Page 1 of 1

if i wanted it i'd ask

Posted: Mon Dec 01, 2008 3:00 pm
by Kit-Fox
Now I know that the forum has recently has a few problems with regards towards security however forcing everyone to change their password isnt really the way to go and just really peeves off those of us who take time to pick a relatively secure password for such a site/account.

You couldnt I dunno use an announcement or a mass PM, no you had to annoy those of us who actually understand computer/online security.

needless to say not pleased, there are many ways that security can be enhanced at the user level and using the blunt instrument of forced mass password changing isnt it

Re: if i wanted it i'd ask

Posted: Mon Dec 01, 2008 3:16 pm
by DaDigi
Feel free to change your password back to what it was.

The general idea of what happened, AFAIK, the hacked persons were registered on another forum. Their passwords were decrypted. The "hackzorz" then used the decrypted passwords to gain access to the person's account on these forums. As a vast majority of users use simple passwords, it's better to be safe rather then sorry and an administrator (not sure which) decided to force a password change.

Again, feel free to restore your previous password. If your account is compromised, then don't complain. It was done for your protection only.

Re: if i wanted it i'd ask

Posted: Mon Dec 01, 2008 3:21 pm
by buck
Forums Forum, And forum enforced the change. Which i agreed with, if you knew the full extent of the issue we have been dealing with for the past few weeks, Youd understand why we had to do that.

As it happens i feel the matter has been resolved as far as top level security is concerned. Which is a good thing. Changeing your password is a precaution, if you choose not to do it (or change it back) and your account gets hacked, we will of course, help you out. However you are a hell of a lot less likely to be hacked if your password is changed, Agreed? :)

Re: if i wanted it i'd ask

Posted: Mon Dec 01, 2008 4:03 pm
by Jack
Kit-Fox wrote:Now I know that the forum has recently has a few problems with regards towards security however forcing everyone to change their password isnt really the way to go and just really peeves off those of us who take time to pick a relatively secure password for such a site/account.

You couldnt I dunno use an announcement or a mass PM, no you had to annoy those of us who actually understand computer/online security.

needless to say not pleased, there are many ways that security can be enhanced at the user level and using the blunt instrument of forced mass password changing isnt it

Oh boo fracking hoo, you've been faced with the very MINOR inconvenience of having to change your password. :roll:


Why don't you go cry to your mommy? I'm sure she'd care a whole hell of a lot more then we do. Gawd if having to change my password was the only inconvenience to beset me during this whole mess...

Re: if i wanted it i'd ask

Posted: Mon Dec 01, 2008 6:00 pm
by Kit-Fox
And once again by your rude and abrasive manner Jack you prove you are unworthy of acting in any kind of moderator capacity. EDIT: Fine your account was affected, you have to take that out on me?? Its not my fault

But leaving that aside lets just address the issue at hand shall we?

Forcing people to change their passwords will not make most users choose an appropiate password nor will they treat it as sensitive information simply because they had to change it.

It wont stop people from using the same password they use elsewhere

And its annoying to those of us who know to use appropiate passwords and to treat them as sensitive information as well as using a wide variety of passwords.

User education via announcements or by the mass PM system detailing how to choose a password, how to keep it safe and warning people that using the same password for several accounts is a very unwise idea would be more helpful & more people might be encouraged to use the information imparted in such messages.

Forced mass changings are just a blunt tool and a cheap way of avoiding the issue, as you can bet it will happen again in the same way because of a users stupidity.

Oh & Buck if I lost control of my account I wouldnt whine as it would be my fault, I wouldnt expect to gain control of it back again either. I would inform the forum involved so they were aware but then go on to make a new accoutn with a different name & password & email combination to hopefully prevent such an event happening again. But as I said it would be wholly my fault for divulging my password or for using the same password elsewhere.

Re: if i wanted it i'd ask

Posted: Mon Dec 01, 2008 6:12 pm
by Solus
Kit-Fox wrote:And once again by your rude and abrasive manner Jack you prove you are unworthy of acting in any kind of moderator capacity.
sure, because hes a little frustrated about losing 14000 posts and putting up with someone being as self righteous and arrogant as yourself warrants attacks on his status?

But leaving that aside lets just address the issue at hand shall we?

Forcing people to change their passwords will not make most users choose an appropiate password nor will they treat it as sensitive information simply because they had to change it.

It wont stop people from using the same password they use elsewhere

And its annoying to those of us who know to use appropiate passwords and to treat them as sensitive information as well as using a wide variety of passwords.

User education via announcements or by the mass PM system detailing how to choose a password, how to keep it safe and warning people that using the same password for several accounts is a very unwise idea would be more helpful & more people might be encouraged to use the information imparted in such messages.
and those at risk might ignore it? ever think of that? seriously. just make another password and stop whining.

Forced mass changings are just a blunt tool and a cheap way of avoiding the issue, as you can bet it will happen again in the same way because of a users stupidity.
avoided the issue? someone used passwords to infiltrate accounts. changing the password on accounts removes one tool for infiltration. duh. sure there are other ways to get to accounts etc but just because you follow certain standards doesnt mean that others do. again, duh.

Oh & Buck if I lost control of my account I wouldnt whine as it would be my fault, I wouldnt expect to gain control of it back again either. I would inform the forum involved so they were aware but then go on to make a new accoutn with a different name & password & email combination to hopefully prevent such an event happening again. But as I said it would be wholly my fault for divulging my password or for using the same password elsewhere.
a lot of people WOULD care about there accounts. again, trying to confine others to your views and or logic. bravo.


and as buck said FORUM aka ADMIN JASON said it should be done so its done. privately owned forum, owners rules.

~soul
'oopses'

Re: if i wanted it i'd ask

Posted: Mon Dec 01, 2008 6:32 pm
by Mordack
Regardless of how blunt an instrument it is, it does help to safeguard the forums in some small way.

I don't want to sound cynical, or like I'm belittling our playerbase, but I don't think a mass PM or a sticky topic would have been especially effective. Sometimes you have to lead a horse to water before it'll drink; and I find the same is especially true of people.

I think most people are willing to undergo a little convenience in order to prevent the mass spamming, and high profile account hacking, which went on in the none too distant past. I'm sorry if you were especially annoyed, though.

Re: if i wanted it i'd ask

Posted: Mon Dec 01, 2008 6:36 pm
by Kit-Fox
uh-huh, you know when this happens again further on down the line because of the same reasons i'll remember what was said here & laugh and point


/edit: nevermind, no one will get it anyways

Re: if i wanted it i'd ask

Posted: Mon Dec 01, 2008 7:21 pm
by DaDigi
Maybe, instead of taking the time to lash out at the forum administration for preventing another spam attack, just maybe you could make a post in General about password security? Our userbase needs to be educated in cybersecurity, and you are obviously a very knowledgeable person when it comes to it.

Edit: Also, thank you for taking the time and effort to make this topic. In addition to changing back your password, which makes your entire point null and void, you decided to "waste" even more additional time to whine. Congratulations and good night.

Lock'd.