Page 1 of 2 12 LastLast
Results 1 to 25 of 39

Thread: PASSWORD CHANGES

  1. #1
    Moderator Duncan Glenday's Avatar
    Join Date
    Apr 2003
    Location
    Frederick, MD
    Posts
    2,104

    PASSWORD CHANGES

    We've had discussions with our ISP, and we believe we have the hacking situation resolved. Specifically:

    1). They have migrated the site to a slightly different version of the software. You shouldn't see any difference. (If you saw a notice sayinbg "Alert: The forums are currently turned off!" - no need for concern. That was done during the upgrade.)

    2). It is HIGHLY recommended that EVERYONE change their passwords.

    I have set a parameter that will force everyone to change their password (at least once) in the next 24 hours ... and I'll turn the parameter off again soon. Sorry about the major PITA. In addition we've set a parameter tat will force all users to change passwords every 6 months.

    3). If you use more than one email address, it would be advisable for you to change the email in your PE profile to one of your alternates. This is NOT a critically necessary step ... it's simply recommended as a caution.

    4). Another non-essential step, but suggested in the interest of caution: If you have used the same password on PE as you use on your email system, it would be prudent to change that email system's password as well.

    Again - DON'T PANIC - but please follow these recommendations.

    These steps reflect the best practices used in all responsible sites, and they have been recommended to help secure your data.
    Regards,

    Duncan

  2. #2
    I'm a bit surprised the password reset form here doesn't use HTTPS.

    So if you change your password here, absolutely do not change it to a password you use anywhere else (a good practice in general, but especially important in the case of insecure transmission).

  3. #3
    Moderator Duncan Glenday's Avatar
    Join Date
    Apr 2003
    Location
    Frederick, MD
    Posts
    2,104
    I'm busy purchasing an SSL certificate, and the whole site will be "https" when that is done.

    Meantime, if you're concerned, feel free to install "HTTPS Everywhere" : https://www.eff.org/https-everywhere - it will enable you to have HTTPS / SSL security.
    Regards,

    Duncan

  4. #4
    Duncan - apologies for the slight pushback...could you wait to force the password reset until the site is secure? I don't want to have to install HTTPS everywhere on my work machine just so I can safely reset my PE password. At this point I'm more inclined to delete my account and re-create it once things are sorted out.

    Again, apologies...but Sean's right. I'm not really OK with a password change that isn't secure.
    If you're actually reading this then chances are you already have my last album but if NOT and you're curious:
    https://battema.bandcamp.com/

    Also, Ephemeral Sun: it's a thing and we like making things that might be your thing: https://ephemeralsun.bandcamp.com

  5. #5
    ALL ACCESS Gruno's Avatar
    Join Date
    Jan 2006
    Location
    Dio, Alabama
    Posts
    3,173
    A mass email message would have been good alerting us of this password change. With the recent hacking taking place, once I got to PE and the first message was to force me to change my password, I was leery of doing so. Since PE was down last night, it also raised my suspicion.

  6. #6
    Moderator Duncan Glenday's Avatar
    Join Date
    Apr 2003
    Location
    Frederick, MD
    Posts
    2,104
    'K
    Regards,

    Duncan

  7. #7
    Moderator Duncan Glenday's Avatar
    Join Date
    Apr 2003
    Location
    Frederick, MD
    Posts
    2,104
    The parameter has been reset ... but watch this space.
    Regards,

    Duncan

  8. #8
    OK, all updated.
    G.A.S -aholic

  9. #9
    Member Garyhead's Avatar
    Join Date
    Jun 2011
    Location
    Washington State
    Posts
    1,684
    Quote Originally Posted by Gruno View Post
    A mass email message would have been good alerting us of this password change. With the recent hacking taking place, once I got to PE and the first message was to force me to change my password, I was leery of doing so. Since PE was down last night, it also raised my suspicion.
    Yup.....me too.....advanced warning would have been good
    The Ice Cream Lady Wet her drawers........To see you in the Passion Playyyy eeee - I. Anderson

    "It's kind of like deciding not to date a beautiful blonde anymore because she farted." - Top Cat

    I was expecting to be kinda meh, but it made my nips stiffen - Jerjo

    (Zamran) "that fucking thing man . . . it sits there on my wall like a broken clock " - Helix

    Social Media is the "Toilet" of the Internet - Lady Gaga

  10. #10
    I tried installing HTTPS Everywhere as an extension in Chrome, and while it seems to work for other sites, it goes inactive when I try to use it with Prog Ears. Is it just my ignorance of the tool? Anyone able to make that work?
    If you're actually reading this then chances are you already have my last album but if NOT and you're curious:
    https://battema.bandcamp.com/

    Also, Ephemeral Sun: it's a thing and we like making things that might be your thing: https://ephemeralsun.bandcamp.com

  11. #11
    Member interbellum's Avatar
    Join Date
    Sep 2014
    Location
    Xymphonia-city
    Posts
    4,644
    Quote Originally Posted by Gruno View Post
    A mass email message would have been good alerting us of this password change. With the recent hacking taking place, once I got to PE and the first message was to force me to change my password, I was leery of doing so. Since PE was down last night, it also raised my suspicion.
    That would indeed have been better, especially because we did get such a mail about the hacking.
    To be shure it was a message from PE I locked out first, then locked in and got the same message, so I wasn't worried anymore.

