Sha256

Hacp

Lifer
Jun 8, 2005
13,923
2
81
Does AT store our actual passwords or do they store the salted SHA256 value?
 

Markbnj

Elite Member <br>Moderator Emeritus
Moderator
Sep 16, 2005
15,682
14
81
www.markbetz.net
The common practice (i.e. accepted industry standard/best practice) is to store the hash and salt, send the submitted credential to the back end over TLS, hash it there and compare the values.
 

Platypus

Lifer
Apr 26, 2001
31,046
321
136
vbulletin uses md5 the last I looked, laff, but who knows in our unsupported ALPHA version of the software

more alarming is that a technology forum still refuses to implement any form of TLS transport security. jokes^jokes
 

Beer4Me

Senior member
Mar 16, 2011
564
20
76
The AT forums had a password breach in March 2016 according to leakedsource.com.
 

FerrelGeek

Diamond Member
Jan 22, 2009
4,669
266
126
Not worried. I use a password on here that I only use for discussion forums. I have a much more secure one for real stuff.
 

Jeff7

Lifer
Jan 4, 2001
41,596
19
81
The articles I've read on it make it sound like any password a human can reasonably memorize is going to have patterns that a computer can recognize and use in order to generate a password library. (Or that a human can type in a reasonable amount of time. Sure, a 512-character password might - might - be secure, but it's slightly inconvenient.)

Wouldn't the only real solution to that problem be to always use a strong, salted hash?
 

Elixer

Lifer
May 7, 2002
10,371
762
126
Wouldn't the only real solution to that problem be to always use a strong, salted hash?
Naw, they need to go to public/private keys, kinda like PGP.
That would pretty much eliminate password guessing, and instead would require the key (& the passphrase).
 

TwiceOver

Lifer
Dec 20, 2002
13,544
44
91
The AT forums had a password breach in March 2016 according to leakedsource.com.

Maybe this is why I got an email from Amazon today asking me to change my password because they found my email address in a list of password/emails.
 

Schmide

Diamond Member
Mar 7, 2002
5,595
730
126
I'd like to clarify now that every stupid thing I said here was hackers.
 

Ns1

No Lifer
Jun 17, 2001
55,418
1,599
126
I would also like to apologize for all the errant dick pics and bull penis topics. Because hackers.
 

slugg

Diamond Member
Feb 17, 2002
4,723
78
91
Your passwords are stored in a shared text file on DropBox. That's how you can access the forums from many internets.
 

Markbnj

Elite Member <br>Moderator Emeritus
Moderator
Sep 16, 2005
15,682
14
81
www.markbetz.net
There was a thread on this briefly yesterday morning in OT.

Yeah that was my post, which included a screen cap of my own password in clear text. The new forum owners pulled it until they could "figure out what happened."

Now this morning I see a forum announcement claiming that "Our passwords in the database are encrypted and we currently do not have any reason to believe the incident resulted in those being revealed." It then goes on to suggest users change their password. Nothing like a big plate of corporate double speak for breakfast.

The passwords in the database are not encrypted. They are hashed with a very weak md5 hash algorithm, and at least some of them were most definitely revealed. Most of the mods received screen caps of their own email addresses and passwords in email yesterday morning from an interested party who was trying to warn everyone. Several mods/former mods, myself included, verified that the hashes and salts were correct for the passwords.

Message of the day: ignore the forum announcement, change your passwords.
 
Last edited:

Ns1

No Lifer
Jun 17, 2001
55,418
1,599
126
Most of the mods received screen caps of their own email addresses and passwords in email yesterday morning from an interested party who was trying to warn everyone. Several mods, myself included, verified that the hashes and salts were correct for the passwords.

Message of the day: ignore the forum announcement, change your passwords.

daaaaaaaaaaaaaaaaaaaaaaaaaaaaaaamn
 

Ns1

No Lifer
Jun 17, 2001
55,418
1,599
126
goddamnit slapped my email into leakedsource.com

https://www.leakedsource.com/

Search completed in: 0.7102 seconds.

Linkedin.com has: 1 result(s) found. This data was hacked on approximately 2012-06-05 00:00:00 What is in this database?
VerticalScope Network (Vbulletin) (939 Websites) has: 1 result(s) found. This data was hacked on approximately 2016-02-01 00:00:00 What is in this database?
Dodonew.com (Chinese) has: 1 result(s) found. This data was hacked on approximately 2012-01-01 00:00:00 What is in this database?
Gawker has: 1 result(s) found. This data was hacked on approximately 2010-12-01 00:00:00 What is in this database?
Anandtech.com has: 1 result(s) found. This data was hacked on approximately 2016-03-15 00:00:00 What is in this database?
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |