# Questions:

**URL:** <https://boards.straightdope.com/t/questions/875>\
**Category:** About This Message Board\
**Created:** [February 25, 2000, 8:44pm UTC](https://boards.straightdope.com/t/questions/875 "2000-02-25T20:44:00Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![jab1](https://avatars.discourse-cdn.com/v4/letter/j/ee7513/32.png) [@jab1](https://boards.straightdope.com/u/jab1)\
**Post date:** [February 25, 2000, 8:44pm UTC](https://boards.straightdope.com/t/questions/875/1 "2000-02-25T20:44:00Z")

</div>

1. Why is the address now [boards.straightdope.com/](http://boards.straightdope.com/) ? Will the old addresses work?

2. When the Board was up on Wednesday, I changed my password. Should I change it yet again?

3. Has the FBI been notified? This WAS an interstate crime, you know.

* * *

\>\< DARWIN \>  
\_\_ **L\_\_\_L**

---

<div class="post-metadata">

**Author:** ![Drain\_Bead](https://avatars.discourse-cdn.com/v4/letter/d/e47774/32.png) [@Drain\_Bead](https://boards.straightdope.com/u/Drain_Bead)\
**Post date:** [February 25, 2000, 9:15pm UTC](https://boards.straightdope.com/t/questions/875/2 "2000-02-25T21:15:00Z")

</div>

1. My old bookmark has to be reloaded when I get to the page, and then it works. Don’t ask me.

2. In another thread, Melin said that some mod said it was best to be safe and change your PW again if you changed it at some point on the 23rd.

3. Where’s Konrad been? 😉

---

<div class="post-metadata">

**Author:** ![Arnold\_Winkelried](https://avatars.discourse-cdn.com/v4/letter/a/3d9bf3/32.png) [@Arnold\_Winkelried](https://boards.straightdope.com/u/Arnold_Winkelried)\
**Post date:** [February 25, 2000, 9:26pm UTC](https://boards.straightdope.com/t/questions/875/3 "2000-02-25T21:26:00Z")

</div>

> [@](#):
>
> Originally posted by Drain Bead:  
> 2. In another thread, Melin said that some mod said it was best to be safe and change your PW again if you changed it at some point on the 23rd.

**Say it ain’t so!!**

---

<div class="post-metadata">

**Author:** ![Ed\_Zotti](https://avatars.discourse-cdn.com/v4/letter/e/fbc32d/32.png) [@Ed\_Zotti](https://boards.straightdope.com/u/Ed_Zotti)\
**Post date:** [February 25, 2000, 10:30pm UTC](https://boards.straightdope.com/t/questions/875/4 "2000-02-25T22:30:00Z")

</div>

We got hacked. The hacker had access to everything on the whole damn server, including the password list. So unless you want somebody using your screen name to start posting obscene limericks in Gaelic, we advise changing your password. There’s an announcement in each forum that talks about this - click on it for detailed instructions if you’re not clear on the procedure.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/straightdope/original/2X/e/e489c3b7d8fce19c4b355dd4fc3f88cc39c34b87.png) [@system](https://boards.straightdope.com/u/system)\
**Post date:** [February 25, 2000, 10:41pm UTC](https://boards.straightdope.com/t/questions/875/5 "2000-02-25T22:41:00Z")

</div>

"There once was a woman from Kilkenny . . . "

-Melin

---

<div class="post-metadata">

**Author:** ![Arnold\_Winkelried](https://avatars.discourse-cdn.com/v4/letter/a/3d9bf3/32.png) [@Arnold\_Winkelried](https://boards.straightdope.com/u/Arnold_Winkelried)\
**Post date:** [February 25, 2000, 10:48pm UTC](https://boards.straightdope.com/t/questions/875/6 "2000-02-25T22:48:00Z")

</div>

Any word on whether or not we should change our password **again** if we changed it on the 23rd?

---

<div class="post-metadata">

**Author:** ![manhattan](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/manhattan/32/7_2.png) [@manhattan](https://boards.straightdope.com/u/manhattan)\
**Post date:** [February 25, 2000, 10:50pm UTC](https://boards.straightdope.com/t/questions/875/7 "2000-02-25T22:50:00Z")

</div>

**Arnold** , it is unclear to any of us whether the password file was re-accessed after the first outage, but changing your password is a 10-second operation that costs nothing. _Not_ changing it is a zero-second operation that potentially could be bad for you. I re-changed mine.

* * *

[Change Your Password, Please](http://204.95.48.199/cgi-bin/ubbcgi/ubbmisc.cgi?action=getannounce&ForumNumber=3&Start=2451545.99&End=2451911&Session=2451598.1854) and don’t use HTML, as it has been disabled

---

<div class="post-metadata">

**Author:** ![SterlingNorth](https://avatars.discourse-cdn.com/v4/letter/s/8dc957/32.png) [@SterlingNorth](https://boards.straightdope.com/u/SterlingNorth)\
**Post date:** [February 25, 2000, 10:54pm UTC](https://boards.straightdope.com/t/questions/875/8 "2000-02-25T22:54:00Z")

</div>

You’re saying they saw everything.

Should I change my email address also, to just be on the safe side.

* * *

Provided that, by the time somebody responds to this, I would have already changed the address. But I’d like to know if I’m being too paranoid.

* * *

I will not be pushed, filed, stamped, briefed, debriefed, or numbered. My life is my own. You won’t hold me!"  
–Matrix

---

<div class="post-metadata">

**Author:** ![jab1](https://avatars.discourse-cdn.com/v4/letter/j/ee7513/32.png) [@jab1](https://boards.straightdope.com/u/jab1)\
**Post date:** [February 26, 2000, 12:08am UTC](https://boards.straightdope.com/t/questions/875/9 "2000-02-26T00:08:00Z")

</div>

Okay, I changed my password again. But I don’t think I need to change my email adress because I use a different password there. I use different passwords EVERYWHERE.

If you think you need to change your password every time you post, I’m pretty sure you’re over-reacting. 😉

On the other hand, paranoia is justified if they really are out to get you. 🙂

* * *

\>\< DARWIN \>  
\_\_ **L\_\_\_L**

---

<div class="post-metadata">

**Author:** ![Arnold\_Winkelried](https://avatars.discourse-cdn.com/v4/letter/a/3d9bf3/32.png) [@Arnold\_Winkelried](https://boards.straightdope.com/u/Arnold_Winkelried)\
**Post date:** [February 26, 2000, 12:22am UTC](https://boards.straightdope.com/t/questions/875/10 "2000-02-26T00:22:00Z")

</div>

> [@](#):
>
> Originally posted by manhattan:  
> **Arnold** , it is unclear to any of us whether the password file was re-accessed after the first outage, but changing your password is a 10-second operation that costs nothing

Except that I’m the kind of idiot that uses the same password everywhere, so I went ahead and spent an hour changing all my passwords. Now I have to go do it again!?! :mad:

---

<div class="post-metadata">

**Author:** ![manhattan](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/manhattan/32/7_2.png) [@manhattan](https://boards.straightdope.com/u/manhattan)\
**Post date:** [February 26, 2000, 12:28am UTC](https://boards.straightdope.com/t/questions/875/11 "2000-02-26T00:28:00Z")

</div>

Nah. Just ours. Before you do it, kill the cookies (in the preferences screen). When you’ve changed it, go back to preferences and choose the option to store the username and password. When you post, the password should fill itself in. Then you don’t have to remember it at all. You just have to write it down somewhere so you can re-enter it if you or the board has a cookie problem in the future.

## **Sterling** , I don’t think you have to go change your email addy, but if you used the same password for the email and the board, you will want to change the password. Also, if you start getting any weird emails, let us know.

[Change Your Password, Please](http://204.95.48.199/cgi-bin/ubbcgi/ubbmisc.cgi?action=getannounce&ForumNumber=3&Start=2451545.99&End=2451911&Session=2451598.1854) and don’t use HTML, as it has been disabled

---

<div class="post-metadata">

**Author:** ![Arnold\_Winkelried](https://avatars.discourse-cdn.com/v4/letter/a/3d9bf3/32.png) [@Arnold\_Winkelried](https://boards.straightdope.com/u/Arnold_Winkelried)\
**Post date:** [February 26, 2000, 12:45am UTC](https://boards.straightdope.com/t/questions/875/12 "2000-02-26T00:45:00Z")

</div>

manhattan, what I mean is that on the 23rd I changed my password for SDMB, but I also changed the password that I use (for example) to order books from a large on-line merchant, so if someone could guess my username with the large on-line merchant, they would know my password, since the password I use for SDMB is the same password that I use for any web-based account. Though the chances of someone going to all that trouble are pretty slim.  
Again, :mad:

---

<div class="post-metadata">

**Author:** ![manhattan](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/manhattan/32/7_2.png) [@manhattan](https://boards.straightdope.com/u/manhattan)\
**Post date:** [February 26, 2000, 1:29am UTC](https://boards.straightdope.com/t/questions/875/13 "2000-02-26T01:29:00Z")

</div>

Ooh. That’s more serious indeed. Lemme ask.

