Archive for myfreeforum.org Before posting please check the "stickies" in the support forums.
Please ask questions in real English and not "txt". You will get a better response.
Please do not ask support questions via PMs.
 



       myfreeforum.org Forum Index -> What's new? Announcements!
admin (no pm's please)

Will you be getting a warning email?

New code is now installed to monitor your control panels password strength.

From some point in the next week forums with weak passwords will start getting monthly warnings to change a weak password.
Bravo

Is this really necessary?

I can only imagine this being somewhat irritating to people.
admin (no pm's please)

More irritating than a fried forum?

At current settings 10% of recent sign ups will be qualifying for the email on password alone. but the email will only go out when a forum has reached a level where it has a significant number of posts.
Bravo

Most passwords are secure unless given out freely, the exception being the oft used password of 'password'.

It's only weak if somebody guesses/knows it, and even something silly like 'banana' would take a bloomin long time to guess.

I can't recall a single fried forum that has occurred from a guessed password.  All the ones in my memory are from people giving out their password, or giving admin access to strangers.  Bit too much nannying for my taste.
admin (no pm's please)

Fair point.

Though the system can be tweaked to only email on the really stupid passwords like "password". Perhaps I should reduce it to that level.
Zudane

Actually, with the constant pushing for people to use more complex passwords, I would guess that a lot of people won't even try the old classics like "password" "sex" "god" (assuming you could use a 3 letter password), simply because it won't be common anymore.

I can't argue much, but what would be considered a weak password?
admin (no pm's please)

Zudane wrote:


I can't argue much, but what would be considered a weak password?


Good question, I was expecting to be able to grab some code to cleverly determine that, code I found was way too dumb in my view.

What I have done is based on password length, use of known stupid passwords like "password" ( I won't state the others), then bonuses for the more you are using a mix of character type, e.g. lowercase, uppercase, symbols, numbers.

As Bravo says though even if you are using "banana" then only a real dictionary attack would break in, and the firewall would block the attempt anyway, so maybe this is a nag too far?

       myfreeforum.org Forum Index -> What's new? Announcements!
Page 1 of 1
Create your own free forum | Buy a domain to use with your forum