DailyStrength Members Community Support Group
Welcome! This community exists for DailyStrength members to have a place to share thoughts and feedback about the site with the folks that run DailyStrength. DailyStrength team members will regularly visit this community, sharing new product ideas, seeking feedback and beta testers, and most importantly, listening to you. Come join us!
Hello,
A few weeks ago, we began receiving reports that some member accounts were showing a link to graphic material in their status updates, and those same accounts were sending out random friend requests.
After a thorough investigation, we have concluded that this issue is NOT happening due to a technology issue with the DailyStrength.org site. It's been discovered that some members are using email addresses from outside organizations who have previously experienced data breaches. This information was not taken from DailyStrength's account database nor was DailyStrength's login system compromised.
What we're doing to address this issue:
· Here at DailyStrength, we are committed to ensuring the safety, privacy and the integrity of your accounts.
· To combat this issue we have blocked access to the DailyStrength.org site from regions across the globe where many of these spammers were originating.
· We are also deactivating any accounts we come across that look affected by this issue.
· Additionally, please know that we use best practices for safeguarding your information, and industry standard technologies to prevent unauthorized access to member accounts.
Our recommendations for you:
If at any time you are concerned that someone has unauthorized access to your DailyStrength account, you should:
· Change the password associated with the email address that you use to login to DailyStrength. You'll need to contact your email provider for instructions on how to do this.
· Change your DailyStrength account password by navigating to your own profile page and clicking on the orange "edit" button.
· Let us know by filling out this form
Please contact us via the submit a request form if you have any questions or concerns.
Best,
Team DailyStrength
-
Hey all, i know its been quite awhile since i posted on here. Its been a summer all right. Its been something else........... You know how they say not to open the can of worms? Well a few months ago i decided to find out what my due date would have been for my first baby, the one conceived by r***. My baby would have been due on March 4th of 2006. They would be 20 years old. I was R**** on June...
-


https://www.theguardian.com/technology/2018/oct/02/facebook-hack-compromised-accounts-tokens
Bottom line - don't use Facebook for logging in to other accounts. DS shouldn't have offered something that undermined it's members and the site's security.
Anytime Facebook gets hacked or some hacker or whatever gets the Facebook data from a previous breach they can do more or less what they like with the accounts here.
***Once upon a time, DS was more popular and back then it was fairly easy to google to see the real names of some DS employees who had responsibility for the site. Or I could google the names of the people who had posted comments.
I'm FAR from a computer expert, but this stuff takes me about 2 minutes to look up.
Right now as my son is looking up internship possibilities, I'm teaching him how to find out real names of people to address his letters to.***
Way back when, it was common to post lists of Who was your first boyfriend? First car? Favorite food? Favorite color? etc, etc, etc....30-40 questions long. (All of those are now common password security questions.)
In my real life, I never use one word answers...ever. And still I worry, because I've been through password resets and I know the questions that they go through to try to re-establish identity.
Here’s an example:
A database breach is made (fbook or other outside organisation) where the email address is the account name. You have a readymade list of email accounts. Now let’s say the breach extends to the account passwords for use with (let’s say) fbook. You now have a list of email with corresponding fbook password. Then Let’s say a bot goes to DS and tries all the email accounts on the log in screen and uses the corresponding fbook password for said email. IF a DS member used the same password for their Facebook and DS account, then they’re in. That would also mean DS’s log in process was none the wiser.
For this theory to be correct, it needs to be a big organisation that was breached such as fbook, gmail, yahoo, for that many accounts to be on both websites.
I confess i’m out of my depth trying to explain this and it doesn’t explain why only those type of DS accounts inactive since 2016/17 were affected.
Btw that was just one theory.
And even so it would seem then that if something somewhere gets hacked DS is completely unable to do anything about it if that then ends up doing stuff here. That doesn't seem right.
I've looked and it seems DS no longer offers sign on through Facebook.
But whatever it is I think a message which boils down to "it wasn't us that messed up, it was someone else and also it was you the member" doesn't really help. Or that the problem is still going on and it seems other than switching off accounts it can't be stopped.
With the hackers, as far as I know, the most they did was change status and add friends, I don’t know if that’s fairly simple for a bot. Perhaps the bot just finds viable accounts and a human adds a status etc.
It would be good to know it’s dealt with, solved. But it seems members are still being affected.
How do "they" manage to find a local phone number to put in the caller ID to my house?
Answer...because if you are 20 years old in certain countries, you've got nothing to do with your life other than to try to scam money out of people who have money.
It's gone beyond random local phone numbers though...now it's local businesses that you're likely to have had contact with. And coming are computer generated voices that sound like neighbors (that they will get from recording the voices of neighbor's voices when they answer their phones.)
Focusing on the specifics of what happened in this case...is missing the point. Point is that there WILL be a next time. And we ALL need to be very careful about our Real Lives (because scammers don't care about anyone's ptsd, depression, anxiety, etc). What they want is our $$$.
We thought DS was our safe space. We accepted spamming as being everywhere. What we didn't expect was our old friends and familiar members accounts suddenly coming back to life as spambots.
What DS has told us is if a hack is made on some other organisation which members share an email with then the hackers can do whatever they like on DS. And DS have more less told us they can't stop it.
I'm sure DS would love us to stop focusing on what and how this happened because they are not taking any responsibility.
I'm not going to argue with you over this, the point is that many of us are concerned about this and the implications for us for whatever personal reasons we might have. You don't, fair enough but don't tell me what I should or should not worry about.
Thanks.
And my point is...DS was NEVER a safe place.
I agree with DS...they can't stop it. They can and do slow it down...considerably. They react AFTER the fact, and probably a number of things beforehand...but they'll never be able to stop it.
Look, DS is a small, small, small little site on the web. But as long as there are people in this world earning $2/day...there will be scammers trying to get someone to bite.
As far as "arguing with me over this"....I've never asked you to argue. It would be nice if you'd listen even if you don't agree.
But..there's not a whole lot of talk on DS.
From what YOU write on here...DS/Sharecare doesn't "talk" with you. And from your responses to me, it's clear that you don't want to "talk" with me.
Ironic?
That's my favourite thing on DS..... So I'm sending them all around....xo
As for DS being a "small" little space on the net...I don't think people understand how big of an entity Sharecare, the Corporation that owns and operates DS is, its not a small little space.
It hasn't happened to me in about a week now. So maybe the pervs gave up or were dealt with.
I've thought this for a while that a business is not going to share all that goes on with people outside of the business, volunteers and people using the site
I think DS did give an explanation and if some people aren't satisfied with the answer then they should write DS directly with any questions that they have
I do think that we need to be cognisant of the fact that real people are working on this site....and we're here to give and receive support
So as much as we've all been frustrated we can also take a breath and simply ask the questions that we may want an answer to.... They may be limited because it's a business and I imagine staff is told what they can share..... This is with pretty much all business's I think
https://www.forbes.com/sites/zinamoukheiber/2010/10/22/webmd-founder-jeff-arnold-stages-comeback-with-new-health-site-watch-out-webmd/#24941766623c
https://www.globenewswire.com/news-release/2018/09/21/1574500/0/en/Sharecare-teams-up-with-Walmart-to-help-people-across-the-country-take-control-of-their-health-at-Walmart-Wellness.html