Upgrade your passwords!

  • Thread starter Thread starter Buzzfuzz
  • Start date Start date
  • Replies Replies 38
  • Views Views 1061
Bear in mind that eab deactivates accounts that haven't posted in a while so some people may not necessarily be hacked.

Should we enforce a password change on amibay?
 
If that is the case, being deactivated, than I have no problem with it if it can be activated again.

Bear in mind that eab deactivates accounts that haven't posted in a while so some people may not necessarily be hacked.

Only weak ones or the ones that are very easy, but I guess most people know by now that a good password is at least 10-20 positions and with upper case letters, numbers and special characters.

Should we enforce a password change on amibay?
 
Well, with the rainbow tables out there, even some "good passwords" aren't as good as they used to be...

One of the reasons I have different passwords for different "important" sites.
(Generally sites involving money/transactions.)

Someone gets my EAB pwd, they don't have my Amibay one, because I consider amibay a transaction site.
If they get my EAB, then they do get a few others, but nothing critical.
(Well, that and the combination to my luggage.. ;-) )
It's the dance between security and usability..

It's a painful dance some places tho.. I have many different passwords at work, and I don't write any of them down....
I have a good memory, but password change time can be painful, especially when they "line up."

Personally, I wouldn't enforce a password change policy here..

Some people will just use some guessable pattern or just not show up.

Make passwords too hard and people come up with work-arounds that tend to make the passwords even more vulnerable...

Whenever we've increased password strength at work, the number of post-its under keyboards has increased.. ;-)

desiv
 
@AmiNeo & Buzzfuzz

@AmiNeo & Buzzfuzz

Ok, after some feverish PMing between me and the admins over at EAB I have the answer, um....maybe :roll:
Accounts are removed if they have less than 10 posts and haven't used the board for more than four months. If that is you guys then Prowler's advice is just to re-register with new accounts. hope that helps you two. Looks like chiark's suggestion is the right one :)
 
Thanks Geraldine :thumbsup:
It was indeed removed, strange policy for Amiga fans.
I'm not much their simply because it's all tech talk, I'd like to have some fun too, and here I can :-D

Ok, after some feverish PMing between me and the admins over at EAB I have the answer, um....maybe :roll:
Accounts are removed if they have less than 10 posts and haven't used the board for more than four months. If that is you guys then Prowler's advice is just to re-register with new accounts. hope that helps you two. Looks like chiark's suggestion is the right one :)

Why we are targeted ?
Well it seems to be someone who hacked Trevor's account, yeah the big man behind the X1000.
So why he's doing that, remains unknown.
 
The hacker can have my password for here if they so wish ... they can't do much with it except make my life easier by buying and selling miggy stuff for me :)

Couldn't agree more :)

I can't be arsed to change my password on each and every other forum, mainly because it won't harm me in any way if an account is hacked. The only thing that will happen is that the hacker will use my account for spamming reasons. Big deal.

I too was hacked on a few Amiga sites, and I can't access my accounts on a.org and amigans.net anymore, but since I don't visit those sites anymore anyway I'm not even bothering trying to get my accounts over there up and running again...
 
Hmm...

This is a trading site.

If a well known seller account is compromised, people could end up sending money (via gift) to Mr Random Stranger thinking it's safe to deal with them because they're regulars and have positive feedback.

You might choose to trade with one of those who has -unknown to you- had their account compromised... So it could cost you too.

It's not just a spam problem, it's a scam problem if we're not a little careful. I will have suspicion detectors turned up a little higher for a few weeks :D
 
We should each have a barcode printed on our foreheads that's read in by a webcam and validated on the server. :lol:

Seriously though this makes me think, computers are so damn clever but nobody has yet designed a fool proff access method. Rather like locks on car doors that we still have to have.
 
@ all

It appears that it has only been one account that has been compromised, the account being Trevor Dickinson's of A-EON.

As the same password was being used at several sites, this is why spurious messages were being posted in Trevor's name about A-EON shutting down, causing confusion on the forums concerned.

FOL of Amigakit has refuted the messages on EAB, stating that A-EON has not folded and if this were so, Amigakit as the official distributor would be the first to know

Trevor is in the process of getting the accounts reset and I am certain that he will post giving details of what happened in due course.
 
It appears that it has only been one account that has been compromised, the account being Trevor Dickinson's of A-EON.

Wll, apparently my account has been used on AW.net to at least send a number of PMs, and maybe some posts on the forum as well which have later been deleted. Also, my account has been changed on both a.org and amigans.net so I'd like to think of that as an account being compromised :)


edit: small correction: my amigans.net seems to be deleted. Google cache shows I haven't logged in there since 2009, so it probably was because of inactivity :-)
 
Last edited:
Seriously though this makes me think, computers are so damn clever but nobody has yet designed a fool proff access method. Rather like locks on car doors that we still have to have.

Um. Car access already is pretty smart. Most modern car keys are digital, rather than mechanical, talking to the car's ecu and immobiliser, randomly changing the key codes every time they are used, so pretty secure.

It's one reason older cars are stolen more often these days, and newer cars only by stealing the car keys from owners houses.
 
EAB Update

EAB Update

@ Ami Neo & Buzzfuzz
RCK (the site admin at EAB) finally got back to me. Buzzfuzz, you just need to request a new password to re-activate your account using the same email address you registered with. Ami Neo, your account has totally disappeared, so you would need to create a new one. :)
 
Hi Gereldine, are there any other Amiga sites frequesntly visited by the guys here? I def signed up to one other one but I cant recall which exactly, which prob shows how often I used the account.
 
Hi AmiNeo, I did a search on EAB for any posts you might have made and drew a blank. Are you sure you signed up to EAB? Maybe it was Amiga.org, but there are quite a few miggy sites out there
 
Back
Top Bottom