That's certainly your right, but do you abandon every site, company that gets hacked as well?I'll be sending an mail today to have my account deleted.
I'm thinking about 1password. Do I have to buy the iPhone/iPad/Mac app seperately? Or buying it at one place give me access throughout?
I want to have all my passwords synced through all devices
Thanks
All I want to know is was this reported to the proper authorities ?
Is that too much to ask ? Or does it take a 4 hour online meeting ?
\
Yes, I understand the legal standard to notify. Thanks. As with most "standards" there is an ethical standard that supersedes the legal requirements. The real issue here is whether there were adequate protections in-place to reasonably protect MacRumors passwords and identities. In your view, were there?
While I agree that everything you read on the internet should be taken with a grain of salt, are those people you're referring to running the forum? It's a rhetorical question: of course they're not. If I'm an expert in something but have no decision-making authority at a place that I frequent, then how does a problem in that venue devalue my expertise?This indicates that most of those who masquerade as forum security experts, cryptographers and lawyers in their posts are hardly those who have real credentials to be making those comments.
While I agree that everything you read on the internet should be taken with a grain of salt, are those people you're referring to running the forum? It's a rhetorical question: of course they're not.
(Note that I'm not a security expert, I'm just taking issue with this line of reasoning.)
If I'm an expert in something but have no decision-making authority at a place that I frequent, then how does a problem in that venue devalue my expertise?
I really think it's time to stop the ranting. .
You used MD5? Are you guys retarded?
Suppose I'm a security expert and I happen to spend my off-time on MacRumors, advising people and helping to troubleshoot. I am not in any administrative or staff position at the forum, which is to say, I do not know the specifics about how the forum is set up or run, nor am I involved in the setup or operation of the forum. The forum gets hacked. What you seem to be saying is that my expertise would be questionable, simply by virtue of my being here and somehow not having prevented what happened?Give me an example and I'll provide a response to that question.
That's certainly your right, but do you abandon every site, company that gets hacked as well?
For instance, in the past few years, I've had 2 credit card companies, 1 bank, MacRumors and Adobe get hacked. All with varying levels of security before the hacking. Do I cancel all my interactions because of hackers?
The exposure of MR's data is a lot more limited then my banks. This is a great site, and I think there are definitely lessons learned regarding this event. Its definitely a teachable moment, just from my perspective. While I kept different passwords across my accounts, I've decided to use a stronger password combination (thanks to 1Password)
Why were you storing our passwords in the first place?
You are supposed to store an irreversible hash of them instead.
Suppose I'm a security expert and I happen to spend my off-time on MacRumors, advising people and helping to troubleshoot. I am not in any administrative or staff position at the forum, which is to say, I do not know the specifics about how the forum is set up or run, nor am I involved in the setup or operation of the forum. The forum gets hacked. What you seem to be saying is that my expertise would be questionable, simply by virtue of my being here and somehow not having prevented what happened?
Yes, vBulletin needs to change their choice of hashing algorithm. I'm surprised they didn't do that after the Ubuntu forums were breached.
I offer an apology, because now I see what you are trying to say, as wellI see what you're trying to say.
I'm honestly not that mad at the site being hacked, **** happens but am a little pissed at the weak password hashing. Surely there must be a modification over at vb.org that has a different hashing scheme.
Somebody apparently cracked my password because I use the same one for Steam and they were able to login (luckily it was blocked thanks to SteamGuard). Change your passwords people!
You have nothing to apologize for. You gave me the opportunity to clarify my previous post so I hope it's much clearer now.Ledgem said:I offer an apology...
I really think it's time to stop the ranting. If people wish to leave the site, as Maflynn says, that's up to them,
Just to put things in perspective here.
From my view the MF would be a much more informative site for Mac help which is what it is supposed to be. If all the goodie two shoes who spend time and wasted bandwidth complaining about everything they read, would just leave and let the rest of us enjoy asking software questions and receiving help from the sincere members who would be left. That is not going to fly.............there are always some who enjoy jumping on the soap box and making derogatory statements. Maybe a change of name for our forum might be in line. Call it the MacForum for complainers.
And on a slightly more positive note (apologies to all)...
SEARCH functions is back up!
Thanks, arn!