password

OT: anything goes!

Moderator: Edi

Locked
GoneCrazy
Village Idiot
Posts: 88
Joined: 2002-09-07 11:02am

password

Post by GoneCrazy »

why'd you guys make there be rules for your password? i was quite content with my old password (all letters) and now i had to change it to the password i use on a different site (letters, symbols, and numbers).
Mess with the Best,
Die Like the Rest
User avatar
Exonerate
Sith Marauder
Posts: 4454
Joined: 2002-10-29 07:19pm
Location: DC Metro Area

Post by Exonerate »

Because we had people's accounts cracked because they used unsecure passwords. So we decided to force them to make it alphanumeric so it would be harder to crack.

BoTM, MM, HAB, JL
GoneCrazy
Village Idiot
Posts: 88
Joined: 2002-09-07 11:02am

Post by GoneCrazy »

shouldn't you have maybe just suggested a better password, and not forced people to have one?
Mess with the Best,
Die Like the Rest
User avatar
aerius
Charismatic Cult Leader
Posts: 14802
Joined: 2002-08-18 07:27pm

Post by aerius »

Because you touch yourself at night. Actually it's because want you to forget your password so we can purge your account to free up more server space. Actually I have no idea what I'm talking about, so listen to what that other guy said.
Image
aerius: I'll vote for you if you sleep with me. :)
Lusankya: Deal!
Say, do you want it to be a threesome with your wife? Or a foursome with your wife and sister-in-law? I'm up for either. :P
User avatar
phongn
Rebel Leader
Posts: 18487
Joined: 2002-07-03 11:11pm

Re: password

Post by phongn »

GoneCrazy wrote:why'd you guys make there be rules for your password? i was quite content with my old password (all letters) and now i had to change it to the password i use on a different site (letters, symbols, and numbers).
Because the types of passwords you want can be broken relatively easily via dictionary search. Thus, we force users to have a more difficult password so that we minimize future problems of the sort.
GoneCrazy
Village Idiot
Posts: 88
Joined: 2002-09-07 11:02am

Post by GoneCrazy »

lol. that's kind of funny aerius.
Mess with the Best,
Die Like the Rest
GoneCrazy
Village Idiot
Posts: 88
Joined: 2002-09-07 11:02am

Post by GoneCrazy »

but shouldn't what happens on a user's account be the user's responsibility? if a user's account gets cracked then its the user's fault, and anything the cracker does with the account can be blamed on the user's negligence. i still don't see why it shouldn't be totally optional.
Mess with the Best,
Die Like the Rest
User avatar
General Zod
Never Shuts Up
Posts: 29211
Joined: 2003-11-18 03:08pm
Location: The Clearance Rack
Contact:

Post by General Zod »

this also makes it harder for idiots to go about posting stupid things and then claim that the stupidity was a result of their password being hacked. otherwise any script kiddy could use brute force programs to break someone's password, which would cause all kinds of trouble.

EDIT: also, blaming a user for someone hacking into their account is stupid. while they may have some responsibility for making their password easy to crack, someone else decided to do so on their own, and is responsible for actually breaking it. so they both share some of the blame, but it's not completely the user's fault.
"It's you Americans. There's something about nipples you hate. If this were Germany, we'd be romping around naked on the stage here."
User avatar
Exonerate
Sith Marauder
Posts: 4454
Joined: 2002-10-29 07:19pm
Location: DC Metro Area

Post by Exonerate »

On the other hand, any idiot who makes their password "password" or something like that deserves to be shot...

IIRC, TK managed to grab passwords this way. It may be your responsibility to keep a secure password, but if you fail to do so, it affects all of us.

BoTM, MM, HAB, JL
User avatar
General Zod
Never Shuts Up
Posts: 29211
Joined: 2003-11-18 03:08pm
Location: The Clearance Rack
Contact:

Post by General Zod »

i'll agree to that. making a password from the most commonly used words is just plain moronic. like making the password either password, admin, god, love, hate, etc. in that case they deserve to be smacked.
"It's you Americans. There's something about nipples you hate. If this were Germany, we'd be romping around naked on the stage here."
User avatar
GrandMasterTerwynn
Emperor's Hand
Posts: 6787
Joined: 2002-07-29 06:14pm
Location: Somewhere on Earth.

Post by GrandMasterTerwynn »

GoneCrazy wrote:but shouldn't what happens on a user's account be the user's responsibility? if a user's account gets cracked then its the user's fault, and anything the cracker does with the account can be blamed on the user's negligence. i still don't see why it shouldn't be totally optional.
Well, if some malicious fuckwit got his or her hands on the password of John Q. User, they could either make a lot of spam posts linking to high-bandwidth pictures, or pornography or hate sites. The spurious posts would not only cause the site to tank for the rest of us, but if someone's parent happens to be looking over their child's shoulder while such an attack is taking place, they might take it on themselves to make an official complaint, causing the site to be shut down. And that's just the damage a bog-standard user can inflict, the thought of a moderator account getting cracked is even more frightening when one thinks of the damage that can be caused there.

So password security is very important. One should not take so blaise an attitude toward it.
User avatar
Tsyroc
Emperor's Hand
Posts: 13748
Joined: 2002-07-29 08:35am
Location: Tucson, Arizona

Post by Tsyroc »

Darth_Zod wrote:i'll agree to that. making a password from the most commonly used words is just plain moronic. like making the password either password, admin, god, love, hate, etc. in that case they deserve to be smacked.
I like the Pointy Haired Boss' password from Dilbert. "*******"
By the pricking of my thumb,
Something wicked this way comes.
Open, locks,
Whoever knocks.
User avatar
Sarevok
The Fearless One
Posts: 10681
Joined: 2002-12-24 07:29am
Location: The Covenants last and final line of defense

Post by Sarevok »

GoneCrazy wrote:but shouldn't what happens on a user's account be the user's responsibility? if a user's account gets cracked then its the user's fault, and anything the cracker does with the account can be blamed on the user's negligence. i still don't see why it shouldn't be totally optional.
Most of the time yes. But in certain cases hackers employ techniques far more advanced than simple dictionary attack. Luckily script kiddies are not programmers and dont have the knowledge to pull this off.
I have to tell you something everything I wrote above is a lie.
User avatar
kojikun
BANNED
Posts: 9663
Joined: 2002-07-04 12:23am
Contact:

Post by kojikun »

its called preventative measures. holy crap, just shut up and accept thef act. mike says use full alphanumerics, so you do. whats so fucking hard to get.
Sì! Abbiamo un' anima! Ma è fatta di tanti piccoli robot.
User avatar
ArmorPierce
Rabid Monkey
Posts: 5904
Joined: 2002-07-04 09:54pm
Location: Born and raised in Brooklyn, unfornately presently in Jersey

Post by ArmorPierce »

hmm that reminds me, I've changed my password and I don't remember the password :?
Brotherhood of the Monkey @( !.! )@
To give anything less than your best is to sacrifice the gift. ~Steve Prefontaine
Aoccdrnig to rscheearch at an Elingsh uinervtisy, it deosn't mttaer in waht oredr the ltteers in a wrod are, the olny iprmoetnt tihng is taht frist and lsat ltteer are in the rghit pclae. The rset can be a toatl mses and you can sitll raed it wouthit a porbelm. Tihs is bcuseae we do not raed ervey lteter by it slef but the wrod as a wlohe.
User avatar
Rogue 9
Scrapping TIEs since 1997
Posts: 18684
Joined: 2003-11-12 01:10pm
Location: Classified
Contact:

Post by Rogue 9 »

ArmorPierce wrote:hmm that reminds me, I've changed my password and I don't remember the password :?
Brilliant, Holmes. :roll:
User avatar
Sharp-kun
Sith Devotee
Posts: 2993
Joined: 2003-09-10 05:12am
Location: Glasgow, Scotland

Post by Sharp-kun »

GoneCrazy wrote:but shouldn't what happens on a user's account be the user's responsibility? if a user's account gets cracked then its the user's fault, and anything the cracker does with the account can be blamed on the user's negligence. i still don't see why it shouldn't be totally optional.
Its still a pain for other members.

We had this once on Animenation. A members brother found out their password, and ended up spamming the forum badly, and posting all sorts of offensive shit just to get his brother banned. It pisses off other members.
User avatar
Faram
Bastard Operator from Hell
Posts: 5271
Joined: 2002-07-04 07:39am
Location: Fighting Polarbears

Post by Faram »

Stop wining and get Password Safe.
Password Safe
The security of Blowfish in a password database
Support
The current version of Password Safe is an open source project, which you can download from its Sourceforge page. Please use the Sourceforge tracking system for feature requests and bug reports. (Update: The first public release of version 2.0 came out on December 15, 2003.)

For support of 1.7.1 and earlier versions, see the Password Safe FAQ or e-mail passwordsafe@counterpane.com. You can still download Password Safe 1.7.1 from this web site.

Many computer users today have to keep track of dozens of passwords: for network accounts, online services, premium web sites. Some write their passwords on a piece of paper, leaving their accounts vulnerable to thieves or in-house snoops. Others choose the same password for different applications, which makes life easy for intruders of all kinds.

With Password Safe, a free Windows 9x/2000 utility from Counterpane Labs, users can keep their passwords securely encrypted on their computers. A single Safe Combination--just one thing to remember--unlocks them all.

Password Safe protects passwords with the Blowfish encryption algorithm, a fast, free alternative to DES. The program's security has been thoroughly verified by Counterpane Labs under the supervision of Bruce Schneier, author of Applied Cryptography and creator of the Blowfish algorithm.

Password Safe features a simple, intuitive interface that lets users set up their password database in minutes. You can copy a password just by double-clicking, and paste it directly into your application. Best of all, Password Safe is completely free: no license requirements, shareware fees, or other strings attached.

See the Blowfish page for more information on the Blowfish algorithm, including links to more than 120 other products that use Blowfish.

Counterpane Internet Security, Inc. Home Page.
This is badass stuff make the passphrase +25 char long and it's next to impossible to break it, we arer talikng impossible for NSA and those guys the script kiddie next door... :lol:

D/L Linky
[img=right]http://hem.bredband.net/b217293/warsaban.gif[/img]

"Either God wants to abolish evil, and cannot; or he can, but does not want to. ... If he wants to, but cannot, he is impotent. If he can, but does not want to, he is wicked. ... If, as they say, God can abolish evil, and God really wants to do it, why is there evil in the world?" -Epicurus


Fear is the mother of all gods.

Nature does all things spontaneously, by herself, without the meddling of the gods. -Lucretius
User avatar
Dalton
For Those About to Rock We Salute You
For Those About to Rock We Salute You
Posts: 22640
Joined: 2002-07-03 06:16pm
Location: New York, the Fuck You State
Contact:

Post by Dalton »

Strong password rules are enforced because some people are fucking stupid when selecting passwords. I remember someone here once had the password "password".

This isn't optional, nor should it be. We're not going to have some script-kiddie fucker running around and posting disgusting images in a spree of childish bullshit, not to mention crack moderator accounts and majorly fuck up several threads, just because some whiny newbie is complaining that his password has to be complicated now.

End of story, thread locked. Live with it.
Image
Image
To Absent Friends
Dalton | Admin Smash | Knight of the Order of SDN

"y = mx + bro" - Surlethe
"You try THAT shit again, kid, and I will mod you. I will
mod you so hard, you'll wish I were Dalton." - Lagmonster

May the way of the Hero lead to the Triforce.
Locked