos
OtterChaos

413

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

@snail said:
@spitznock said:

Who_watches_the_Watch_Dogs?!?!

Quis custodiet ipsos puppies?

I imagine that would be @rorie wouldn't it?

Avatar image for spraynardtatum
spraynardtatum

4384

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 1

@scratch: It was in my spam folder too.

Avatar image for morden2261
morden2261

285

Forum Posts

25

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

I hate that crap like this doesn't even surprise me anymore.

Avatar image for sterling
Sterling

4134

Forum Posts

2

Wiki Points

0

Followers

Reviews: 0

User Lists: 4

My new password is: fuckingpassword

in case anyone wants it.

Avatar image for pimblycharles
PimblyCharles

1922

Forum Posts

102

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Edited By PimblyCharles

Damnit, got the email. I'm so damn sick of all these password hacks this year. Was also affected by a google hack not long ago. Can't forget about my Evernote account getting hacked too. Ridiculous.

Avatar image for pimblycharles
PimblyCharles

1922

Forum Posts

102

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

My new password is: fuckingpassword

in case anyone wants it.

Dexter's back

Avatar image for rvone
RVonE

5027

Forum Posts

8740

Wiki Points

0

Followers

Reviews: 0

User Lists: 6

@mrmazz said:

Or you know just never have a Uplay account because it's terrible.

Yes, unfortunately that is impossible if you want to play, for example, Far Cry 3.

Avatar image for budwyzer
Budwyzer

801

Forum Posts

39

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

@iamjohn said:

These publisher-exclusive services sure are great and necessary, you guys.

Captain Totally!

Avatar image for jedted
Jedted

2970

Forum Posts

1307

Wiki Points

0

Followers

Reviews: 8

User Lists: 17

Edited By Jedted

Goddamn Cyber-Terrorists.

Avatar image for randomstring
randomstring

21

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By randomstring

Fortunately I don't have a Uplay account. I refuse to buy ubisoft games since they put that turd into service.

Avatar image for test0r
test0r

121

Forum Posts

7

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

@starfoxa: While I understand why you want to keep using KeePass I'd just like to clarify that both 1Password and Lastpass stores a local copy of your database. 1Password is in essence just a closed-source KeePass.

I personally use Lastpass, but that's just because it's really nice to have it on every device I use without having to share the database file with an application like dropbox.

Avatar image for spraynardtatum
spraynardtatum

4384

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 1

@starfoxa: I'm sorry about that. I thought you were calling me paranoid. Or should I say "I was paranoid that you called me paranoid". I took it the wrong way. Sorry.

Avatar image for siln
siln

110

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By siln

Today is a sad day, as thousands of Uplay users, myself included, were tragically reminded that at some point in their lives, they signed up for a Uplay account.

Avatar image for benu302000
benu302000

221

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 2

Edited By benu302000

I'm so glad that I had to create a UPlay account in order to play single-player FarCry 3. That was totally worth this pain in my ass.

Avatar image for zoozilla
zoozilla

1025

Forum Posts

25

Wiki Points

0

Followers

Reviews: 2

User Lists: 4

I like lastpass better than 1password

And I like KeePass best of all!

Avatar image for brownsfantb
brownsfantb

455

Forum Posts

493

Wiki Points

0

Followers

Reviews: 2

User Lists: 30

I have no idea what my password is for Uplay. Hopefully it's something dumb that I don't use anywhere else.

The good news is this reminded me that I bought 1Password a while back but never set it up.

Avatar image for musubi
musubi

17524

Forum Posts

5650

Wiki Points

0

Followers

Reviews: 8

User Lists: 17

I still dont get why password managers are needed the only accounts I truly care about are both my emails,social media,PSN and Bank accounts. All which I use every day and monitor like a hawk for suspicious activity.

Changed my password for posterity sake but honestly the reason these hacks happen aren't to get at peoples passwords. Morale than likely its to get a huge bulk of thousands of emails they can either sell to or use in phishing rings. The actual value in hacking a Uplay account is nothing. Now being able to send a phishing email to 20 or 30 thousand people and hope someone bites is another story.

Avatar image for silentbob251
silentbob251

68

Forum Posts

20

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Video game related websites getting hacked? Must be summer!!

Avatar image for hawkerace
Hawkerace

364

Forum Posts

0

Wiki Points

0

Followers

Reviews: 2

User Lists: 0

Haven't touched blood dragon and any other ubisoft title I owned because of uplay.

It's the worst.

Avatar image for musubi
musubi

17524

Forum Posts

5650

Wiki Points

0

Followers

Reviews: 8

User Lists: 17

Edited By musubi

@kingsalo: Linking accounts doesn't mean your PSN is exposed it simply means you gave the authority to Uplay to access your PSN account. No PSN information would have been exposed.

Avatar image for kindgineer
kindgineer

3102

Forum Posts

969

Wiki Points

0

Followers

Reviews: 0

User Lists: 5

Getting really sick and tired of this. I'm not going to jump on the bandwagon and harp about 'these services aren't necessary,' but damn if all of these hacking (& attempts) don't annoy the living hell out of me. Why can't people just leave our shit alone?

Avatar image for toxeia
Toxeia

792

Forum Posts

2

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

So I've got a password for stuff that I find to be sketchy, my email, and then passwords with slight modifications for systems that would have my credit card information (Steam, Amazon, etc.).

Who wants to guess where uPlay fit into those three?

Avatar image for aetheldod
Aetheldod

3914

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

So yeah DRM is the future right guys? All those juciy hacked accounts ... yeah su much better than physical copies indeed.

Avatar image for kmg90
kmg90

514

Forum Posts

2705

Wiki Points

0

Followers

Reviews: 1

User Lists: 8

Edited By kmg90

@dagbiker said:

@starfoxa said:

It is so, so, so important to use a password manager nowadays. I recommend KeePass, because it is open source, cross platform, and doesn't require an internet connection. This is the most important thing you can do when it comes to protecting your online security.

This is not a bad Idea, but I would only use an open source Password Manager if I Looked at the code, understood it, and perhaps modifyed it. Because, being open source it is that much easer to create something that can open the files that it creates.

That concern would be valid if it not being that it uses AES/Rijnael and relies on security features that make no two databases alike including using additional files/user information for authentication..

My Keepass Master password is seaserpent does giving this information out to anyone a hindrance to my security? No since it requires additional information to open my password database

Avatar image for mikey87144
mikey87144

2114

Forum Posts

3

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

I guess I haven't played too many ubi games.

Avatar image for brainwins
brainwins

354

Forum Posts

5

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Awesome! I had to sign up to their shitty service after buying Assassin's Creed from Steam, and now they fuck it up. Way to go!

Avatar image for nux
Nux

2898

Forum Posts

130

Wiki Points

0

Followers

Reviews: 2

User Lists: 2

Good thing I don't have a Uplay account.

Avatar image for mooseymcman
MooseyMcMan

12785

Forum Posts

5577

Wiki Points

0

Followers

Reviews: 0

User Lists: 13

Oh no! Someone is going to steal those points I use to unlock stupid things in Assassin's Creed games!

Avatar image for rkofan87
rkofan87

473

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

@bribo:

dam it son of bitch this is going to be a hell

Avatar image for sooty
Sooty

8193

Forum Posts

306

Wiki Points

0

Followers

Reviews: 2

User Lists: 3

I would if Uplay wasn't absolutelyfuckinguseless and not worth my time to log into.

Avatar image for mrslaphappy
MrSlapHappy

240

Forum Posts

323

Wiki Points

0

Followers

Reviews: 0

User Lists: 13

Sweet!! Switching to Lastpass after the sorta Blizzard thing awhile back paid off! Uplay usage has never been higher!

Also, damnit, why does this have to keep happening?

Avatar image for sooty
Sooty

8193

Forum Posts

306

Wiki Points

0

Followers

Reviews: 2

User Lists: 3

Edited By Sooty

@demoskinos said:

I still dont get why password managers are needed the only accounts I truly care about are both my emails,social media,PSN and Bank accounts. All which I use every day and monitor like a hawk for suspicious activity.

Changed my password for posterity sake but honestly the reason these hacks happen aren't to get at peoples passwords. Morale than likely its to get a huge bulk of thousands of emails they can either sell to or use in phishing rings. The actual value in hacking a Uplay account is nothing. Now being able to send a phishing email to 20 or 30 thousand people and hope someone bites is another story.

Password managers aren't needed, but they make logging into everything easier. I never have to worry about forgetting the password for some obscure website I rarely ever use. I have a few passwords I alternate between and super secure ones for anything valuable, so sometimes I forget which ones and it saves me having to go through all of them.

I like using Dashlane, automatically fills in my credit card, addresses (I have 2, for my uni dorm and home address), passwords and automatically logs me in.

Plus, if in the event you got keylogged (which I never have) they could potentially save your ass there too.