Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.
In situations like this, it's best to assume that your MacRumors Forum username, email address and (hashed) password is now known.

Just curious.... what is the best way for websites to store and protect this sort of data?

And why isn't every website doing that RIGHT NOW?

I often wonder this... after reading about the countless attacks like these over the years.
 
Just curious.... what is the best way for websites to store and protect this sort of data?

And why isn't every website doing that RIGHT NOW?

I often wonder this... after reading about the countless attacks like these over the years.

salt and pepper encryption system , which few use.

most just salt them and store in DB

designed a few myself.....there unstoppable.
 
The hackers harvest as much as they can - email, account logins, password if they can. They have automated tools that will then go through and try to get into other sites/email using that info.

Since many people will use the same details, if they even manage to get into a few peoples actual details, thats worth it. From then on its your bank, credit card etc they can target.

If all else fails, they still sell the stolen data to a bunch of data miners for marketing purposes. e.g. things like average age of poster, where they live, name etc etc.

Its all very scary and very real :mad:
 
Imagine if you could use touch id to log into websites when you're on an iOS device in safari :O without your print being stored. Is this possible that would be awesome
 
I'm changing other sites' passwords in other Safari's tabs, while MacRumors is oppened in this Safari tab. Is this safe? Or may be any security issue entering MacRumors? Thanks.

Imagine if you could use touch id to log into websites when you're on an iOS device in safari :O without your print being stored. Is this possible that would be awesome
That would be awesome, yes.
 
Well this is annoying - iCloud Keychain doesn't even work for this site (it doesn't remember the password when I log in on my iPad/iPhone).
 
Genuine question -

Say, for example, that I let Safar create a complex password for my online banking site. It will be saved and available across Safari on all of my devices. That's great!

How about when I need to enter the complex password into my online banking iOS app? How does that work?
Obviously I didn't memorize the password. Can I copy and paste it from Safari?

I want to love this feature, but I use so many apps with log-ins that I don't know how useful it will be for most sites that also have apps.

To see the complex password stored by safari on your iOS device, simply go to Settings>Safari>Passwords & AutoFill>Saved Passwords and select the site you need the saved password for, enter your device passcode and copy the password from there using the normal iOS copy and paste routine.
 
Well this is annoying - iCloud Keychain doesn't even work for this site (it doesn't remember the password when I log in on my iPad/iPhone).

It worked with my ipad air once I logged off macrumors and then back in.
 
If my iMessage and FaceTime were randomly set up on a device without my consent, doesn't that mean my Apple ID was hacked? It used to have the same password as MacRumors.
 
Well this is annoying - iCloud Keychain doesn't even work for this site (it doesn't remember the password when I log in on my iPad/iPhone).

1. Enter User Name and Password in Macrumors Forum Login
2. Do Not Hit Log In
3. Instead Refresh Page in Safari
4. Dialog Box asks if you want to reload page, click Reload
5. Keychain dialog box should now come up

Source: https://forums.macrumors.com/threads/1661881/

Edit: Why doesn't it work for Bank of America and other sites similar to this? Will we see updates on Keychain's side of the website to get functionality up to par?
 
Last edited:
Reset Passwords For All Users?

Why don't you guys reset the passwords for all users? Tons of people aren't going to reset them because they'll never hear the news.
 
If my iMessage and FaceTime were randomly set up on a device without my consent, doesn't that mean my Apple ID was hacked? It used to have the same password as MacRumors.

You've been asking this question for a few hours now. Have you gone to apple and reset your password ?

Hopefully you have.
 
If my iMessage and FaceTime were randomly set up on a device without my consent, doesn't that mean my Apple ID was hacked? It used to have the same password as MacRumors.

It's possible...very possible. I would advise you to change all of your passwords that are the same and then I will tell you to be smarter with your accounts next time. Your iCloud password is sacred. No other password should be the same. Just like your bank account.
 
You've been asking this question for a few hours now. Have you gone to apple and reset your password ?

Hopefully you have.

Yes, I have. I'm just worried about other accounts as well. Are iCloud generated passwords secure enough? The password I was using before seems a lot more complex to me (more special characters, not just hyphens)
 
If MacRumors was really taking this as seriously as they portray to be then the article on the front page would stay at the top of the page for an extended period of time. Instead the article has already been pushed down by two other articles and tomorrow it probably won't even be on the front page anymore. Almost seems intentional to try and get it off of the front page as soon as possible. Not surprised that it wasn't a second page story.

This is a good textbook case of how not to handle security and and how not to react to being hacked.
 
If this happened to the Ubuntu forums a few months back, why didn't you idiots do something about it before it happened to you?

You should all be fired.

That's like saying some people in China got the Bird Flu and you heard about it but didn't get the bird flu vaccine because you were a continent away and then a few months later you contracted the bird flu. The are plenty of forums using vbulletin, the odds were in their favor.

So disrespectful. And you should stop coming here if you really feel that way. They didn't ask you to come here, you came on your own.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.