RE: Changing Our Password Policy
July 22, 2012 at 10:48 am
(This post was last modified: July 22, 2012 at 7:37 pm by Tiberius.)
(July 22, 2012 at 9:05 am)Paul the Human Wrote: For the record, I actually agree that more complicated passwords are a good idea. I have no problem with them being strongly suggested and recommended. I have a problem with them being forced upon us 'for our own good'. That kind of thing seriously pisses me off.Lots of sites are doing this. Almost every site I sign up to requires me to enter a complex password. I doubt you mind those sites doing it; no, it's just that we changed our policy here and made everyone comply with it.
Quote:If I have a weak password, it would present no danger to the forums. Saying it does is a flat out lie. What could anyone accomplish by logging into my account?Other than the fact they would have access to any personal details you've stored here? How about not thinking about yourself, but other people? If the database is stolen, an attacker can crack at least 36% of the passwords. Since people often use the same password, that leaves them open to getting hacked on other sites (including email). We would be to blame, since if we had a complex password policy, less passwords would be crackable.
Quote:Next thing you know, Tiberius will be forcing minimum and maximum word counts for your posts... you know... for your own good (to stop spammers).This is a lie and you know it. You don't need to make stuff up to present your point; it makes you look desperate.
(July 22, 2012 at 10:16 am)5thHorseman Wrote: I changed my password, and then after visiting a few more times, I had to do it again. I changed it to exactly the same one. Is this a potential problem(the doing it again or the same one)?Neither are a problem. We had to make everyone do it again, my bad. Changing your password to the same thing just means you didn't need to think up a new one.
(July 22, 2012 at 10:42 am)Rev. Rye Wrote: Okay, three of those times were false starts because it turned out that my passwords were not complicated enough. But still, making us change our passwords twice in one day! Maybe it would be a good idea to make up your minds as to what the passwords should be before starting on this project.Apologies, we had decided to make the change, but I reversed it when a few people complained. I then went back in my decision when I realised these people were in the clear minority, and most people appreciate staff who value high forum security.