  12. #12
    Man of repute progmatist's Avatar
    Join Date
    Nov 2012
    Location
    Mesa, Arizona
    Posts
    3,828
    Now I have to remember something other than "password123."
    "Well my son, life is like a beanstalk, isn't it?"--Dalai Lama

  13. #13
    KrimsonCat MissKittysMom's Avatar
    Join Date
    Nov 2012
    Location
    Cary, NC
    Posts
    111
    A mass email would have missed me, since the email address for my account here no longer exists. Also, the forced password change let me re-use my old password, which is fine for me since it's useless without a meaningful email, but really not so good security-wise.
    I think the subtext is rapidly becoming text.

  14. #14
    Member helicase's Avatar
    Join Date
    Nov 2012
    Location
    Netherlands
    Posts
    245
    Quote Originally Posted by Duncan Glenday View Post
    I'm busy purchasing an SSL certificate, and the whole site will be "https" when that is done.
    Wouldn't a free Let's Encrypt certificate work?

  15. #15
    Quote Originally Posted by battema View Post
    I tried installing HTTPS Everywhere as an extension in Chrome, and while it seems to work for other sites, it goes inactive when I try to use it with Prog Ears. Is it just my ignorance of the tool? Anyone able to make that work?
    have you tried Tor? it's a better option than a redirect
    i.ain't.dead.irock

  16. #16
    Member zravkapt's Avatar
    Join Date
    Nov 2012
    Location
    canada
    Posts
    280
    I already changed my password because of the hack....I have to change it again?
    The truth will set you free, but first it will piss you off

  17. #17
    Moderator Duncan Glenday's Avatar
    Join Date
    Apr 2003
    Location
    Frederick, MD
    Posts
    2,104
    Quote Originally Posted by MissKittysMom View Post
    A mass email would have missed me, since the email address for my account here no longer exists. Also, the forced password change let me re-use my old password, which is fine for me since it's useless without a meaningful email, but really not so good security-wise.
    We've already changed that. Going forward, you won't be able to re-use a password you've used for [xxx] days. But the count from fay 1 to day [xxx] only starts now.

    Quote Originally Posted by proggosaurus View Post
    have you tried Tor? it's a better option than a redirect


    Quote Originally Posted by zravkapt View Post
    I already changed my password because of the hack....I have to change it again?
    No!
    Regards,

    Duncan

  18. #18
    Duncan - just for saying: thanks for chasing down this stuff. Can't be fun, but it is really appreciated
    If you're actually reading this then chances are you already have my last album but if NOT and you're curious:
    https://battema.bandcamp.com/

    Also, Ephemeral Sun: it's a thing and we like making things that might be your thing: https://ephemeralsun.bandcamp.com

  19. #19
    Quote Originally Posted by Gruno View Post
    A mass email message would have been good alerting us of this password change. With the recent hacking taking place, once I got to PE and the first message was to force me to change my password, I was leery of doing so. Since PE was down last night, it also raised my suspicion.
    Same here, I asked on Facebook about it, but I wasn't sure if this was part of the hacking thing or not.

  20. #20
    Quote Originally Posted by battema View Post
    Duncan - just for saying: thanks for chasing down this stuff. Can't be fun, but it is really appreciated
    Seconded!

  21. #21
    ALL ACCESS Gruno's Avatar
    Join Date
    Jan 2006
    Location
    Dio, Alabama
    Posts
    3,173
    +1

  22. #22
    Parrots Ripped My Flesh Dave (in MA)'s Avatar
    Join Date
    Nov 2012
    Location
    42°09′30″N 71°08′43″W
    Posts
    6,295
    Thanks. I just changed my password to 4321 instead of 1234.

  23. #23
    Member Garyhead's Avatar
    Join Date
    Jun 2011
    Location
    Washington State
    Posts
    1,684
    So can we blame all these Yes Threads on hacked passwords?
    The Ice Cream Lady Wet her drawers........To see you in the Passion Playyyy eeee - I. Anderson

    "It's kind of like deciding not to date a beautiful blonde anymore because she farted." - Top Cat

    I was expecting to be kinda meh, but it made my nips stiffen - Jerjo

    (Zamran) "that fucking thing man . . . it sits there on my wall like a broken clock " - Helix

    Social Media is the "Toilet" of the Internet - Lady Gaga

  24. #24
    Quote Originally Posted by Dave (in MA) View Post
    Thanks. I just changed my password to 4321 instead of 1234.
    $WørDʄ1șн
    Confirmed Bachelors: the dramedy hit of 1883...

  25. #25
    Thanks for this Duncan.
    Hey, here's a thing. Since the password change, the default on my telephone (iPhone 5) for PE is now a kinda 'computer website' version of the forum, which requires me making everything bigger and doesn't fit nicely on the screen.
    Has anyone else experienced this? Is there a thing where I can change the parameters back?
    Sorry if I'm acting like a total Luddite, it's because I largely am one...

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •