Forums Latest Members

IMPORTANT ALL READ , RockMasterMike - Account Compromised

  1. Rockmastermike Mar 7, 2018

    Posts
    543
    Likes
    5,483
    OF - my account has been hacked and I am "selling" watches - this is not me!!
    working with mod to get it straightened out
    Sincerely
     
  2. dsio Ash @ ΩF Staff Member Mar 7, 2018

    Posts
    26,989
    Likes
    32,704
    This is the third time we've seen this now in the FS section, can people please use unique passwords per site, and if you have an account on WUS, reset your password on all sites that you have used it on because its easy for people to pretend to be you everywhere since they were done over twice, once in 2016 and again in late 2017.

    red.jpg
     
    watchos and R3D9 like this.
  3. kidkimura Mar 7, 2018

    Posts
    602
    Likes
    1,524
    One suggestion for the mods:

    check new or reset password hashes vs the haveIbeenpwned api and reject any pw that matches.


    Might be good for any other work you build as well.
     
    kov and BenBagbag like this.
  4. cicindela Steve @ ΩF Staff Member Mar 7, 2018

    Posts
    15,047
    Likes
    23,791
    Guys this is a serious matter and not a place for jokes or non contributing posts

    Yellow.jpg
     
    watchos likes this.
  5. R3D9 Mar 7, 2018

    Posts
    1,288
    Likes
    3,310
    @dsio do you have a way to trigger a password reset for all users? Might be an idea, if possible?

    Also great is an automatic feature that forces a new password at set intervals.
     
  6. watchos Mar 7, 2018

    Posts
    255
    Likes
    732
    I never get tired of repeating this to everyone that will listed. Unique random passwords stored in an encrypted service like 1Password and if the services has it, have 2fa enabled. Rule of thumb: if you know your password(ie. can write it from memory), it's a bad password(or you are a genius).
     
    R3D9 likes this.
  7. Tuura990 Mar 7, 2018

    Posts
    41
    Likes
    135
    This is not a bad idea. I work, depending on certain factors I have to change passwords every 3 months.
     
    watchos likes this.
  8. cicindela Steve @ ΩF Staff Member Mar 7, 2018

    Posts
    15,047
    Likes
    23,791
    ,
     
  9. larryganz The cable guy Mar 8, 2018

    Posts
    2,808
    Likes
    8,198
    Many of us would not like this option.
     
  10. R3D9 Mar 9, 2018

    Posts
    1,288
    Likes
    3,310
    May I ask what specifically your objections would be?
     
  11. Kmart Mar 9, 2018

    Posts
    1,228
    Likes
    3,770
    No one likes forced password resets. I also have to change passwords essentially on a monthly basis at work and I can tell you it accomplishes nothing because people just reuse virtually the same passwords with the minimum amount of alterations necessary.

    People should be responsible for their own accounts. OF hasn't been compromised so there should be no reason to force every member to change their password. And not everybody has a WUS account.
     
  12. time flies Mar 9, 2018

    Posts
    1,225
    Likes
    4,549
    As one who "liked" @larryganz comment...i, to my perhaps convoluted way of thinking, believe i am best able to control the security for my accounts and don't really care to be forced to change according to another's schedule. I'm not sure it makes the whole any stronger. Maybe it's a " big brother thing" maybe it's accepting responsibility for ones actions. Any how. Thanks.

    Have fun
    kfw
     
  13. R3D9 Mar 9, 2018

    Posts
    1,288
    Likes
    3,310
    Both you and @Kmart make very valid points. Enough to bump me off the regular-interval idea.

    To your point about managing your own password - well, lax password management (not saying yours is) can have repercussions on more than just the individual, as we’ve seen with the case of @Rockmastermike having his password compromised.

    A one-time reset would have the effect of clearing the decks in order to make sure anyone potentially exposed to the WUS hack have changed their password. I’d hazard a guess that a meaningful percentage of OF members also have a WUS account. I’d further posit that a large percentage of them use a common password across websites.

    A small inconvenience for the greater good, is how I would frame it.

    As an aside, I’m curious to know from the mods if there is an account freeze feature when a member enters the wrong password more than X amount of times?
     
    time flies likes this.