SECURITY ALERT!! -- Please Read!!
Spammers....the parasitic slime of all good internet sites....have found a new technique for infiltrating our site and spreading their filth.
I highly encourage...strongly encourage...EVERYone who reads this, if you have a registered account here at BP.net, whether you post every day, or just lurk and read (especially if you just lurk and read, I fear) CHANGE YOUR PASSWORD. Make it something truly secure, with a mix of uppercase and lowercase letters, numbers, special symbols and no obvious, actual words.
Hopefully our tech guy can find this security leak and plug it up tight. I don't really know how this is being done. But changing to a truly secure password is the first logical step to keeping the bad guys out.
Re: SECURITY ALERT!! -- Please Read!!
So is the security flaw only effecting weak passwords? If our password already meets your description above does it still need to be changed?
Re: SECURITY ALERT!! -- Please Read!!
It is always good to be safe, however, even if anyone has gotten any access to the site, the passwords shouldn't be stored in plaintext, and should be encrypted. Which they most likely are.
Re: SECURITY ALERT!! -- Please Read!!
Quote:
Originally Posted by
George1994
Wait, are they getting the passwords of users and taking over their accounts? Could they not just be poor passwords that have been brute forced or figured out from patterns of passwords or even commandeered email accounts? If that is the case, it may not be the sites issue.
We don't know yet. The problem MAY be poor passwords that have been "brute forced" and that is the reason for this warning. If you have a weak password, it needs to be changed.
Yes, our password database is encrypted. I can't tell anyone what their password is. I can only change them if one gets forgotten. I really don't think the security breach is THAT big that they've gotten into all the actual account keys. But they've gotten into SOME, and until we know why and how, it behooves everyone to make sure they have something not easily forced.
If you already have one that you feel is sufficiently strong, it should be fine. If they can see past the encryption and look at everything anyhow, then changing it wouldn't make much difference anyhow.
Re: SECURITY ALERT!! -- Please Read!!
Nice, this is good news. I doubt they have managed to get the keys, and the sure as hell haven't beaten the encryption haha! My first guess was either brute forcing or people using the same passwords etc. Thanks for the news.