Were passwords hashed, salted, plain text...?
lmao, probably plain text. I'm gone.
Were passwords hashed, salted, plain text...?
Why isn't macrumors using SSL/TLS on at least it's login pages? I tried to use it got a proxy error and a certificate warning about a godaddy cert. The proxy error came from a site that ironically claims to block hacking attempts, guess that's not working out real well is it? I'd ask for a refund on that service.
.
Shouldn't MacRumors force a password reset for every forum account? That's what I've seen other sites do that had their data compromised in the past...
I hate forced password resets. I'll decide for myself when to change my damn password.
Keychain won't remember my new password that is suggested by Apple. Instead, it keeps my old password that I had before I changed. How do I make it save my new password? I tried deleting it from the list of passwords in options but I can't get the new one to get saved there. I've reset my password about 7 times now.
You guys are using salted/hashed passwords right... right? That's what it says in the Canonical blog so I assume that's the case since you said the incident is similar.
If that is the cade I'm not too worried. That said, you should take the time to switch away from MD5 if you haven't already.
Why isn't macrumors using SSL/TLS on at least it's login pages?
lmao, probably plain text. I'm gone.
I think you will find there are some laws in place that require the site to notify anyone who is affected by this.
My iMessage and FaceTime were just added to device " " (blank)? What the hell is going on?
Which is not that strong...
I'm having the same issue, pretty much trying the same things you are.
Shouldn't MacRumors force a password reset for every forum account? That's what I've seen other sites do that had their data compromised in the past...
So why do you use it instead of something stronger? And why were email addresses stored without any encryption?
I'm sure someone has already told you this comic is massively incorrect.
In the english words you don't count each individual letter as that assumes the attackers have never heard of a dictionary.
Originally Posted by gnasher729:
I think you will find there are some laws in place that require the site to notify anyone who is affected by this.
Do tell.