Jump to content

Plus votes give away!


gwnn

Recommended Posts

I do know other bridge players who are members of ravelry, and I know someone else who is a member of both forums, but he is not a frequent poster, and has not posted on this thread.

Sorry to put serious information into a fabulous forum thread like this, but if you don't know about Ravelry being hacked, and to change your password, as well as passwords on any other account anywhere (BBO?) that has the same username/password combination, you should.

 

(please note, link from (yet another site), and as I am not a ravelry member, I can't read it without logging in to confirm, but I trust the several people who pointed this out. *If* I am just scare-mongering, I am really sorry).

  • Upvote 2
  • Downvote 1
Link to comment
Share on other sites

Sorry to put serious information into a fabulous forum thread like this, but if you don't know about Ravelry being hacked, and to change your password, as well as passwords on any other account anywhere (BBO?) that has the same username/password combination, you should.

 

(please note, link from (yet another site), and as I am not a ravelry member, I can't read it without logging in to confirm, but I trust the several people who pointed this out. *If* I am just scare-mongering, I am really sorry).

 

Of course I saw that, it was front page news there. But who is silly enough to have the same username/password combo on different sites that you can spend money?

  • Upvote 1
  • Downvote 1
Link to comment
Share on other sites

Of course I saw that, it was front page news there. But who is silly enough to have the same username/password combo on different sites that you can spend money?

Reminds me of a time I did some contracting for a company in Atlanta and needed a half dozen passwords to get at the various systems involved. Huge red-on-white signs hung in every room:

 

1. Use a different password for each system!

2. Change your passwords every week or lose your privileges!

3. Never use the same password twice!

4. Never write down your passwords!

 

They were very security conscious.

<_<

  • Upvote 2
Link to comment
Share on other sites

Reminds me of a time I did some contracting for a company in Atlanta and needed a half dozen passwords to get at the various systems involved. Huge red-on-white signs hung in every room:

 

1. Use a different password for each system!

2. Change your passwords every week or lose your privileges!

3. Never use the same password twice!

4. Never write down your passwords!

 

They were very security conscious.

<_<

 

Actually they were not.

If you change your password on half a dozen systems every week, you need to learn 6 passwords every week. After a few weeks you will start to mix them up or you will start to invent some systemic change. e.g. use the same password, with the number of the week in the end or you will violate rule 4 and write them down.

So rules 1 and 2 force you to violate rules 3 and 4.

 

Does changing the password help? No really.

Assume it takes 7 days to try all possible passwords, and assume that you change the password at the end of day 1.

If your password was hacked at day 1, the damage was already done.

If it was not hacked, than changing the password has a 6 to 1 chance that the new password is still in the set that hast to be tested. So changing the password will not slow down that hack in 6/7 of the cases. Obviously changing the password will help more if it happens at the end of the 7 day period. If your password is created in a way that it takes much longer than 7 days to hack you will hardly ever benefit from the change.

But ... if you change your system settings in a way that only on login try is allowed in 15 minutes, hacking an insecure 4 digit password will on average take 5000 times 15 minutes which is about 21 hours. Allowing one try every millisecond will allow the hack to be done in about 1.25 seconds.

 

So if these guys where really aware of security, they would have allowed you to pick a long password that you can remember and implemented a slow login retry.

This would allow you to follow rules 1,3 and 4.

 

As to rule 4, if you write down your password and put the paper with the password into a locked drawer of your desk.

It can usually only be accessed by someone who is allowed to enter your office. If your office is inside an access restricted area, the risk from writing down your passwords is very small.

In fact if you are able to use a password that is longer and more complicated, by writing it down the fact that it is more difficult to hack can over compensate for the small risk of writing it down.

  • Upvote 2
Link to comment
Share on other sites

or perhaps we could all go and upvote someone so he feels relieved, since shubi (or was it his name?) is not around anymore I propose pirate22 or TWOferBride

 

Rejoice. Shubi lives:

http://www.bridgebas...opic/46417-tst/

 

Well, over the last year or two, BBF has had flame wars, hurt feelings, and the quality of posts going down.

I expect proof of this assertion to appear shortly.

I confidently expect the quality of posts to rise imminently.

 

(I have low aspirations. My goal is to reach "Excellent")

  • Upvote 2
Link to comment
Share on other sites

FWIW I just + voted myself 40 times after losing ~50 in 2 days of not posting on random old threads, and ~100 in general from lurpoa and some brand new accounts. Sorry if anyone is offended by that action, I am not trying to be a downvote police or whatever, and would not do that just because I disagreed with a BS - vote or something in normal conditions. Posting here to explain/not be shady.
  • Upvote 2
  • Downvote 1
Link to comment
Share on other sites

Finally, in relation to the Lurpoa thing:

 

http://www.bridgebase.com/forums/topic/35619-notice-of-threadpost-moderation/page__st__80__gopid__555917#entry555917

 

Action finally taken against Lurpoa. Rain thinks that Lurpoa was driven to this due to our harassment! I made a long post. My favorite part was remembering that jillybean first mass downvoted everyone in this thread (while downvoting was anonymous), then spammed this thread hoping for + votes (still anon downvoting). Then - votes were public, and I downvoted her, and she messaged me on BBO telling me to stop downvoting her! Haha. That is right up there with Lurpoa's profile posting that is in my signature, while downvoting everyone.

 

Haters gonna hate. At least jilly had the sense to stop downvoting everyone for no reason.

  • Upvote 2
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
×
×
  • Create New...