Page 3 of 7 FirstFirst 123456 ... LastLast
Results 33 to 48 of 108

Thread: Problems accessing forums?

  1. #33
    DILLIGAF GoNz0's Avatar
    Join Date
    Jun 2006
    Location
    Derby
    Posts
    10,872
    Thanks
    632
    Thanked
    1,192 times in 945 posts
    • GoNz0's system
      • Motherboard:
      • Asus Rampage V Extreme
      • CPU:
      • i7 something X99 based
      • Memory:
      • 16gb GSkill
      • Storage:
      • 4 SSD's + WD Red
      • Graphics card(s):
      • GTX980 Strix WC
      • PSU:
      • Enermax Galaxy 1250 (9 years and counting)
      • Case:
      • Corsair 900D
      • Operating System:
      • win10 64bit
      • Monitor(s):
      • Dell 24"
      • Internet:
      • 220mb Cable

    Re: Problems accessing forums?

    Quote Originally Posted by The Hand View Post
    Thanks for the heads up DR, I've had the same password since 2004, so it's about time I changed it. lol
    Guilty of that as well, couldn't be bothered as it wasn't used for anything important but it's done now.

    Quote Originally Posted by Peter Parker View Post
    Thanks for the warning - password changed.

    Funnily enough I was reading this post last night :
    https://blog.codinghorror.com/your-p...oo-damn-short/

    I generate random passwords for all sites using Lastpass (not perfect but at least I'm better off than 95% of people) and where by default length was 12 I'm already considering extending it.
    Yeah Lastpass is great, the security challenge keeps pointing out I still have an old password on several dozen sites!

    Capitalization is the difference between helping your Uncle Jack
    off a horse and helping your uncle jack off a horse.

  2. #34
    DR
    DR is offline
    on ye old ship HEXUS DR's Avatar
    Join Date
    Jul 2003
    Location
    HEXUS HQ, Elstree
    Posts
    13,412
    Thanks
    1,060
    Thanked
    841 times in 373 posts

    Re: Problems accessing forums?

    Quote Originally Posted by Lucio View Post
    Appreciate the transparency and the action taken was to protect us, but the communication wasn't clear that you had *actually* reset the password, as in cleared down the existing password.

    A little bit worrying to think "bugger, my account's already been compromised" because I can't log into it, before realising that you've probably just cleared all the passwords at the database level, rather than triggering the "forgot my password" link for everyone.
    Sorry we didn't make this clear enough, we did email people to say we need them to change their passwords. We didn't feel it was right to email people and state "please change your password" we felt it was right to force the change. We do appreciate all feedback and hope we don't need to do things differently if it happens again, but if it does we will

  3. Received thanks from:

    gupsterg (16-08-2016)

  4. #35
    DILLIGAF GoNz0's Avatar
    Join Date
    Jun 2006
    Location
    Derby
    Posts
    10,872
    Thanks
    632
    Thanked
    1,192 times in 945 posts
    • GoNz0's system
      • Motherboard:
      • Asus Rampage V Extreme
      • CPU:
      • i7 something X99 based
      • Memory:
      • 16gb GSkill
      • Storage:
      • 4 SSD's + WD Red
      • Graphics card(s):
      • GTX980 Strix WC
      • PSU:
      • Enermax Galaxy 1250 (9 years and counting)
      • Case:
      • Corsair 900D
      • Operating System:
      • win10 64bit
      • Monitor(s):
      • Dell 24"
      • Internet:
      • 220mb Cable

    Re: Problems accessing forums?

    Quote Originally Posted by DR View Post
    Sorry we didn't make this clear enough, we did email people to say we need them to change their passwords. We didn't feel it was right to email people and state "please change your password" we felt it was right to force the change. We do appreciate all feedback and hope we don't need to do things differently if it happens again, but if it does we will
    Last time I saw this done a moderated section was created to allow guests to post who couldn't get back into the forum due to dead email accounts. It might be worth doing for a few weeks?

