_GOTOBOTTOM
Site Talk
Site announcements, comments, or feedback about the site.
About Passwords....
staff_Jim
Staff MemberPublisher
KITMAKER NETWORK
Visit this Community
New Hampshire, United States
Joined: December 15, 2001
KitMaker: 12,571 posts
Armorama: 6,599 posts
Posted: Friday, January 13, 2006 - 11:08 PM UTC
As many of you have already read their is a ruckus going on about what passwords you use and where you use them. For the record:

1. All user passwords on Armorama are MD5 encrypted (http://www.phptr.com/articles/article.asp?p=31690&seqNum=2&rl=1), however Paul Owen's comment that some web admins should not be trusted is true. And for the record I myself always use a different password for sites I want to be more secure.

2. In 4 years of operation I think no one can attest to me ever telling them what their password is, nor could I log into their account (for bug checking, etc) without first changing their password first to one of my own creation. This is just the way this site was coded (and not by me actually but by the original PostNuke programmers).

3. I am directing all staff members to modify their passwords to something complex and unique and to only use that password for this site.

Thanks,
Jim

Sabot
Joined: December 18, 2001
KitMaker: 12,596 posts
Armorama: 9,071 posts
Posted: Friday, January 13, 2006 - 11:13 PM UTC
Wilco.
jimbrae
Visit this Community
Provincia de Lugo, Spain / España
Joined: April 23, 2003
KitMaker: 12,927 posts
Armorama: 9,486 posts
Posted: Friday, January 13, 2006 - 11:20 PM UTC
Done... twice in fact...
Merlin
Staff MemberSenior Editor
AEROSCALE
#017
Visit this Community
United Kingdom
Joined: June 11, 2003
KitMaker: 17,582 posts
Armorama: 903 posts
Posted: Friday, January 13, 2006 - 11:43 PM UTC
Cheers Jim

I changed mine earlier today as a precaution.

All the best

Rowan
slodder
Visit this Community
North Carolina, United States
Joined: February 22, 2002
KitMaker: 11,718 posts
Armorama: 7,138 posts
Posted: Saturday, January 14, 2006 - 12:04 AM UTC
Already done - totally different - totally unique - true IT gizmo stuff : caps, numbers, mixed, etc etc.....
dexter059
Visit this Community
Region de Valparaiso, Chile
Joined: July 28, 2005
KitMaker: 1,569 posts
Armorama: 1,385 posts
Posted: Saturday, January 14, 2006 - 12:04 AM UTC
Done .....twice too
Eagle
Visit this Community
Noord-Brabant, Netherlands
Joined: May 22, 2002
KitMaker: 4,082 posts
Armorama: 1,993 posts
Posted: Saturday, January 14, 2006 - 02:34 AM UTC
Roger..... Changed
Grumpyoldman
Staff MemberConsigliere
KITMAKER NETWORK
Visit this Community
Florida, United States
Joined: October 17, 2003
KitMaker: 15,338 posts
Armorama: 7,297 posts
Posted: Saturday, January 14, 2006 - 03:35 AM UTC
Already done..
Graywolf
Staff MemberSenior Editor
HISTORICUS FORMA
Visit this Community
Izmir, Turkey / Türkçe
Joined: December 01, 2001
KitMaker: 6,405 posts
Armorama: 1,850 posts
Posted: Saturday, January 14, 2006 - 04:10 AM UTC
Jim..i changed my password and i wish this event will be the last example of CANDY SECURITY in Armorama... for who may not know what it is it is a term coined by Bellovin and Cheswick to describe a security scenario where the outer perimeter, such as a firewall, is strong, but the infrastructure behind it is weak. The term refers to M&M candy, which has a hard outer shell and soft center....so all members should know some (more or less but as it should be due to our access levels) about website security...at least we should think on how not to be hacked easily.


Stormbringer
Visit this Community
England - South East, United Kingdom
Joined: January 20, 2002
KitMaker: 1,667 posts
Armorama: 1,116 posts
Posted: Saturday, January 14, 2006 - 04:32 AM UTC
Done boss.

Pete
 _GOTOTOP