Page 2 of 7

Re: PASSWORD Security

Posted: Mon Jul 24, 2017 9:14 pm
by mcthulhu
I had changed my password yesterday per rdearman's suggestion, and logged in again to test it with no problems. I just had another problem with logging in today, however, and I had to answer the CAPTCHA.

Re: PASSWORD Security

Posted: Mon Jul 24, 2017 9:39 pm
by Xenops
After some confusion and with CAPTCHA, I know have a new password and I can log in. Mods, you may disregard my email. :) Thank you for your work.

Re: PASSWORD Security

Posted: Mon Jul 24, 2017 11:27 pm
by MorkTheFiddle
Iversen wrote:Those of us who are moderators in both places can block your HTLAL account, but then you can't use the search facilites or the list over the latest messages (though that list has become somewhat of joke lately). Besides your name would still figure on the user list, and we can't remove it from there.
If the user list still shows the name, there is no point in blocking my account. So don't bother. If I am not mistaken, searching can still be done through Google (website:how-to-learn-any-language.com etc.). Thanks to both you and Rhian for your replies.

Re: PASSWORD Security

Posted: Mon Jul 31, 2017 2:25 am
by Hank
Old news maybe, but this just happened to me. I changed my password. It really stinks because my password was easy to remember, but not very safe. :(

Re: PASSWORD Security

Posted: Mon Jul 31, 2017 7:49 am
by Tillumadoguenirurm
Hank wrote:Old news maybe, but this just happened to me. I changed my password. It really stinks because my password was easy to remember, but not very safe. :(


And I got the captcha again today, but I've only tried to logg in once.

Re: PASSWORD Security

Posted: Mon Jul 31, 2017 11:10 am
by Cainntear
Presumably this is them attempting to use the data from the recent hack...?

It's happened to me several times recently, and the most recent was five minutes ago. I logged in with my password yesterday too, so it looks like the hackers attempted overnight.

As for password security settings, four unrelated words from four unrelated languages make for a surprisingly secure password, and you can even add in a few extra characters to mix things up.

Re: PASSWORD Security

Posted: Mon Jul 31, 2017 12:25 pm
by Iversen
It is necessary to have good strong passwords, but actually there is no reason to believe that they have been guessed so far (and therefore no reason to change a good strong password). The point is at the fake login attempts fizzle out when the limit is reached, and to go beyond this point you have to supply the correct password AND solve a riddle - in other words the riddle isn't used unless you also have supply a correct password. When the rightful account owner has passed this double test and got access to the forum the counter is of course reset and the hacker can then attempt a new series of guesses - but with a good password you would need an astronomical number of rounds before finding the right one purely by guessing. Maybe the goal of the attacker right now simply is to irritate us.

Re: PASSWORD Security

Posted: Tue Aug 01, 2017 8:10 am
by William Camden
I keep getting "the number of tries has been exceeded" -type messages, after just trying to log in once, and I get the CAPTCHA. I may change my password.

Re: PASSWORD Security

Posted: Tue Aug 01, 2017 9:37 am
by Adrianslont
Iversen wrote:Maybe the goal of the attacker right now simply is to irritate us.


Or maybe they are hoping to find one of us has used a password such as "password" or "12345678" and steal an identity. And find a bank account attached to that identity.

Or maybe a bored, clueless person who has no real objective.

I'd love to hear the theories of the computer boffins on the forum who know more than me!

Re: PASSWORD Security

Posted: Tue Aug 01, 2017 1:20 pm
by Elenia
I didn't bother changing my password. It's not particularly easy to guess, I don't think, and it's not the same as my password for anything else. It's automatically saved in my browser, so I only had the CAPTCHA problem when trying to log in from my phone - which I only tried to see if I would have that problem.