View Single Post
  #25  
Old 04-17-2014, 08:42 AM
Carl Kolchak Carl Kolchak is offline
Member
 
Join Date: Dec 2004
Location: U.K.
Posts: 2,201
Default Re: my cranesong phoenix was stolen from me by ilok

Two important things guys :

1. So long as you don't sync your iLok, you wont loose anything (if needs be, buy a new iLok, and only ever sync that to add new plug-in purchases).

2. Heartbleed.

I checked ilok.com when Heartbleed was first discovered, and it was vulnerable, but has just been made secure (there has been no word from PACE on this issue).

It's entirely possible that the reason you "must not contact iLok support, as they can't help you" is because none of this communication is actually coming from PACE / iLok (and they are unaware of it).

Heartbleed makes it possible for nefarious 3rd parties to not only harvest all your passwords and user ID's etc, but to also create a convincing facade of being the original host website - so this could be either a grand hoax, or an actual hijack of assets.

PACE need to be notified, as does the wider community, and everyone now needs to change their ilok.com passwords.

FYI avid.com always was secure, as it doesn't use OpenSSL. The DUC on the other hand, was vulnerable, but has since been secured.
Reply With Quote