myfreeforum.org Forum Index
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups  Who is OnlineWho is Online   Join! (free) Join! (free)  
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 
For an excellent guide to using your myfreeforum forum, you can visit
howtodoit
The howtodoit "readonly" forum provides answers and walkthroughs for all common questions.
  • Welcome
  • Country: US
    US
    Address: 38.107.191.115
  • Server Appeal

Will you be getting a warning email?

 
Post new topic   Reply to topic    myfreeforum.org Forum Index -> What's new? Announcements!
View previous topic :: View next topic  
Author Message
admin (no pm's please)
Site Admin
Site Admin


Virtual Cash: 22860

Joined: 22 May 2005
Posts: 25384



Add Karma

rated by 213 members
Add Comment
Show Comments

online/offline
PostPosted: Thu Jun 11, 2009 10:45 am    Post subject: Will you be getting a warning email? Reply with quote

New code is now installed to monitor your control panels password strength.

From some point in the next week forums with weak passwords will start getting monthly warnings to change a weak password.



_________________

Family Friendly Shareware | | Web Design/Services | Free Forums

Back to top
View user's profile Private message Visit poster's website
Bravo
Moderator
Moderator


Virtual Cash: 14050

Joined: 12 Mar 2006
Posts: 2485



Add Karma

rated by 28 members
Add Comment
Show Comments

online/offline
PostPosted: Thu Jun 11, 2009 4:56 pm    Post subject: Reply with quote

Is this really necessary?

I can only imagine this being somewhat irritating to people.
_________________
CG Arts for free Banners, headers, logo's, signatures and avatars.

Back to top
View user's profile Private message
admin (no pm's please)
Site Admin
Site Admin


Virtual Cash: 22860

Joined: 22 May 2005
Posts: 25384



Add Karma

rated by 213 members
Add Comment
Show Comments

online/offline
PostPosted: Thu Jun 11, 2009 5:05 pm    Post subject: Reply with quote

More irritating than a fried forum?

At current settings 10% of recent sign ups will be qualifying for the email on password alone. but the email will only go out when a forum has reached a level where it has a significant number of posts.
_________________

Family Friendly Shareware | | Web Design/Services | Free Forums

Back to top
View user's profile Private message Visit poster's website
Bravo
Moderator
Moderator


Virtual Cash: 14050

Joined: 12 Mar 2006
Posts: 2485



Add Karma

rated by 28 members
Add Comment
Show Comments

online/offline
PostPosted: Thu Jun 11, 2009 5:43 pm    Post subject: Reply with quote

Most passwords are secure unless given out freely, the exception being the oft used password of 'password'.

It's only weak if somebody guesses/knows it, and even something silly like 'banana' would take a bloomin long time to guess.

I can't recall a single fried forum that has occurred from a guessed password.  All the ones in my memory are from people giving out their password, or giving admin access to strangers.  Bit too much nannying for my taste.
_________________
CG Arts for free Banners, headers, logo's, signatures and avatars.

Back to top
View user's profile Private message
admin (no pm's please)
Site Admin
Site Admin


Virtual Cash: 22860

Joined: 22 May 2005
Posts: 25384



Add Karma

rated by 213 members
Add Comment
Show Comments

online/offline
PostPosted: Thu Jun 11, 2009 5:50 pm    Post subject: Reply with quote

Fair point.

Though the system can be tweaked to only email on the really stupid passwords like "password". Perhaps I should reduce it to that level.
_________________

Family Friendly Shareware | | Web Design/Services | Free Forums

Back to top
View user's profile Private message Visit poster's website
Zudane
Moderator
Moderator


Virtual Cash: 14250

Joined: 10 May 2008
Posts: 1366



Add Karma

rated by 18 members
Add Comment
Show Comments

online/offline
PostPosted: Thu Jun 11, 2009 9:03 pm    Post subject: Reply with quote

Actually, with the constant pushing for people to use more complex passwords, I would guess that a lot of people won't even try the old classics like "password" "sex" "god" (assuming you could use a 3 letter password), simply because it won't be common anymore.

I can't argue much, but what would be considered a weak password?
_________________


Harsh Reality - Unleash your creativity!

Harsh Reality
Back to top
View user's profile Private message Visit poster's website
admin (no pm's please)
Site Admin
Site Admin


Virtual Cash: 22860

Joined: 22 May 2005
Posts: 25384



Add Karma

rated by 213 members
Add Comment
Show Comments

online/offline
PostPosted: Thu Jun 11, 2009 9:13 pm    Post subject: Reply with quote

Zudane wrote:


I can't argue much, but what would be considered a weak password?


Good question, I was expecting to be able to grab some code to cleverly determine that, code I found was way too dumb in my view.

What I have done is based on password length, use of known stupid passwords like "password" ( I won't state the others), then bonuses for the more you are using a mix of character type, e.g. lowercase, uppercase, symbols, numbers.

As Bravo says though even if you are using "banana" then only a real dictionary attack would break in, and the firewall would block the attempt anyway, so maybe this is a nag too far?



_________________

Family Friendly Shareware | | Web Design/Services | Free Forums

Back to top
View user's profile Private message Visit poster's website
Display posts from previous:   
Post new topic   Reply to topic    myfreeforum.org Forum Index -> What's new? Announcements! All times are GMT
Page 1 of 1
 
 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum

Card File  Gallery  Forum Archive
Powered by phpBB © 2001, 2005 phpBB Group
Create your own free forum | Buy a domain to use with your forum