    Capitalization is the difference between helping your Uncle Jack
    off a horse and helping your uncle jack off a horse.

  5. #36
    don't stock motherhoods
    Join Date
    Jun 2005
    Posts
    1,298
    Thanks
    809
    Thanked
    125 times in 108 posts
    • Millennium's system
      • Motherboard:
      • MSI X470 Gaming Plus
      • CPU:
      • AMD 3600x @ 3.85 with Turbo
      • Memory:
      • 4*G-Skill Samsung B 3200 14T 1T
      • Storage:
      • WD850 and OEM961 1TB, 1.5TB SSD SATA, 4TB Storage, Ext.
      • Graphics card(s):
      • 3070 FE HHR NVidia (Mining Over)
      • PSU:
      • ToughPouwer 1kw (thinking of an upgrade to 600w)
      • Case:
      • Fractal Design Define S
      • Operating System:
      • Windows 101 Home 64bit
      • Monitor(s):
      • HiSense 55" TV 4k 8bit BT709 18:10
      • Internet:
      • Vodafone 12 / month, high contentions weekends 2, phone backup.

    Re: Problems accessing forums?

    It's good of you to highlight this, my only concern lies with other vB (or similar) forums I signed up to years ago and used a generic password and haven't changed them in ages - is the hash / salt ok to presume these other forums are still reasonably secure?
    hexus trust : n(baby):n(lover):n(sky)|>P(Name)>>nopes

    Be Careful on the Internet! I ran and tackled a drive by mining attack today. It's not designed to do anything than provide fake texts (say!)

  6. #37
    HEXUS webmaster Steve's Avatar
    Join Date
    Nov 2003
    Posts
    14,283
    Thanks
    293
    Thanked
    841 times in 476 posts

    Re: Problems accessing forums?

    Quote Originally Posted by Millennium View Post
    It's good of you to highlight this, my only concern lies with other vB (or similar) forums I signed up to years ago and used a generic password and haven't changed them in ages - is the hash / salt ok to presume these other forums are still reasonably secure?
    My advice is no, you cannot assume that. It's a bad idea to use the same password in multiple places, because although each hash will be different due to salt, if just one of them gets successfully cracked (say, weak password or simply enough time/effort put in), then a hacker can just try that extracted username/password combo in an array of other locations.
    PHP Code:
    $s = new signature();
    $s->sarcasm()->intellect()->font('Courier New')->display(); 

  7. #38
    Senior Member
    Join Date
    Aug 2013
    Location
    North Wales
    Posts
    1,849
    Thanks
    165
    Thanked
    271 times in 202 posts
    • virtuo's system
      • Motherboard:
      • Gigabyte Aorus Master X570
      • CPU:
      • Ryzen 9 5950x
      • Memory:
      • 64Gb G.Skill TridentZ Neo 3600 CL16
      • Storage:
      • Sabrent 2TB PCIE4 NVME + NAS upon NAS upon NAS
      • Graphics card(s):
      • RTX 3090 FE
      • PSU:
      • Corsair HX850 80+ Platinum
      • Case:
      • Fractal Meshify 2 Grey
      • Operating System:
      • RedStar 3, Ubuntu, Win 10
      • Monitor(s):
      • Samsung CRG90 5140x1440 120hz
      • Internet:
      • PlusNet's best, but still poor, attempt

    Re: Problems accessing forums?

    Quote Originally Posted by Millennium View Post
    It's good of you to highlight this, my only concern lies with other vB (or similar) forums I signed up to years ago and used a generic password and haven't changed them in ages - is the hash / salt ok to presume these other forums are still reasonably secure?
    I think presuming anything is secure is a dangerous approach. It's a ballache but it does make sense to use different passwords for each site.

    Consider that vB being so popular (historically, less so now) and the reluctance of many sites to update the code that has been heavily modified to suit their needs make it an attractive target for attackers.

    Some exploits I have seen in the past have been absolute clangers and given pretty much full server access. Stealing the database is one thing, but grabbing encryption keys from config files, or even modifying code to grab credentials at the point of login make your salted hashed passwords that little bit less reliable, if they were even used in the first place. I've run a couple of large vB boards in the past and I seem to recall password hashing being optional in earlier versions.




    Having said that, I actually do a similar thing to you, I have a "standard" password (and throwaway email aliases) that I'll use for most sites that don't hold any personal information. I have more secure (and unique) passwords for important stuff like email, paypal, Hexus etc.

    I'd say so long as you can guarantee your email, banking and anything that has personal or financial details on it is safe, then you should be fine - that's what these people are ultimately trying to get at. They have very little interest in logging in to your old forum accounts and posting videos of Rick Astley, and if they do it's not much effort to fix.


    Good job Hexus on the way this was handled, it's always a bit gutting having to tell your users the bad news, but we all know the score. It happens and the worst thing you can do is try and cover it up.

    Must say I'm a bit shocked that even in 2016, the password reset process involves sending me an email with both my username and new password in plain text.

  8. #39
    Almost Ex-HEXUS Staff Jonatron's Avatar
    Join Date
    Sep 2009
    Location
    London
    Posts
    705
    Thanks
    48
    Thanked
    272 times in 167 posts

    Re: Problems accessing forums?

    It's really disappointing that vB has so many security vulnerabilities Hopefully HEXUS can switch to more secure software at some point

  9. #40
    DILLIGAF GoNz0's Avatar
    Join Date
    Jun 2006
    Location
    Derby
    Posts
    10,872
    Thanks
    632
    Thanked
    1,192 times in 945 posts
    • GoNz0's system
      • Motherboard:
      • Asus Rampage V Extreme
      • CPU:
      • i7 something X99 based
      • Memory:
      • 16gb GSkill
      • Storage:
      • 4 SSD's + WD Red
      • Graphics card(s):
      • GTX980 Strix WC
      • PSU:
      • Enermax Galaxy 1250 (9 years and counting)
      • Case:
      • Corsair 900D
      • Operating System:
      • win10 64bit
      • Monitor(s):
      • Dell 24"
      • Internet:
      • 220mb Cable

    Re: Problems accessing forums?

    Quote Originally Posted by Jonatron View Post
    It's really disappointing that vB has so many security vulnerabilities Hopefully HEXUS can switch to more secure software at some point
    I disagree, it is so popular it is a target for hackers.

    Sent from my SM-G920F

    Capitalization is the difference between helping your Uncle Jack
    off a horse and helping your uncle jack off a horse.

  10. #41
    HEXUS webmaster Steve's Avatar
    Join Date
    Nov 2003
    Posts
    14,283
    Thanks
    293
    Thanked
    841 times in 476 posts

    Re: Problems accessing forums?

    Quote Originally Posted by GoNz0 View Post
    I disagree, it is so popular it is a target for hackers.
    Nah, it definitely has some failings that are irrelevant to its popularity. As such we have, for quite some time, explored what other options we have, but these things take time on a site of such size & legacy as HEXUS.
    PHP Code:
    $s = new signature();
    $s->sarcasm()->intellect()->font('Courier New')->display(); 

  11. #42
    Senior Member watercooled's Avatar
    Join Date
    Jan 2009
    Posts
    11,478
    Thanks
    1,541
    Thanked
    1,029 times in 872 posts

    Re: Problems accessing forums?

    XtremeSystems recently had a massive breach and lost years' worth of posts. Hexus do at least keep offline backups, right?

  12. #43
    HEXUS webmaster Steve's Avatar
    Join Date
    Nov 2003
    Posts
    14,283
    Thanks
    293
    Thanked
    841 times in 476 posts

    Re: Problems accessing forums?

