Bug causes inadvertent security notification emails
					Forum rules
The News forum is only for updates about the Prohashing pool.
Replies to posts in this forum should be related to the news being announced. If you need support on another issue, please post in the forum related to that topic or seek one of the official support options listed in the top right corner of the forums page or on prohashing.com/about.
For the full list of PROHASHING forums rules, please visit https://prohashing.com/help/prohashing- ... rms-forums.
	The News forum is only for updates about the Prohashing pool.
Replies to posts in this forum should be related to the news being announced. If you need support on another issue, please post in the forum related to that topic or seek one of the official support options listed in the top right corner of the forums page or on prohashing.com/about.
For the full list of PROHASHING forums rules, please visit https://prohashing.com/help/prohashing- ... rms-forums.
- Chris Sokolowski
- Site Admin
- Posts: 945
- Joined: Wed Aug 27, 2014 12:47 pm
- Location: State College, PA
Bug causes inadvertent security notification emails
Hi Everyone,
I wanted to explain what is happening with security notification emails. I first want to emphasize that these messages are not a result of a hack or breach of our security.
I was performing a routine check of our services today, and I discovered that there was one customer with an invalid email address that was causing the routine that sends security notifications to fail. When I fixed the issue and the routine executed properly, all queued emails from the past three weeks were sent at the same time.
These notifications are correct, but they are not for changes made today. They are related to account changes that have occurred since May 21. If anything was changed multiple times since May 21, then multiple emails would have been sent today. Note that a security notification is sent if anyone changes a payout address or email address, even if it was the account owner and the change was intentional.
If you received a security notification, I recommend checking your account's payout addresses and email addresses to be sure they are correct. However, most likely you will not need to take any action because you were the one that changed the information and the email was just a routine warning.
I apologize for the issue and any concern it has caused. If you have any questions, feel free to ask. Thank you for mining with us.
Sincerely,
-Chris Sokolowski
			
			
									
									
						I wanted to explain what is happening with security notification emails. I first want to emphasize that these messages are not a result of a hack or breach of our security.
I was performing a routine check of our services today, and I discovered that there was one customer with an invalid email address that was causing the routine that sends security notifications to fail. When I fixed the issue and the routine executed properly, all queued emails from the past three weeks were sent at the same time.
These notifications are correct, but they are not for changes made today. They are related to account changes that have occurred since May 21. If anything was changed multiple times since May 21, then multiple emails would have been sent today. Note that a security notification is sent if anyone changes a payout address or email address, even if it was the account owner and the change was intentional.
If you received a security notification, I recommend checking your account's payout addresses and email addresses to be sure they are correct. However, most likely you will not need to take any action because you were the one that changed the information and the email was just a routine warning.
I apologize for the issue and any concern it has caused. If you have any questions, feel free to ask. Thank you for mining with us.
Sincerely,
-Chris Sokolowski
Re: Bug causes inadvertent security notification emails
Thank you for the quick breakdown Chris.  
Good
			
			
									
									
						Good
Re: Bug causes inadvertent security notification emails
So my payout address was definitely changed how do you explain that?
			
			
									
									
						- Steve Sokolowski
- Posts: 4585
- Joined: Wed Aug 27, 2014 3:27 pm
- Location: State College, PA
Re: Bug causes inadvertent security notification emails
Unfortunately, we can't explain how your payout address was changed, as that is out of the scope of this issue. The most likely cause is that someone obtained your password and changed it.bachel wrote:So my payout address was definitely changed how do you explain that?
The scope of this post is solely to explain that E-Mails indicating payout address changes were delayed by a few weeks. There were no widespread hacks; the only impact was a delay in sending E-Mails, for which we apologize.
Re: Bug causes inadvertent security notification emails
not sure if this feature is enabled here or not (as it has been some time since i have actually mined here) but on other pools, as a security feature, everytime a payout address is modified, payment is suspended for 24/48 hours. being that most will notice when a payment is missed, this feature helps to stop theft before it happens.
			
			
									
									
						Re: Bug causes inadvertent security notification emails
So the 20 others in the chat this morning with the same problem all got fished ?Steve Sokolowski wrote:Unfortunately, we can't explain how your payout address was changed, as that is out of the scope of this issue. The most likely cause is that someone obtained your password and changed it.bachel wrote:So my payout address was definitely changed how do you explain that?
The scope of this post is solely to explain that E-Mails indicating payout address changes were delayed by a few weeks. There were no widespread hacks; the only impact was a delay in sending E-Mails, for which we apologize.
- Steve Sokolowski
- Posts: 4585
- Joined: Wed Aug 27, 2014 3:27 pm
- Location: State College, PA
Re: Bug causes inadvertent security notification emails
fished?bachel wrote:So the 20 others in the chat this morning with the same problem all got fished ?Steve Sokolowski wrote:Unfortunately, we can't explain how your payout address was changed, as that is out of the scope of this issue. The most likely cause is that someone obtained your password and changed it.bachel wrote:So my payout address was definitely changed how do you explain that?
The scope of this post is solely to explain that E-Mails indicating payout address changes were delayed by a few weeks. There were no widespread hacks; the only impact was a delay in sending E-Mails, for which we apologize.
If you mean "phished," as in someone stealing information, then the answer is no. There were no systemwide hacks.
Re: Bug causes inadvertent security notification emails
1st this happened to my was in april 2018, I had not 2fa enabled and got back into my account after 3 days and I lost one payout because the address was changed, I fixed all back and enabled 2fa, yesterday 8jun18 it happened again and I could not get back into my account since 2fa did not send me the code to login. so I have to move my miners to another pool since I cannot use my account anymore and not want to mine and someone else get my payout. Can you fix my account so I can use it again? account: qosmio
			
			
									
									
						Re: Bug causes inadvertent security notification emails
So why did so many payout addresses get changed ?Steve Sokolowski wrote:fished?bachel wrote:So the 20 others in the chat this morning with the same problem all got fished ?Steve Sokolowski wrote:
Unfortunately, we can't explain how your payout address was changed, as that is out of the scope of this issue. The most likely cause is that someone obtained your password and changed it.
The scope of this post is solely to explain that E-Mails indicating payout address changes were delayed by a few weeks. There were no widespread hacks; the only impact was a delay in sending E-Mails, for which we apologize.
If you mean "phished," as in someone stealing information, then the answer is no. There were no systemwide hacks.
Miracle Hack or Devs who develop on a live system without testing anything before hand ?
Re: Bug causes inadvertent security notification emails
request for improvement to the notification email:
1) state which coin it's talking about
2) it says "Action: Payout Address Changed" however the same email is generated if the minimum payout amount is
changed. so perhaps rephrase it to say "Payout Address and/or Minimum Amount Changed" or something similar.
			
			
									
									
						1) state which coin it's talking about
2) it says "Action: Payout Address Changed" however the same email is generated if the minimum payout amount is
changed. so perhaps rephrase it to say "Payout Address and/or Minimum Amount Changed" or something similar.



