The Student Room Group

Scroll to see replies

I'm thinking that, at the very least, your e-mail password and (if relevant) your bank password should be different to all others (and obviously not the same as each other)?

I just went and changed all of my passwords on a 'just in case' basis; sad how few websites that is, really. :getmecoat:

(I also found that the hardest part was trying to remember what I had as my original password. :sigh:)
(edited 11 years ago)
Reply 41
Are changes being made at the moment, or are the instances of people being repeatedly logged out and needing to reset their passwords examples of cracked passwords being exploited?
Original post by Mr Dangermouse
I have an email address that's only used to sign up to TSR but my old TSR password is used in other places. Should it still be changed everywhere?


Yes, change everything which is the same as your previous TSR password.
Reply 43
If I have my bank details on a shopping website, with the same email and password for TSR do you think it'll get hacked and will all my sweet sweet dollas go? :eek:
Reply 44
Original post by RyJ
I know, it's quite scary how this **** can happen...


Especially those who have lost a lot and no ones willing to compensate
Reply 45
Why have most of the flags changed??
Original post by judicious
Why have most of the flags changed??


That's unrelated, clear your cache to fix that :smile:
Reply 47
Original post by estel
Default vB hash is:

$password_hash = md5(md5($password_text) . $user_salt);
With a per-user three character salt which is also stored in the database.

What the actual ****. This is bull****. 5 days to crack any 7 character ascii password using a single half decent GPU :mad:
Reply 48
Original post by cfizzle
If I have my bank details on a shopping website, with the same email and password for TSR do you think it'll get hacked and will all my sweet sweet dollas go? :eek:

Well yes now that you've posted that information here. Probably want to change those passwords.
Reply 49
Original post by EierVonSatan
That's unrelated, clear your cache to fix that :smile:


Thanks, that worked. I thought it was related because of the timing and it has never happened before :colondollar:
So has anyone had their bank account emptied yet?
changed my password...the password i have for this is different from any other account i have on internet but changed password just as a precaution
Reply 52
The joys of my bank using numbers and not letters for it's passwords. I am safe on the bank account front :colonhash:

I think I'll just change everything that uses old TSR password to my new one :h: Though my password is different for YT and other places. I don't think hackers could do that much damage to me to be honest :tongue: My Amazon password needs changing I think though >.>
Original post by Mr Dangermouse
So has anyone had their bank account emptied yet?


Yea, it's called being a student....

I think most banks use numbers rather than words, or use both at least so it's harder to crack and, even better even use number secure keys issued at the time of logging on now so fingers crossed bank passwords will be ok. But if anyone's worried, obviously change your password.
Reply 54
Wtf is going on???!!? :confused:


This was posted from The Student Room's iPhone/iPad App
I am still wondering how/why this happened. Why was the data not secure enough?
Reply 56
Probably wouldn't have happened if the staff spent more time working on security, instead of warning people for literally every pro-Israel post there is. Typical, farcical TSR really, and someone should be sacked over this.
Original post by R4INBOW
Wtf is going on???!!? :confused:


This was posted from The Student Room's iPhone/iPad App


It's come to TSR's attention that some usernames, passwords and email addresses have been compromised. The passwords are hashed and salted so if they are cracked it should take a while but it can't be guaranteed it won't so you need to change your TSR password and any other password which maybe the same as your TSR password ASAP.
Original post by tufc
Probably wouldn't have happened if the staff spent more time working on security, instead of warning people for literally every pro-Israel post there is. Typical, farcical TSR really, and someone should be sacked over this.


Yes, mod duties are to moderate the forums and test the security in every way...
Reply 59
Original post by tufc
Probably wouldn't have happened if the staff spent more time working on security, instead of warning people for literally every pro-Israel post there is. Typical, farcical TSR really, and someone should be sacked over this.


tufc, the Administration team do not moderate users in the same way that the Moderators do not administrate the operation of the site.

Latest

Trending

Trending