![]() |
::READ:: IMPORTANT INFO regarding your forum password
To log on forums you now need to use your graal password, it mean that if you change your graal password it will also change your forum password.
|
oh what a relief. I was just thinking that my forum password was stolen.
|
As was I.
|
Goodie, easier to recover.
|
Quote:
I liked it when you could have a different password. :cry: |
Well damnit thats annoying.
|
Quote:
|
Gah.
|
So I cant use my 12 character pw now?:(
|
Hmm, this means if I want to log into the forums elsewhere I'd have to go through my e-mails, look for my Graal password as I've still not got the hang of it.
|
Quote:
|
True. I'm not a fan of this movement.
|
Quote:
|
Quote:
|
Quote:
|
I'm not liking this for the security issue it poses.
I always liked that the forum pass and account pass could be different. Because there seem to be many more ways to get your account pass stolen. For example, if someone obtained your graal account pass and e-mail, you could have the forum account linked to a different pass and e-mail, and then private message an admin to try and help you get your account back. Also if someone get's your graal account pass, now they could come on the forum and post a bunch of spam or porn or whatever and get your forum account banned really fast. =/ |
They are meant to be linked anyway, just like Graal.net is, and the Wiki is.
|
Woah, that's a huge flaw. Listen to Konidias!
|
Excellent, we can start a loriel-esque way to not only get forum passwords but now graal passwords aswell!
|
I don't see any security issues:
If your graal password is stolen you can get it changed by the password changer in 30 seconds, you can also request by the support center giving your payement reference ID. There are no reasons to get your graal password stolen, graal password are really random and they are really secure, we don't store them unencrypted and they are also salted. We want to stop account sharing so it will be another good reason to not share his/her account to not have someone posting using your name... Quote:
|
Quote:
|
Random, auto-generated passwords is a good idea anyway because too many people pick way too easy passwords, and tend to use the same password for everything, or at least several things.
|
Quote:
I could make a support ticket, if I remember my username and password for that, but by the time it's responded to and acted on it'll probably already be too late. (And when I say 'acted on' I mean having the account temp-globalled.) Since all my paypal info would also be in my email account, or they would have direct access to it as a consequence of having my email address, then the chances of me ever being able to fully regain control of my account are slim to none. |
Hahaha @ Demisis.
I had all my accounts switched to one email and thats like 5-10 accounts (ask ibonic on this =P). And recently my IP's been changing a lot aswell (ask Ibonic on that aswell =P) Anyway.. I don't think anyones accounts even been leaked out (actual password).. it was more for security of something that MAY happen then DID happen @ Googi =o |
Quote:
|
Quote:
|
Yeah i learned to remember my graal password along time ago. its real easier logging into graal
|
Quote:
|
Quote:
And as you already said, having the same password for multiple things is a security risk. Quote:
Quote:
Once, just once, do a poll or something and actually give the players what they want. |
Quote:
If either your primary or your secondary email address expire then they can also simply be re-registered by another person, and they would still be in the database for whatever things you signed up for with that email address. Alternatively if you use an ISP email address and you change ISPs or move then the email address is lost, and could be re-registered by somebody else that uses that same ISP. It's also possible for 'graal hackers' to put keyloggers or trojans into their programs and gain access to accounts that way. Of they could make a graal-related website that requires registration and do a Velox. There are lots of possibilities. Quote:
|
Quote:
1) Choose a hard to guess password/secret answers. 2) Don't use the same passwords on unrelated websites. 3) Don't use poor free services to store sensitive information. 4) Pay attention to your e-mail account's expiration date. 5) Don't open unknown applications. 6) Use a firewall/anti-virus. If you fail to do it and your account gets stolen, it's your fault. |
Having separate forum passwords was more a insecurity than a help. You were able before to update the forum password by changing the Graal password, so it's not making something worse in that direction.
|
Quote:
Also, you do realize that we are talking about the security of our account passwords, not our forum passwords. The forum password security isn't nearly as big of a deal as the account passwords. |
Quote:
This sounds like another horrible mistake and You and Unixmads part. And Please dont give me that George Bush BS and lie about making mistakes and just face up to them and fix them...like this one for example. @Unixmad, ok yea we can change out passwords and send in support tickets when out account is stolen. But that doesnt change the fact that it is now easier to steal. Id rather not have my account stolen in the first place alright. So this is a Security Issue. |
People can only get your password if you are not careful.
The solution is to check that you are typing your passwords into GraalOnline.com instead of other websites trying to immitate it. You should also keep a spyware scanner up to date and not keep copies of your password in stupid places like "Hotmail" accounts. It's simple and I am not sure what you all find so difficult about that. As for the accounts database being intruded, the people involved only got hashes of passwords. They could have spent a long time trying to bombard the hashes but it still would have been an unconstructive use of their time, since they are salted anyway. |
| All times are GMT +2. The time now is 03:36 PM. |
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
Copyright (C) 1998-2019 Toonslab All Rights Reserved.