Index | Recent Threads | Unanswered Threads | Who's Active | Guidelines | Search |
![]() |
World Community Grid Forums
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
No member browsing this thread |
Thread Status: Active Total posts in this thread: 16
|
![]() |
Author |
|
Former Member
Cruncher Joined: May 22, 2018 Post Count: 0 Status: Offline |
Due to the possibility of a another project having a security breach (their database may have been accessed....revealing account email addresses and passwords) I have been changing the passwords on all of the projects I have accounts with. After detaching from the one in question of course. This is actually something I needed to do for a while as my old password was weak.
So, my new password is much stronger. Unfortunately, WCG is the only project that does not accept non-alphanumeric characters in passwords. ![]() The question is whether or not WCG will modify their password policy to allow for more characters and therefore stonger, more secure passwords. |
||
|
Former Member
Cruncher Joined: May 22, 2018 Post Count: 0 Status: Offline |
Hello Teratoma [SETI.USA],
The intention has always been to eventually activate BAM on the WCG. I do not know when this will be done. At that time, the staff will review our policies to see if we should adopt all the current BAM policies. For the moment, I do not expect any quick changes. Lawrence |
||
|
zombie67 [MM]
Senior Cruncher USA Joined: May 26, 2006 Post Count: 228 Status: Offline Project Badges: ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
The concern here is not about the ability to use BAM. The concern is that the password policy here is too weak. That needs to be fixed regardless of BAM.
----------------------------------------![]() |
||
|
Former Member
Cruncher Joined: May 22, 2018 Post Count: 0 Status: Offline |
It is not the fault of WCG if users want to use a weak password. I use an 8 letter alpha/numeric mixture which is quite strong enuff.....and no matter what policy is used, if what happened is the database was compromised as stated in the firt post, no matter what 'strength' of password you have used, someone has stolen it.....even if it was 2 characters long or 128!
----------------------------------------[Edit 1 times, last edit by Former Member at Apr 17, 2009 5:28:01 AM] |
||
|
Sekerob
Ace Cruncher Joined: Jul 24, 2005 Post Count: 20043 Status: Offline |
Database security breached... hmmm well at WCG I give you zero chance, also because SSL is used and as Scribe says, with the regular codes available, alpha and numeric plus caps, 15 long, security experts think there is a thoroughly secure password to be formatted, IBM thinks it is... heck your banking pin code is just 4 or 5 digit numbers. I've got more concerns about BAM and how they access accounts on projects than my password here, and elements I'd never allow to be changes via BAM, for if you have that password, you've got it effectively for all projects someone participates in.
----------------------------------------Anyway, the one critique I have is that I see no query on the Sign-in Manager screen for the old password. There's always conditions when someone walks away from a forum screen while logged in e.g. and a rogue having chance to change email and password without challenge. just my personal view.
WCG
----------------------------------------Please help to make the Forums an enjoyable experience for All! [Edit 1 times, last edit by Sekerob at Apr 17, 2009 7:13:05 AM] |
||
|
Former Member
Cruncher Joined: May 22, 2018 Post Count: 0 Status: Offline |
The sign in manager will require your password if you are signed in with the "Remember Me" feature. As you know, your session times out quickly.
|
||
|
Sekerob
Ace Cruncher Joined: Jul 24, 2005 Post Count: 20043 Status: Offline |
Does RM only work here long as cookies are not wiped? Does not stick here when tried in past. Those wanting will be there sitting waiting for someone to step away.
----------------------------------------
WCG
Please help to make the Forums an enjoyable experience for All! |
||
|
Former Member
Cruncher Joined: May 22, 2018 Post Count: 0 Status: Offline |
Q1: How many people posted on this thread have passwords using non alphanumeric on other systems even if it is not required?
Q2: How many use 4-5 numbers even if you are allowed to use alpha also? |
||
|
Sekerob
Ace Cruncher Joined: Jul 24, 2005 Post Count: 20043 Status: Offline |
Now there you're asking for the first snippet of information from those that are thinking the WCG system is not allowing a strong enough passcode... here mix cap/lower/number and the fun is, my browser is flat instructed to never save any for sites that pop over to https... do they on any other BOINC site ;>)
----------------------------------------
WCG
Please help to make the Forums an enjoyable experience for All! |
||
|
Former Member
Cruncher Joined: May 22, 2018 Post Count: 0 Status: Offline |
I am not saying that there is a security issue here. I was just stating what has occured and the reason for me changing my passwords on all projects.
----------------------------------------WCG has a weaker password policy than all of the other projects I participate in. I realize that WCG did not start as a BOINC project and did not start with their default site template. My concern is not whether or not a breach would occur here exposing all user information. It is simply that I cannot use a stonger password. WCG is supported in BAM to a certain point....enough for me to do what I have to do. If I can't use it, fine...that won't stop me. This may not be a bank, but none of my banking accounts allow a 4 digit password to access my account information online. Don't confuse a pin with a password. The risk is that if a an account is hacked into, someone can theoretically leverage Boinc to access the computers and transmit malicious code to them. Considering that I think that stronger passwords should be mandatory, but I will settle for the option at a minimum. [Edit 1 times, last edit by Former Member at Apr 17, 2009 2:55:53 PM] |
||
|
|
![]() |