The Straight Dope

Go Back   Straight Dope Message Board > Main > About This Message Board

Reply
 
Thread Tools Display Modes
  #1  
Old 02-25-2000, 02:44 PM
jab1 jab1 is offline
Guest
 
Join Date: Sep 1999
1) Why is the address now boards.straightdope.com/ ? Will the old addresses work?

2) When the Board was up on Wednesday, I changed my password. Should I change it yet again?

3) Has the FBI been notified? This WAS an interstate crime, you know.

------------------
>< DARWIN >
____L___L__
Reply With Quote
Advertisements  
  #2  
Old 02-25-2000, 03:15 PM
Drain Bead Drain Bead is online now
Guest
 
Join Date: Mar 1999
1. My old bookmark has to be reloaded when I get to the page, and then it works. Don't ask me.

2. In another thread, Melin said that some mod said it was best to be safe and change your PW again if you changed it at some point on the 23rd.

3. Where's Konrad been?
Reply With Quote
  #3  
Old 02-25-2000, 03:26 PM
Arnold Winkelried Arnold Winkelried is offline
Charter Member
Charter Member
 
Join Date: Oct 1999
Location: Irvine, California, USA
Posts: 14,822
Quote:
Originally posted by Drain Bead:
2. In another thread, Melin said that some mod said it was best to be safe and change your PW again if you changed it at some point on the 23rd.
Say it ain't so!!
Reply With Quote
  #4  
Old 02-25-2000, 04:30 PM
Ed Zotti Ed Zotti is offline
Gormless Wienie
Administrator
 
Join Date: Feb 1999
Posts: 1,672
We got hacked. The hacker had access to everything on the whole damn server, including the password list. So unless you want somebody using your screen name to start posting obscene limericks in Gaelic, we advise changing your password. There's an announcement in each forum that talks about this - click on it for detailed instructions if you're not clear on the procedure.
Reply With Quote
  #5  
Old 02-25-2000, 04:41 PM
Guest
 
"There once was a woman from Kilkenny . . . "

-Melin
Reply With Quote
  #6  
Old 02-25-2000, 04:48 PM
Arnold Winkelried Arnold Winkelried is offline
Charter Member
Charter Member
 
Join Date: Oct 1999
Location: Irvine, California, USA
Posts: 14,822
Any word on whether or not we should change our password again if we changed it on the 23rd?
Reply With Quote
  #7  
Old 02-25-2000, 04:50 PM
manhattan manhattan is offline
Charter Member
Charter Member
 
Join Date: Aug 1999
Posts: 9,127
Arnold, it is unclear to any of us whether the password file was re-accessed after the first outage, but changing your password is a 10-second operation that costs nothing. Not changing it is a zero-second operation that potentially could be bad for you. I re-changed mine.

------------------
Change Your Password, Please and don't use HTML, as it has been disabled
Reply With Quote
  #8  
Old 02-25-2000, 04:54 PM
SterlingNorth SterlingNorth is offline
Guest
 
Join Date: Mar 1999
You're saying they saw everything.

Should I change my email address also, to just be on the safe side.

-------
Provided that, by the time somebody responds to this, I would have already changed the address. But I'd like to know if I'm being too paranoid.

------------------
I will not be pushed, filed, stamped, briefed, debriefed, or numbered. My life is my own. You won't hold me!"
--Matrix
Reply With Quote
  #9  
Old 02-25-2000, 06:08 PM
jab1 jab1 is offline
Guest
 
Join Date: Sep 1999
Okay, I changed my password again. But I don't think I need to change my email adress because I use a different password there. I use different passwords EVERYWHERE.

If you think you need to change your password every time you post, I'm pretty sure you're over-reacting.

On the other hand, paranoia is justified if they really are out to get you.

------------------
>< DARWIN >
____L___L__
Reply With Quote
  #10  
Old 02-25-2000, 06:22 PM
Arnold Winkelried Arnold Winkelried is offline
Charter Member
Charter Member
 
Join Date: Oct 1999
Location: Irvine, California, USA
Posts: 14,822
Quote:
Originally posted by manhattan:
Arnold, it is unclear to any of us whether the password file was re-accessed after the first outage, but changing your password is a 10-second operation that costs nothing
Except that I'm the kind of idiot that uses the same password everywhere, so I went ahead and spent an hour changing all my passwords. Now I have to go do it again!?!
Reply With Quote
  #11  
Old 02-25-2000, 06:28 PM
manhattan manhattan is offline
Charter Member
Charter Member
 
Join Date: Aug 1999
Posts: 9,127
Nah. Just ours. Before you do it, kill the cookies (in the preferences screen). When you’ve changed it, go back to preferences and choose the option to store the username and password. When you post, the password should fill itself in. Then you don’t have to remember it at all. You just have to write it down somewhere so you can re-enter it if you or the board has a cookie problem in the future.

Sterling, I don’t think you have to go change your email addy, but if you used the same password for the email and the board, you will want to change the password. Also, if you start getting any weird emails, let us know.


------------------
Change Your Password, Please and don't use HTML, as it has been disabled
Reply With Quote
  #12  
Old 02-25-2000, 06:45 PM
Arnold Winkelried Arnold Winkelried is offline
Charter Member
Charter Member
 
Join Date: Oct 1999
Location: Irvine, California, USA
Posts: 14,822
manhattan, what I mean is that on the 23rd I changed my password for SDMB, but I also changed the password that I use (for example) to order books from a large on-line merchant, so if someone could guess my username with the large on-line merchant, they would know my password, since the password I use for SDMB is the same password that I use for any web-based account. Though the chances of someone going to all that trouble are pretty slim.
Again,
Reply With Quote
  #13  
Old 02-25-2000, 07:29 PM
manhattan manhattan is offline
Charter Member
Charter Member
 
Join Date: Aug 1999
Posts: 9,127
Ooh. That’s more serious indeed. Lemme ask.

------------------
Change Your Password, Please and don't use HTML, as it has been disabled
Reply With Quote
  #14  
Old 02-26-2000, 05:40 PM
tanstaafl tanstaafl is offline
Charter Member
 
Join Date: Mar 1999
Location: ATL
Posts: 3,044
I know how you feel Arnold. I just finished changing my password on 17 sites. I guess I should be using different passwords everywhere but... How the heck am I supposed to remember a different password for every site I access. (23, if I found all of them, plus my two ISPs and two personal domains)

------------------
"Drink your coffee! Remember, there are people sleeping in China."

dennis@mountaindiver.com
www.mountaindiver.com
Reply With Quote
  #15  
Old 02-27-2000, 12:26 AM
TubaDiva TubaDiva is offline
Mother's Little Helper
Administrator
 
Join Date: Mar 1999
Location: In the land of OO-bla-dee
Posts: 9,429
It's never a good idea to have the same password on everything you use.

Think of it this way: a potential hacker has a piece of information about you. If that information is good in more than one place, then your security is STILL compromised.

I'd be changing those passwords if I were you.

your humble TubaDiva
Reply With Quote
  #16  
Old 02-27-2000, 10:40 AM
Arnold Winkelried Arnold Winkelried is offline
Charter Member
Charter Member
 
Join Date: Oct 1999
Location: Irvine, California, USA
Posts: 14,822
Quote:
Originally posted by tanstaafl:
I know how you feel Arnold. I just finished changing my password on 17 sites. I guess I should be using different passwords everywhere but... How the heck am I supposed to remember a different password for every site I access. (23, if I found all of them, plus my two ISPs and two personal domains)
That's exactly the way I feel! I also have "accounts" at a lot of web sites! Plus I go to some websites and sign up to see what it's like, and then I might decide it's not that interesting and not go there for a couple of months. But I used to like the fact that when I returned I would know my password.

I guess what I will do is divide my web accounts into two groups:

a) Those often used and those having financial information;
b) Those that I join for a "lark."

The ones in group a) will be maintained in a list and the password frequently changed.
Reply With Quote
  #17  
Old 02-28-2000, 02:02 PM
TubaDiva TubaDiva is offline
Mother's Little Helper
Administrator
 
Join Date: Mar 1999
Location: In the land of OO-bla-dee
Posts: 9,429
The Reader is in discussion with UBB over the software, let me put it like that.

your humble TubaDiva
Administrator
The Straight Dope
Reply With Quote
  #18  
Old 02-29-2000, 12:09 AM
smw smw is offline
Guest
 
Join Date: Jul 1999
How was this cracker able to grab passwords? They're not stored in cleartext, are they? Don't you use a one-way encryption algorithm?
Reply With Quote
  #19  
Old 02-29-2000, 12:13 AM
smw smw is offline
Guest
 
Join Date: Jul 1999
(answering my own question) I see passwords *are* still stored in cleartext. I'd recommend an immediate change to this policy; store passwords encrypted; allow users to request a password change, but not to request their password.
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 11:23 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.

Send questions for Cecil Adams to: cecil@chicagoreader.com

Send comments about this website to: webmaster@straightdope.com

Terms of Use / Privacy Policy

Advertise on the Straight Dope!
(Your direct line to thousands of the smartest, hippest people on the planet, plus a few total dipsticks.)

Publishers - interested in subscribing to the Straight Dope?
Write to: sdsubscriptions@chicagoreader.com.

Copyright © 2013 Sun-Times Media, LLC.