* * *

[Change Your Password, Please](http://204.95.48.199/cgi-bin/ubbcgi/ubbmisc.cgi?action=getannounce&ForumNumber=3&Start=2451545.99&End=2451911&Session=2451598.1854) and don’t use HTML, as it has been disabled

---

<div class="post-metadata">

**Author:** ![tanstaafl](https://avatars.discourse-cdn.com/v4/letter/t/ba8739/32.png) [@tanstaafl](https://boards.straightdope.com/u/tanstaafl)\
**Post date:** [February 26, 2000, 11:40pm UTC](https://boards.straightdope.com/t/questions/875/14 "2000-02-26T23:40:00Z")

</div>

I know how you feel Arnold. I just finished changing my password on 17 sites. I guess I should be using different passwords everywhere but… How the heck am I supposed to remember a _different_ password for _every_ site I access. (23, if I found all of them, plus my two ISPs and two personal domains)

* * *

“Drink your coffee! Remember, there are people sleeping in China.”

[dennis@mountaindiver.com](mailto:dennis@mountaindiver.com)  
[www.mountaindiver.com](http://www.mountaindiver.com)

---

<div class="post-metadata">

**Author:** ![TubaDiva](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/tubadiva/32/507_2.png) [@TubaDiva](https://boards.straightdope.com/u/TubaDiva)\
**Post date:** [February 27, 2000, 6:26am UTC](https://boards.straightdope.com/t/questions/875/15 "2000-02-27T06:26:00Z")

</div>

It’s never a good idea to have the same password on everything you use.

Think of it this way: a potential hacker has a piece of information about you. If that information is good in more than one place, then your security is STILL compromised.

I’d be changing those passwords if I were you.

your humble TubaDiva

---

<div class="post-metadata">

**Author:** ![Arnold\_Winkelried](https://avatars.discourse-cdn.com/v4/letter/a/3d9bf3/32.png) [@Arnold\_Winkelried](https://boards.straightdope.com/u/Arnold_Winkelried)\
**Post date:** [February 27, 2000, 4:40pm UTC](https://boards.straightdope.com/t/questions/875/16 "2000-02-27T16:40:00Z")

</div>

> [@](#):
>
> Originally posted by tanstaafl:  
> \*\*I know how you feel Arnold. I just finished changing my password on 17 sites. I guess I should be using different passwords everywhere but… How the heck am I supposed to remember a _different_ password for _every_ site I access. (23, if I found all of them, plus my two ISPs and two personal domains)  
> \*\*

That’s exactly the way I feel! I also have “accounts” at a lot of web sites! Plus I go to some websites and sign up to see what it’s like, and then I might decide it’s not that interesting and not go there for a couple of months. But I used to like the fact that when I returned I would know my password.

I guess what I will do is divide my web accounts into two groups:

a) Those often used and those having financial information;  
b) Those that I join for a “lark.”

The ones in group a) will be maintained in a list and the password frequently changed.

---

<div class="post-metadata">

**Author:** ![smw](https://avatars.discourse-cdn.com/v4/letter/s/ac8455/32.png) [@smw](https://boards.straightdope.com/u/smw)\
**Post date:** [February 29, 2000, 6:09am UTC](https://boards.straightdope.com/t/questions/875/17 "2000-02-29T06:09:00Z")

</div>

How was this cracker able to grab passwords? They’re not stored in cleartext, are they? Don’t you use a one-way encryption algorithm?

---

<div class="post-metadata">

**Author:** ![smw](https://avatars.discourse-cdn.com/v4/letter/s/ac8455/32.png) [@smw](https://boards.straightdope.com/u/smw)\
**Post date:** [February 29, 2000, 6:13am UTC](https://boards.straightdope.com/t/questions/875/18 "2000-02-29T06:13:00Z")

</div>

(answering my own question) I see passwords _are_ still stored in cleartext. I’d recommend an immediate change to this policy; store passwords encrypted; allow users to request a password change, but not to request their password.

---

<div class="post-metadata">

**Author:** ![TubaDiva](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/tubadiva/32/507_2.png) [@TubaDiva](https://boards.straightdope.com/u/TubaDiva)\
**Post date:** [February 28, 2000, 8:02pm UTC](https://boards.straightdope.com/t/questions/875/19 "2000-02-28T20:02:00Z")

</div>

The Reader is in discussion with UBB over the software, let me put it like that.

your humble TubaDiva  
Administrator  
The Straight Dope
