This is what gets me. I can have every aspect of my life super secure, I can use a 64 character alphanumeric password with special characters and at least 6 urdu characters which I change every single week and I never write it down anywhere, but I shopped at Home Depot once 6 years ago and now my data got swooped up along with millions of other users.
Hell, I live in a state where the DMV got hacked and everyone’s drivers license data in the entire state was stolen. Would smashing my old hard drives with a hammer prevent this?
Is jumping through all of those paranoid hoops even worth it for an individual? The biggest vulnerabilities are outside of my control, so why should I make my day to day life an endless exhausting security theatre ritual?
Plus, my life isn’t that interesting. I don’t have millions of dollars in my investment accounts. I’m not a superspy. I don’t have much data that I need to be secretive with.
I think the problem is people may need to enable it for a prolonged period, then forget to disable it. Making it too easy for the user to leave the software in a vulnerable state. I think this is what’s making Blender a good target.
It might deter hackers if users are always prompted when opening a previously unopened blend file that has an autorun script, because nobody is going to fall foul to their lack of knowledge of the preferences or having forgotten to set it back.
If startup scripts are disabled in preference, or there’s no autorun script present, then no prompt is necessary, but if enabled and there is a script, the user gets a reminder and knows they need to find out what it is first, hacker gets less success and moves onto another target.
The incredible length the hacker is going to to bypass ongoing attempts to block him, suggests he’s having a high success rate, which indicates the current system isn’t enough to keep users protected. I’m guessing he/she’s not only delivering to creators via Blender Market (superhive sorry), so it does feel as though it has a sense of urgency about it.
I wonder if this title should be renamed again to ‘blend file with virus in circulation’ ? Just so more people click on it, as I’m guessing this hacker will be posting it on multiple platforms and email campaigns judging by his persistence.
Yeah, we have had some big data leaks like that down here as well.
Having said that, I’ve largely been unaffected by them and this is partly due to the fact I take my security and privacy ‘off-line’ as well.
Just enter this competition to win a $200 ecard, all you have to do is fill in your name, phone number, etc. NOPE, not doing that, chances I win are so small and I don’t want my data first put into a marketing database and second creating another database that can be hacked/leaked.
The local retailer that on checkout just asks for you postcode, at best they get the overall general State one (which is totally obvious, since that’s the State I’m standing in at the time) or I don’t give anything. What I never do is give my actual real postcode.
General websites or anything outside of official finance/government that asks for DOB in general or as part of age verification, gets a fake DOB. Assuming I care or somewhat need the service or whatever it is to start with. Plenty of times I’ve got to that point and just said, stuff it and closed the tab.
Like I said, there have been big hacks/leaks over the past couple of years down here as well. As a result from that, I am totally sure that the scammers deleted their old ‘contact’ lists and re-built new ones using all the new/latest information.
I’m so sure of this, due to the fact my data was never part of those recent big leaks and prior to that, I did get scam calls fair constant. Now, since then, for the past couple of years, I think I’ve had 1 scam call. Basically I got removed from the scammers system. Now sure, that’s partly good luck, but it’s also good practice of protecting myself.
Hi yall. I just wanted to make folk aware of the shady blender scams going on recently, since this is a new thing to me. I’ve dealt with Blendermarket’s customer support before this and they’re always helpful and nice. I don’t want this thread to be an attack on them Rather attack the scammers
Stay Safe and Blend On
Over the past few weeks, Superhive has seen an influx of spam and phishing attempts targeted at Creators via the Superhive inbox. We have added many security measures over the course of this week and are still experiencing some very persistent phishing attempts with consistently switching tactics.
Steps you can take to stay safe
Look for the Admin badge. We have recently added an Admin badge to user accounts that belong to our Superhive crew. Some of the most dangerous phishing attempts are messages from users posing as the Superhive Support Team. If there is no Admin badge this is not us.
Do not reply to a message in order to create a “secure page.” We will never ask you to do this. Here is an example of a recent phishing attempt.
Never share a 2FA code. Verification codes should never be shared with a third party. This is a clear sign of a phishing attempt.
Turn off auto-exec python scripts. We have been investigating the malware in the .blend file from one of the phishing tactics. While we don’t know the exact intention of the script, it was hidden within an armature and if it ran would proceed to install a host of hidden services on the system, hiding them from the Windows registry, and proceed to do a host of suspicious things.
Security measures we have deployed
Email verification. We deployed email verification for all user signups and email changes. Before a user can login they must verify their email.
Admin badges As mentioned above, we’ve added Admin badges to Superhive crew members in the Inbox. If you get a message from someone claiming to be us that doesn’t have the badge you can safely ignore them (and report them to us!)
Additional automatic spam/bot detection. In addition to blocklists, we have added spam/bot detection to a host of forms, including all Inbox conversations. Attempts that are caught will immediately ban the user and log it for us so we can watch future attempts and false positives.
It’s not just us. We have learned that similar attacks are also being deployed on CGTrader. We have reached out to their team and are working together to fight these bad actors. They have chosen the wrong community to target! Our Blender Community is banding together to fight the good fight and will surely prevail.
In the meantime, remain cautious and keep up the good work!
Best,
Amber
SuperHive team is incredible.
But, beware folks, blender script malware is a thing now, don’t trust files from unknown sources