    I keep a daily printout of all new posts in the basement. It's a serious fire risk but that's the price we pay for data integrity.
    PHP Code:
    $s = new signature();
    $s->sarcasm()->intellect()->font('Courier New')->display(); 

  13. Received thanks from:

    GoNz0 (16-08-2016),Pob255 (22-08-2016),scaryjim (16-08-2016)

  14. #44
    DR
    DR is offline
    on ye old ship HEXUS DR's Avatar
    Join Date
    Jul 2003
    Location
    HEXUS HQ, Elstree
    Posts
    13,412
    Thanks
    1,060
    Thanked
    841 times in 373 posts

    Re: Problems accessing forums?

    Quote Originally Posted by Steve View Post
    I keep a daily printout of all new posts in the basement. It's a serious fire risk but that's the price we pay for data integrity.
    So thats what this was ordered for



    I wondered what it was expensed for.

  15. Received thanks from:

    Pob255 (22-08-2016)

  16. #45
    Senior Member
    Join Date
    Oct 2013
    Location
    Newcastle Upon Tyne
    Posts
    936
    Thanks
    54
    Thanked
    105 times in 72 posts
    • Jowsey's system
      • Motherboard:
      • Asrock H81M-ITX
      • CPU:
      • Intel Xeon E3-1230V3
      • Memory:
      • 8GB Corsair XMS3
      • Storage:
      • 256GB Crucial MX100 & 2TB Seagate Barracuda
      • Graphics card(s):
      • Asus GTX 770 DCUII 2GB
      • PSU:
      • EVGA SuperNova GS 550 watt
      • Case:
      • Phanteks Evolv ITX
      • Operating System:
      • Windows 7 64 bit
      • Internet:
      • Virgin Media 100Mb

    Re: Problems accessing forums?

    Quote Originally Posted by Steve View Post
    I keep a daily printout of all new posts in the basement. It's a serious fire risk but that's the price we pay for data integrity.
    I'll understand there's been an issue when i see hexus post a job vacancy for a mindless touch typer for the next 12 weeks.

  17. #46
    Not a good person scaryjim's Avatar
    Join Date
    Jan 2009
    Location
    Gateshead
    Posts
    15,196
    Thanks
    1,231
    Thanked
    2,291 times in 1,874 posts
    • scaryjim's system
      • Motherboard:
      • Dell Inspiron
      • CPU:
      • Core i5 8250U
      • Memory:
      • 2x 4GB DDR4 2666
      • Storage:
      • 128GB M.2 SSD + 1TB HDD
      • Graphics card(s):
      • Radeon R5 230
      • PSU:
      • Battery/Dell brick
      • Case:
      • Dell Inspiron 5570
      • Operating System:
      • Windows 10
      • Monitor(s):
      • 15" 1080p laptop panel

    Re: Problems accessing forums?

    Quote Originally Posted by Steve View Post
    ... It's a bad idea to use the same password in multiple places, ... if just one of them gets successfully cracked ... a hacker can just try that extracted username/password combo in an array of other locations.
    Obligatory XKCD moment:


    http://www.xkcd.com/792/

  18. Received thanks from:

    Apex (16-08-2016),DR (16-08-2016),Output (16-08-2016),peterb (16-08-2016),Pob255 (22-08-2016)

  19. #47
    Registered User
    Join Date
    Aug 2016
    Posts
    2
    Thanks
    0
    Thanked
    0 times in 0 posts

    Re: Problems accessing forums?

    Hmm, am I the only one who doesn't remember the email the email used to register Hexus?

  20. #48
    Registered User
    Join Date
    Aug 2016
    Posts
    4
    Thanks
    0
    Thanked
    0 times in 0 posts

    Hexus Account!

    Hi

    Since receiving the email regarding the possible data breach a few days ago I have not been able to log into my account (Username: Kanoe) using my previous password and trying to trigger a password reset either via the link in the email I received or by the password reset from the FAQ section has not worked and I don't receive an email to enable me to reset the password.

    Would an admin be able to help me get back into my account?

    Kind regards

    Kanoe

Page 3 of 7 FirstFirst 123456 ... LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •