beck15
Junior Member
Posts: 61
|
Post by beck15 on Feb 15, 2006 0:06:30 GMT -5
|
|
savin
Full Member
Posts: 233
|
Post by savin on Feb 15, 2006 0:15:40 GMT -5
beck,
I think "hacked" is a little strong of a word. Some of the players at the site do not use the most appropriate passwords. Stupid things like same password as name etc. This opens it up to someone trying to log in and guess a password and make a move in a game. The site is pretty secure, but if people's passwords are too easy to guess then .....
We had a similar problem a couple of years ago. We have just had this happen again so we felt it was worth making an appeal to the user base to try and use passwords that are not easily guessable.
I suspect a few will ignore the advace and sooner or later it will happen again ...
Anyway, nothing to worry about unless you have a very obvious password.
|
|
|
Post by yitwail on Feb 15, 2006 9:59:14 GMT -5
i'm curious, was the culprit apprehended, so to speak?
|
|
|
Post by Stan Steliga on Feb 15, 2006 10:58:15 GMT -5
I'm trying to deal with the problem without calling anyone out. The important thing to remember is that anyone on the internet can browse the pages at the site and try guessing passwords. That's why it's important to maintain a password that is impossible to guess.
|
|
|
Post by yassen on Feb 15, 2006 13:10:53 GMT -5
How many cases of guessed passwords are we talking about?!
|
|
|
Post by Stan Steliga on Feb 15, 2006 13:41:33 GMT -5
Only a couple, but it just pointed out that there are many vulnerable accounts because of insecure (guessable) passwords. I am actually going to implement some kind of simple password rules that will force people to use a more secure password. You won't be able to have a password that is the same as your nickname, part of your name...
Most sites and other password protected entities have some sort of password rules. I will not make it a nuisance... just more secure than it is now.
|
|
|
Post by perseus on Feb 15, 2006 18:54:36 GMT -5
I had changed my password already. I sort of sussed this out.
|
|
beck15
Junior Member
Posts: 61
|
Post by beck15 on Feb 17, 2006 3:20:43 GMT -5
is there a limit on the length of password here at stans??
|
|
|
Post by Stan Steliga on Feb 17, 2006 8:59:08 GMT -5
Yes - it is currently limited to 10 characters. I realize that I should have allowed it to be longer. That might be one of the changes (allowing maybe up to 20 characters) we'll make when we work on making the passwords more secure.
When the site first went live, we didn't have the log in option, so you had to enter your password with everything. I think that is why I thought shorter passwords would be ok.
|
|
Blockhead
Full Member
En passant ...
Posts: 167
|
Post by Blockhead on Feb 18, 2006 7:46:07 GMT -5
Perhaps I'm missing something here, but what is the actual scale and nature of the problem? If someone guesses my SNC password what damage can they do? They could mess up some (all?) of my games! They could change my personal details on SNC, maybe make me look silly and absurd! As a blockhead I don't think this would cause undue concern. Should my grade be affected why should I care? I have a sense of my own chessic worth, and I'm not unduly concerned if that is shared by my chessic peers or not. There is no reason I'm aware of why I couldn't just start over again! I love being part of SNC but becoming paranoid about the possibility of someone getting access to my SNC account has no appeal. It would be a waste of my valued emotional inteligence. Rather than seek the objective probability of an event occurring, it wearies me that so many abandon rational thought. On hearing irresponsible media coverage, or worse, anecdotal evidence ... 'gossip', regarding wayward miscreants who 'threaten' to break into their homes (SNC account!), many willingly seek and embrace a siege mentality. They make every effort to transform a home into a 'protected' fortress. Hold ups, c**k-ups, and lost socks, are part of the natural (dis)order of things. I will continue using my present pass word. I await the coming storm with calm equanimity.
|
|
|
Post by nightmare on Feb 18, 2006 8:35:52 GMT -5
Hey Blockhead? Do you have any idea what you just said? Its sounds to me like a bag of hot air. I too dont care about wins and losses, but Idlike to get both on My playings not somebody elses.
|
|
Blockhead
Full Member
En passant ...
Posts: 167
|
Post by Blockhead on Feb 19, 2006 8:22:48 GMT -5
Hmmm, here's me thinking someone had swiped this annoying little mosquito from this MB for good!
|
|
|
Post by nightmare on Feb 19, 2006 12:37:20 GMT -5
Whats a matter Blockhead? The truth hurts, doesn't it?
|
|
|
Post by yassen on Feb 19, 2006 12:48:18 GMT -5
Some time ago, I learned another person's password, because he mistakenly typed it in the game comment field. No complicated password rules will protect you from that.
|
|
|
Post by nightmare on Feb 19, 2006 12:53:27 GMT -5
Maybe Stan should look at using numbers as passwords.
|
|