Something went wrong. Try again later

Giant Bomb News

124 Comments

Everyone Should Change Their Uplay Password

Ubisoft admits to security exploit, meaning it’s time to mix up letters and numbers.

No Caption Provided

Is it time to finally invest in 1Password? Maybe so. Ubisoft has revealed new details about a recent website exploit that exposed its account database, including “user names, email addresses and encrypted passwords.”

“We recently found that one of our Web sites was exploited to gain unauthorized access to some of our online systems,” said the company in a statement on its forums. “We instantly took steps to close off this access, to begin a thorough investigation with relevant authorities, internal and external security experts, and to start restoring the integrity of any compromised systems.”

Encrypted passwords means the passwords themselves were not exposed in their pure form, but if a particular password isn’t very strong, it wouldn’t take much trouble for it to be deciphered.

Ubisoft said payment information was not exposed, so your debit and credit card should be safe.

If your Uplay password is one shared among other web services, it’s time to change all of those, too.

Patrick Klepek on Google+

124 Comments

Avatar image for bawlzinmotion
BawlZINmotion

704

Forum Posts

2025

Wiki Points

0

Followers

Reviews: 9

User Lists: 1

@luck702 said:

Thank Jesus I was smart enough to not buy a single Ubisoft game in 4 years. Uplay has become more than just unnecessary, it's become a liability.

Be careful, they might label you a hacker!

Avatar image for rkofan87
rkofan87

473

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By rkofan87

did the password use numbers?

Avatar image for attropheed
AttroPheed

24

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

So they spent as much time on securing the service as they did making sure it wasn't completely fucking annoying and useless.

Avatar image for ravenlight
Ravenlight

8057

Forum Posts

12306

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

Edited By Ravenlight

@patrickklepek:

Would be interested to learn more about stolen data like this. Does each company build their own security solutions or are there middleware security platforms? Is there a reason companies do/don't use a particular security solution? Are there common exploits across different database leaks? And are companies really just incompetent when it comes to customer data?

Potential investigative journalism piece? Or too techy for GB?

Avatar image for rollingzeppelin
rollingzeppelin

2429

Forum Posts

8

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Aw man, I though this was a phishing attempt today. God damn it.

Avatar image for hockeymask27
hockeymask27

3704

Forum Posts

794

Wiki Points

0

Followers

Reviews: 2

User Lists: 0

Whatever they can have it.

Avatar image for bigd145
BigD145

299

Forum Posts

28

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Ubi loses this and then kicks up a password changer that requires cookies? HAH! As if I'd trust that.

Avatar image for rollingzeppelin
rollingzeppelin

2429

Forum Posts

8

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

I dont really give a fuck about that account, as long as my credit info is safe they can go to town.

Avatar image for shaunage
Shaunage

948

Forum Posts

152

Wiki Points

0

Followers

Reviews: 4

User Lists: 10

Damn it, Ubisoft I don't even want this account. I never did. ARGH.

Avatar image for bluejester
bluejester

64

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

I never thought I could hate Uplay more than I already did. Ubisoft found a way, though.

Avatar image for terranova
Terranova

685

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

@kingsalo said:

so, if console Uplay is affected as well does that mean my PSN pw got stolen? i can't recall creating an account but i'm pretty sure i had to link my PSN account to Uplay for AC: Brotherhood's multiplayer...

Also, my PSN pw changed at least 2 times after that... i hope whoever got my information is as confused about that shit as i am.

no they are not linked that way your PSN user name is linked to the Ubisoft account not your PSN passwords.

Avatar image for zmilla
ZmillA

2519

Forum Posts

195

Wiki Points

0

Followers

Reviews: 0

User Lists: 4

I don't even remember what my uplay password is

Avatar image for xymox
xymox

2422

Forum Posts

2520

Wiki Points

0

Followers

Reviews: 7

User Lists: 8

I don't remember what's on my Uplay account or the password I had for it. If someone gets into it knock yourself out I guess. It's probably just From Dust or something, which doesn't work without a controller anyway.

uugggh.. So tired.. of this.. garbage.

What is with this backwards thinking bullshit? Clearly passwords are useless paper shields. Is there no other way to confirm someone's identity today? It's like every other month a website is hacked and it's change the password time. Just get rid of passwords, duh.

Yeah, this, really. Passwords are so 90's. Can we really not do better than that?

Avatar image for matthewleb
matthewleb

15

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

@iamjohn: I was thinking the same thing.

Avatar image for otacon
Otacon

2337

Forum Posts

846

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

I have Uplay, but I have no idea what it is, or what my password for it is for that matter.

Avatar image for batmanbatman
BatmanBatman

565

Forum Posts

3712

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

DAMN YOU AIDEN PEARCE!!!!

Avatar image for f12
F12

15

Forum Posts

87

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

That explains the 4 or 5 "a password change was requested on your account" emails I got from various services this week.

Also, this:

Hey guys who may have my password, can you tell me what my password was?

Avatar image for bgdiner
bgdiner

315

Forum Posts

1

Wiki Points

0

Followers

Reviews: 13

User Lists: 0

Edited By bgdiner

I'm really sick of this shit.

Avatar image for probablytuna
probablytuna

5010

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

I hate changing passwords.

Avatar image for facelessvixen
FacelessVixen

4009

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 5

So... after trying to log in with the e-mail addresses that typically I use for gaming stuff, though I did log in to U-Play using PSN for Far Cry 3, I apparently don't have a U-Play account.

*changes every password*

Avatar image for wintermute
wintermute

443

Forum Posts

694

Wiki Points

0

Followers

Reviews: 2

User Lists: 15

Edited By wintermute

Lastpass works really well, I use that. But even with it, trying to change my Ubisoft password was a very frustrating experience and I think I may have locked myself out. Apparently I have two accounts on there. It's confusing and unneccessary. All I wanted to do was play some Anno 2070 and I have to put up with this crap for what? Their bullshit DRM? I paid for this game and now I have to wait 15 minutes to see if I can play it. This sucks. I'm having second thoughts about getting Watch Dogs now if it means I have to put up with this more.