Carson Dyle
Diamond Member
- Jul 2, 2012
- 8,173
- 524
- 126
The reset and the mass mailing were done in conjunction, so yeah, you may log in/be logged into the forums before you get the email.Edit: 5) and just now received my first official email notification of issues.
6) <double sigh>
1) just happen to notice the message at the top of forum several days after the stuff hits the fan.
2) immediately change password.
3) several days later am told at login that my password is over 900 days old and it *has* to be changed.
4) <sigh>
Edit: 5) and just now received my first official email notification of issues.
6) <double sigh>
The reset and the mass mailing were done in conjunction, so yeah, you may log in/be logged into the forums before you get the email.
I also share in this frustration, just changed my PW 2 days ago, now its 905 days old???
I also share in this frustration, just changed my PW 2 days ago, now its 905 days old???
Did some major VBB hack pop up or something? I've been forcibly reset on two other major forums I visit.
I had just changed mine 3 days ago, after someone posted a link to "leakedsource" in an OT thread, and then finding AT on a list dated to March of 2016. But I changed it again today, just in case. Thank god for Keepass.When was it compromised? I just changed my password last week, and then had to change it again today.
I actually wanted to take a moment and thank the mods here for the way they are handling this event. Stuff happens, even to the most secure of sites.
The email I received struck the absolute right tone. I want to thank those responsible for:
1) Admitting there was a breech
2) Giving common-sense advice about the use of passwords (unique for each site, etc.)
3) Not requiring long, complex passwords on this site
A very popular, large A/V forum had a similar breech and hid the fact they were compromised, but required password changes. The password they required was at least 10 digits long, with capital and lower case letters, numbers and a special character. It's a ridiculous standard for non-critical information, and many of us have simply left.
I won't visit them again because they demonstrated they don't understand security at all. They weren't hacked because their USERS had weak passwords.
The fact is that there is no information stored here that compromises any private information about me. It does not require the kind of security standard required by financial sites.
VB 3.x has been considered EOL for years, although 3.8.9 was released in 2014, there have been no updates since, its hard to know how many unpatched security holes there are.
As a security precaution we expired all passwords, as that was the safest thing to do. "905 days" is just an artifact of how we went about it.I also share in this frustration, just changed my PW 2 days ago, now its 905 days old???
Purch bought a forum. Nobody told them they'd have to maintain it.
Morons.
Go ahead and change your password over http so we can store the new one in the same broken way as before?
Purch bought a forum. Nobody told them they'd have to maintain it.
Morons.
We are investigating a data incident with respect to the AnandTech Forums database. We believe that some of our user names and other information may have been accessed. Although our passwords in the database are encrypted, we believe that it is advisable to expire all the passwords in use prior to June 24th, 2016. Consequently, the first time that you go to log in to the AnandTech forums after June 24th, 2016, you will be asked to set a new password.
So that's why I was prompted to change my password.
Can anyone recommend a random password generator?
https://www.grc.com/passwords.htm
