IDNetters Forums

Technical News & Discussion => Broadband, Internet & General Computer News & Discussion => Topic started by: Technical Ben on Jun 26, 2012, 11:31:53

Title: Think it's time...
Post by: Technical Ben on Jun 26, 2012, 11:31:53
To use one of those automated email + password programs that gives you very strong and scrambled details for logging into forums.

http://www.theregister.co.uk/2012/06/26/techradar_data_breach/

:slap:
Title: Re: Think it's time...
Post by: Simon on Jun 26, 2012, 11:36:14
:sigh:
Title: Re: Think it's time...
Post by: armadillo on Jun 26, 2012, 12:00:44
I don't think strong passwords would help, Ben. The hack was most likely a SQL injection, so they simply got access to the entire user database. The article said that encryption was not an obstacle. The only solution is for forum techs to proof the code against SQL injection. SQL injection can exploit forum search features, not just login boxes.
Title: Re: Think it's time...
Post by: gizmo71 on Jun 26, 2012, 12:16:29
Quote from: armadillo on Jun 26, 2012, 12:00:44
I don't think strong passwords would help, Ben. The hack was most likely a SQL injection, so they simply got access to the entire user database. The article said that encryption was not an obstacle.

The encryption of those passwords is still a vital obstacle to actually cracking the passwords themselves - crucial if you use the same password in lots of places (in which case it really needs to be a strong password).
Title: Re: Think it's time...
Post by: Technical Ben on Jun 26, 2012, 13:27:50
Quote from: armadillo on Jun 26, 2012, 12:00:44
I don't think strong passwords would help, Ben. The hack was most likely a SQL injection, so they simply got access to the entire user database. The article said that encryption was not an obstacle. The only solution is for forum techs to proof the code against SQL injection. SQL injection can exploit forum search features, not just login boxes.

Oh, true, I just mean as in site specific and automatically managed. As managing it by head, and having hundreds of different forum logins is a pain...
Title: Re: Think it's time...
Post by: armadillo on Jun 27, 2012, 20:47:30
Quote from: gizmo71 on Jun 26, 2012, 12:16:29
The encryption of those passwords is still a vital obstacle to actually cracking the passwords themselves - crucial if you use the same password in lots of places (in which case it really needs to be a strong password).

Yes, certainly. I do make sure passwords and logins are unique. But that does mean they all have to be written down since I have at least 50 of them. The silliest one I ever had was allocated by a vendor I bought some software from. The password to download from their site was about 500 characters long and contained punctuations, upper and lower case letters and numbers. I doubt anyone could have memorised it :)
Title: Re: Think it's time...
Post by: Technical Ben on Jun 27, 2012, 21:23:57
500 chars? Usually some of it is the actual login page address, but 500 chars? Or was it a 256bit key?  :laugh:
Title: Re: Think it's time...
Post by: nowster on Jun 28, 2012, 00:30:07
Or use Firefox plugin "password hasher"?
Title: Re: Think it's time...
Post by: armadillo on Jun 28, 2012, 16:10:27
Sorry Ben. I wasn't clear. It was indeed 500 charas but it was the "activation key". You entered it in the activation box within the software to activate your licence! Perhaps their £10 measly software had been pirated one too many times. I forget now even what software it was. All I remember about it was its impossible activation key.