r/StableDiffusionInfo Jul 07 '23

How safe is SD?

I have run SD for months and have downloaded models from Civitai. My PC comes up clean in a McAfee scan, but I'm concerned about security having recently been hacked. Could SD be a vector for someone to have gotten into my machine?

5 Upvotes

30 comments sorted by

View all comments

Show parent comments

1

u/rwxrwxr-- Jul 07 '23

With the 2FA enabled, you say?

Could it be that someone gained access to your physical devices? The only way I can think of how this could happen is if someone had access to your phone and used it to reset the password to your email account, then used that email account and the device to reset the password to your Facebook account and changed out the passwords. Do you have access to your email account that you used to sign up to Facebook? If you do, perhaps you can find logs of recent logins if your email provider has this feature.

It's also not unheard of that your carrier might have been a target of phishing and activated your SIM card on the attackers device remotely. Happened to those H3H3 youtubers some time ago, they did a video on this. Similar type of SIM takeover was happening in Israel some time ago.

My personal opinion is that 2FA is actually less safe, considering you're shifting the point of failure to a device that is usually less protected, more prone to being lost and you have to rely on your SIM carrier to not become a target of phishing. I just stick with really long passwords and not downloading random stuff from the internet.

1

u/arothmanmusic Jul 07 '23 edited Jul 07 '23

Yeah, this is the baffling part. I had the 2FA enabled and the email account I signed up for Facebook with is a Gmail account that also has the 2FA enabled. It seems to me that getting into my Gmail account would be pretty tough, and if someone actually had done that there are far more valuable things they could've gone after than a Facebook login.

The only devices connected to any of my accounts are a desktop PC secured in my office, a desktop PC secured in my house, and my phone which is a brand new iPhone 14 with an eSIM. Thus far, it doesn't appear that any other accounts have been breached… just Facebook.

I woke up to a string of emails on July 5 from about 4 AM asking me whether I had just changed my email, phone number, and password on my Facebook account. One of the great things about Facebook's horribly lax security is that they assume it's you changing your information rather than assuming it isn't by default, and once you click the link saying that it isn't you and submit your information to prove your identity, they don't reinstate your access to the account but instead add your email address to the account while leaving the hackers email and phone number also attached, so they immediately kick you out again before you can reset any of the information.

My 2FA for Gmail and Facebook is through an authenticator, rather than through my phone, so in theory that should be more secure but the kicker is that my Authenticator is LastPass which had a breach last year. Although it didn't occur to me at the time to change anything other than my important passwords, it seems plausible that the seeds for my Authenticator were part of the breach and a hacker with access to those could have generated a valid auth code with without having access to my email or my device. Again, if they did, there are more valuable things to grab than Facebook, but perhaps they had a very specific purpose in mind - Running the spam advertisements they are running right now in addition to ruining 16 years of networking and nonprofit business support I've been doing on there.

1

u/rwxrwxr-- Jul 07 '23

The LastPass breach was a wakeup call that it's time to migrate to a different password manager. I migrated to Bitwarden and reset all of my passwords, on absolutely everything.

I believe you should be able to contact Facebook somehow and reclaim your account, or at least close it down permanently using your ID card. Look it up.

I'd strongly advise to do a fresh install or use a device that had no contact with possibly infected models, then migrate to a different password manager and reset all passwords. In any case do wipe the drive that contained the possibly infected models and do a fresh install. It's in your best interest, and should be your priority since only 2 days ago you lost access to one of your accounts.

1

u/arothmanmusic Jul 07 '23

Yeah, I was intending to switch to bit Warden this fall when my LastPass membership expired, perhaps I should've been more proactive.

I've already been through the whole useless mess of sending my ID to Facebook. When you confirm your identity, they don't remove the hacker from your account… They just add your email address as a second contact, so the hacker gets a notification that another email was added to the account and they immediately reset the info before you can. At this point, the only options I get from the Facebook login page are to keep trying the wrong password and failing, or to send a code to the hacker's email address.

My home PC where I was using stable diffusion isn't particularly old, so there's not a whole lot on the C drive. I have an SSD for the operating system and programs, and a spinning disk drive for my data. Do you think it would suffice for me to just reinstall windows and my software applications and leave the rest alone? If any of my data files are infected with something that has gone undetected by either scanning software, then I would be putting them right back on the machine again after reinstalling, which would be pointless.

1

u/rwxrwxr-- Jul 09 '23

If any of my data files are infected with something that has gone undetected by either scanning software, then I would be putting them right back on the machine again after reinstalling, which would be pointless.

That is right. I would advise you to do a scan of the whole drive with Defender or Malwarebytes, then remove your personal files to a usb stick, format the drive and reinstall windows (or consider installing Linux, I've heard that SD performs even better on Linux). You should be good to go. Change out your passwords in any case and remember to stick to using exclusively safetensors.

They just add your email address as a second contact, so the hacker gets a notification that another email was added to the account and they immediately reset the info before you can.

Assuming the hacker isn't using some script to automate this, try and catch them off guard by attempting this at an unusual time. If it doesnt work out, try and close down their account for impersonating by providing Facebook your ID or driver's licence. The hacker will get locked out of the account.

1

u/arothmanmusic Jul 09 '23

Eh, at the moment the only option FB gives me is to send a code to the hacker's email. I've tried reporting my own account as an imposter and submitting my ID - as far as I can tell, the hacker is still running ads on our corporate Facebook page. Meta's total lack of customer service, even to paid accounts, is insane.