Index  | Recent Threads  | Unanswered Threads  | Who's Active  | Guidelines  | Search
 

Quick Go ยป
No member browsing this thread
Thread Status: Active
Total posts in this thread: 16
Posts: 16   Pages: 2   [ 1 2 | Next Page ]
[ Jump to Last Post ]
Post new Thread
Author
Previous Thread This topic has been viewed 941 times and has 15 replies Next Thread
Former Member
Cruncher
Joined: May 22, 2018
Post Count: 0
Status: Offline
Reply to this Post  Reply with Quote 
Account Password Strength

Due to the possibility of a another project having a security breach (their database may have been accessed....revealing account email addresses and passwords) I have been changing the passwords on all of the projects I have accounts with. After detaching from the one in question of course. This is actually something I needed to do for a while as my old password was weak.

So, my new password is much stronger. Unfortunately, WCG is the only project that does not accept non-alphanumeric characters in passwords. shock Having a different password is not a huge deal, but since I have computers in several locations and participate in many projects, I use BAM to manage all of them. This means that I can no longer use BAM for WCG. Again, not the end of the world.

The question is whether or not WCG will modify their password policy to allow for more characters and therefore stonger, more secure passwords.
[Apr 17, 2009 4:12:03 AM]   Link   Report threatening or abusive post: please login first  Go to top 
Former Member
Cruncher
Joined: May 22, 2018
Post Count: 0
Status: Offline
Reply to this Post  Reply with Quote 
Re: Account Password Strength

Hello Teratoma [SETI.USA],
The intention has always been to eventually activate BAM on the WCG. I do not know when this will be done. At that time, the staff will review our policies to see if we should adopt all the current BAM policies.

For the moment, I do not expect any quick changes.

Lawrence
[Apr 17, 2009 4:55:54 AM]   Link   Report threatening or abusive post: please login first  Go to top 
zombie67 [MM]
Senior Cruncher
USA
Joined: May 26, 2006
Post Count: 228
Status: Offline
Project Badges:
Reply to this Post  Reply with Quote 
Re: Account Password Strength

The concern here is not about the ability to use BAM. The concern is that the password policy here is too weak. That needs to be fixed regardless of BAM.
----------------------------------------

[Apr 17, 2009 4:58:38 AM]   Link   Report threatening or abusive post: please login first  Go to top 
Former Member
Cruncher
Joined: May 22, 2018
Post Count: 0
Status: Offline
Reply to this Post  Reply with Quote 
Re: Account Password Strength

It is not the fault of WCG if users want to use a weak password. I use an 8 letter alpha/numeric mixture which is quite strong enuff.....and no matter what policy is used, if what happened is the database was compromised as stated in the firt post, no matter what 'strength' of password you have used, someone has stolen it.....even if it was 2 characters long or 128!
----------------------------------------
[Edit 1 times, last edit by Former Member at Apr 17, 2009 5:28:01 AM]
[Apr 17, 2009 5:27:07 AM]   Link   Report threatening or abusive post: please login first  Go to top 
Sekerob
Ace Cruncher
Joined: Jul 24, 2005
Post Count: 20043
Status: Offline
Reply to this Post  Reply with Quote 
Re: Account Password Strength

Database security breached... hmmm well at WCG I give you zero chance, also because SSL is used and as Scribe says, with the regular codes available, alpha and numeric plus caps, 15 long, security experts think there is a thoroughly secure password to be formatted, IBM thinks it is... heck your banking pin code is just 4 or 5 digit numbers. I've got more concerns about BAM and how they access accounts on projects than my password here, and elements I'd never allow to be changes via BAM, for if you have that password, you've got it effectively for all projects someone participates in.

Anyway, the one critique I have is that I see no query on the Sign-in Manager screen for the old password. There's always conditions when someone walks away from a forum screen while logged in e.g. and a rogue having chance to change email and password without challenge.

just my personal view.
----------------------------------------
WCG Global & Research > Make Proposal Help: Start Here!
Please help to make the Forums an enjoyable experience for All!
----------------------------------------
[Edit 1 times, last edit by Sekerob at Apr 17, 2009 7:13:05 AM]
[Apr 17, 2009 7:07:53 AM]   Link   Report threatening or abusive post: please login first  Go to top 
Former Member
Cruncher
Joined: May 22, 2018
Post Count: 0
Status: Offline
Reply to this Post  Reply with Quote 
Re: Account Password Strength

The sign in manager will require your password if you are signed in with the "Remember Me" feature. As you know, your session times out quickly.
[Apr 17, 2009 7:17:25 AM]   Link   Report threatening or abusive post: please login first  Go to top 
Sekerob
Ace Cruncher
Joined: Jul 24, 2005
Post Count: 20043
Status: Offline
Reply to this Post  Reply with Quote 
Re: Account Password Strength

Does RM only work here long as cookies are not wiped? Does not stick here when tried in past. Those wanting will be there sitting waiting for someone to step away.
----------------------------------------
WCG Global & Research > Make Proposal Help: Start Here!
Please help to make the Forums an enjoyable experience for All!
[Apr 17, 2009 8:01:07 AM]   Link   Report threatening or abusive post: please login first  Go to top 
Former Member
Cruncher
Joined: May 22, 2018
Post Count: 0
Status: Offline
Reply to this Post  Reply with Quote 
smile Re: Account Password Strength

Q1: How many people posted on this thread have passwords using non alphanumeric on other systems even if it is not required?
Q2: How many use 4-5 numbers even if you are allowed to use alpha also?
[Apr 17, 2009 9:32:16 AM]   Link   Report threatening or abusive post: please login first  Go to top 
Sekerob
Ace Cruncher
Joined: Jul 24, 2005
Post Count: 20043
Status: Offline
Reply to this Post  Reply with Quote 
Re: Account Password Strength

Now there you're asking for the first snippet of information from those that are thinking the WCG system is not allowing a strong enough passcode... here mix cap/lower/number and the fun is, my browser is flat instructed to never save any for sites that pop over to https... do they on any other BOINC site ;>)
----------------------------------------
WCG Global & Research > Make Proposal Help: Start Here!
Please help to make the Forums an enjoyable experience for All!
[Apr 17, 2009 10:47:49 AM]   Link   Report threatening or abusive post: please login first  Go to top 
Former Member
Cruncher
Joined: May 22, 2018
Post Count: 0
Status: Offline
Reply to this Post  Reply with Quote 
Re: Account Password Strength

I am not saying that there is a security issue here. I was just stating what has occured and the reason for me changing my passwords on all projects.

WCG has a weaker password policy than all of the other projects I participate in. I realize that WCG did not start as a BOINC project and did not start with their default site template. My concern is not whether or not a breach would occur here exposing all user information. It is simply that I cannot use a stonger password.

WCG is supported in BAM to a certain point....enough for me to do what I have to do. If I can't use it, fine...that won't stop me.

This may not be a bank, but none of my banking accounts allow a 4 digit password to access my account information online. Don't confuse a pin with a password.

The risk is that if a an account is hacked into, someone can theoretically leverage Boinc to access the computers and transmit malicious code to them. Considering that I think that stronger passwords should be mandatory, but I will settle for the option at a minimum.
----------------------------------------
[Edit 1 times, last edit by Former Member at Apr 17, 2009 2:55:53 PM]
[Apr 17, 2009 2:53:42 PM]   Link   Report threatening or abusive post: please login first  Go to top 
Posts: 16   Pages: 2   [ 1 2 | Next Page ]
[ Jump to Last Post ]
Post new Thread