Page 1 of 1

why is the forum password requirement so strict?

Posted: Mon Nov 14, 2011 1:15 am
by danny_galaga
Dagnammit! Pretty much all other forums I'm on share the same password so I can remember it. But because this forum has stricter rules I have to use something else. I think it's actual stricter than my bank account! So of course I keep forgetting this password and have to send off for a new one. Of course I haven't been on here in ages either (been too busy to play Oolite :( ) so hopefully I'll remember this time :lol:

Re: why is the forum password requirement so strict?

Posted: Mon Nov 14, 2011 1:28 am
by Cody
Possibly because this forum was hacked last new year's eve. The rules may have been tightened after the updated BB was installed.

Re: why is the forum password requirement so strict?

Posted: Mon Nov 14, 2011 2:00 am
by danny_galaga
El Viejo wrote:
Possibly because this forum was hacked last new year's eve. The rules may have been tightened after the updated BB was installed.
Damn hackorz, roonin' our fun :evil:

Re: why is the forum password requirement so strict?

Posted: Mon Nov 14, 2011 3:55 am
by Yah-Ta-Hey
Be glad that these fine fellows have cinched the belly band on the forum.... I am a security person in IT and do you know how hard it is to encrypt the local smoke signals coming out of the chief's Hogan?????

I am surprised that they don't have a 90 day rotation so hackers have a harder time getting in.

Re: why is the forum password requirement so strict?

Posted: Mon Nov 14, 2011 8:22 am
by Eric Walch
danny_galaga wrote:
Dagnammit! Pretty much all other forums I'm on share the same password so I can remember it.
Hmm, when one of those sites gets hacked, it means they have access to all your other accounts. And because of lot of people re-use passwords, hackers are prepared for that.

I must say that I don't know my current Oolite password at all. My browser does that for me :P . So anyone that hacks my computers main password, has access to everything..... (except bank account passwords, those I don't even trust to my computer)

Re: why is the forum password requirement so strict?

Posted: Mon Nov 14, 2011 8:54 am
by Micha
Why the world at large has failed to protect everything with PKI is beyond me. We -have- the technology for somewhat secure single sign on. And have had it for a long time. Passwords are not a particularly good way to protect anything, especially if you need a different one for each service and, as has been suggested, you have to change it regularly.

I liked this relevant comic: http://xkcd.com/936/

Re: why is the forum password requirement so strict?

Posted: Mon Nov 14, 2011 12:35 pm
by danny_galaga
Eric Walch wrote:
danny_galaga wrote:
Dagnammit! Pretty much all other forums I'm on share the same password so I can remember it.
Hmm, when one of those sites gets hacked, it means they have access to all your other accounts. And because of lot of people re-use passwords, hackers are prepared for that.

I must say that I don't know my current Oolite password at all. My browser does that for me :P . So anyone that hacks my computers main password, has access to everything..... (except bank account passwords, those I don't even trust to my computer)
Yeah, so if I start espousing the virtues of Viagra on any forum I'm on, I've been hacked! I don't use the same passwords for critical stuff like bank accounts (like you, not on my computer), etc...

http://youtu.be/_JNGI1dI-e8