Attention - Password and Security Update - Chevelle Tech
Chevelles.com Site Discussion Website questions, feedback, comments, suggestions.

 53Likes
Reply
 
LinkBack Thread Tools Search this Thread Display Modes
post #1 of 206 (permalink) Old Jun 14th, 16, 11:00 AM Thread Starter
Administrator
Test
 
Join Date: Jan 2010
Posts: 1,099
Garage
Attention - Password and Security Update

Hello all,

Over the next few days we will be implementing some changes to our forum password strength and password expiration policies. To make sure you continue having the best experience possible on the community, we regularly monitor the site and the Internet to keep everyone's account information safe. We've recently become aware of a potential risk to some accounts coming from outside of this community. Just to be safe, we are implementing the following changes to improve security even further:

1) We are asking everyone to change their passwords (and will force a one time reset). Along with every user on the forum, new passwords will need to be more complex, and can't be simple words (sorry, you can't have "fluffy" as your password anymore!). Please use a password unique to this community. Reusing passwords can expose your account indirectly when other websites (Twitter, Linkedin, Badoo, etc) are compromised; and

2) Your passwords will expire on a 365 day basis. When you login on the 366th day, you will have to change it.

We'll also be sending out an email to users to let them know about the changes, in upcoming weeks.

Thanks all,

Helena

Community Management


To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.
Administrator is offline  
Sponsored Links
Advertisement
 
post #2 of 206 (permalink) Old Jun 14th, 16, 8:05 PM
Senior Tech Team
Chevelle Doctor
 
Join Date: Aug 1998
Location: Ft Wayne In.
Posts: 13,028
Re: Attention - Password and Security Update

OH my Fuching DAMN! I've had the same simple 5 character password for almost 20 years and no one has hacked my account yet.

Why don't you concentrate on more important things like how to fit ads on EVERY SQUARE INCH OF THIS WEBSITE!!!!!!!!!!!!

Roll my FUCHING eyes...
Alan F, Mr. D, Derek69SS and 9 others like this.

Authentication and pre-purchase inspection service still available. PM me for more information.
To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.

Still looking for that elusive 76 Nova SS.
People who have nothing better to do than b!tch about signatures need to get a life.
To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.

70 Chevelle L78/M21
10 Avalanche LT 1500 4wd
06 Equinox
Dave Birdwell is offline  
post #3 of 206 (permalink) Old Jun 14th, 16, 8:18 PM
Ken
 
Join Date: Mar 2006
Location: McPherson Ks
Posts: 21
Re: Attention - Password and Security Update

Well Said
KWCCHEVELLES is offline  
 
post #4 of 206 (permalink) Old Jun 14th, 16, 11:50 PM
Tech Team
Nick
 
Join Date: Aug 2008
Location: South Jersey
Posts: 198
Re: Attention - Password and Security Update

Amen

'67 Malibu 355/th350, Aluminum 5.3 swap in the works
'73 Malibu 4.8/th350
alowerlevel is offline  
post #5 of 206 (permalink) Old Jun 14th, 16, 11:58 PM
Senior Tech Team
Vince
 
Join Date: Sep 2006
Location: Los Lunas, NM
Posts: 8,319
Re: Attention - Password and Security Update

yea

68-Malibu 427bbc/t4oo/3.73-12bolt/pro charger f1-r
VinceS427bb is offline  
post #6 of 206 (permalink) Old Jun 15th, 16, 1:04 AM
Administrator
 
Join Date: Feb 1999
Location: Marana, AZ
Posts: 16,031
Garage
Re: Attention - Password and Security Update

Real classy replies. If the folks that own this site think it is needed then just live with it.
70SSTHUMPER likes this.
Philip is offline  
post #7 of 206 (permalink) Old Jun 15th, 16, 9:29 AM
Gold Founding Member
Administrator
 
Join Date: Aug 1998
Location: near Kansas City
Posts: 61,190
Garage
Re: Attention - Password and Security Update

Looks like somebody is really getting to be an old grouch.
Set his password to expire every 7 days

Better just not advise these folks next time Helena.
70SSTHUMPER likes this.

.
.
.
.


To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.


To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.
Dean is offline  
post #8 of 206 (permalink) Old Jun 15th, 16, 9:48 AM
Senior Tech Team
Chevelle Doctor
 
Join Date: Aug 1998
Location: Ft Wayne In.
Posts: 13,028
Re: Attention - Password and Security Update

Dean, that would be one sure way of eliminating a valuable source of helpful information. It's pretty sad, the direction this website is going.
Stokerboats likes this.
Dave Birdwell is offline  
post #9 of 206 (permalink) Old Jun 15th, 16, 10:08 AM
Gold Founding Member
Administrator
 
Join Date: Aug 1998
Location: near Kansas City
Posts: 61,190
Garage
Re: Attention - Password and Security Update

Of course I was kidding Dave but seriously I don't know why anybody would be upset over them trying to make the site more secure with all the hacking that is going on now days.

On the other hand, I can't imagine any hacker wanting to hack my account. I mean what are they going to do, make a post as me or use my email to send out spam?

You know there are things you can do to keep you from seeing ads.
I see zero ads myself.
70SSTHUMPER likes this.

.
.
.
.


To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.


To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.
Dean is offline  
post #10 of 206 (permalink) Old Jun 15th, 16, 1:07 PM
Lifetime Premium Member
Jimmy
 
Join Date: Jun 2014
Location: Texas
Posts: 152
Re: Attention - Password and Security Update

I wonder if this has anything to do with it.

Hacker steals 45 million accounts from hundreds of car, tech, sports forums | ZDNet
Yukon0724 is offline  
post #11 of 206 (permalink) Old Jun 15th, 16, 2:00 PM
Gold Founding Member
Administrator
 
Join Date: Aug 1998
Location: near Kansas City
Posts: 61,190
Garage
Re: Attention - Password and Security Update

Quote:
Originally Posted by Yukon0724 View Post
I guess maybe that does make sense because a lot of people use the same password for all their stuff.

.
.
.
.


To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.


To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.
Dean is offline  
post #12 of 206 (permalink) Old Jun 15th, 16, 2:19 PM Thread Starter
Administrator
Test
 
Join Date: Jan 2010
Posts: 1,099
Garage
Re: Attention - Password and Security Update

Quote:
Originally Posted by Yukon0724 View Post
Quote:
Originally Posted by Dean View Post
I guess maybe that does make sense because a lot of people use the same password for all their stuff.
That's a big part of it. Plus, with basic information like user id's and emails, simple passwords can be easily broken.

As for the article, fails to mention that the breach was for a third party plugin. This breach is on countless sites across the internet and not just limited to ours.

Their system was compromised and they grabbed user data for us and thousands of others. We cleared our part of the breach and went this route to further security. This is also in place as many members on the internet use the same or similar passwords across all things they use.

We cannot go into detail at the moment as it is being dealt with on a legal level.

Thanks,

Kevin


To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.
Administrator is offline  
post #13 of 206 (permalink) Old Jun 15th, 16, 4:05 PM
Senior Tech Team
Steve
 
Join Date: Sep 2015
Location: Central MA
Posts: 1,247
Re: Attention - Password and Security Update

Unless you are storing passwords in unencrypted plaintext, how did they steal the passwords, unless they were keylogging or stole all your encryption keys?

And if you are storing them in plaintext -

Quote:
Originally Posted by Administrator View Post
That's a big part of it. Plus, with basic information like user id's and emails, simple passwords can be easily broken.

As for the article, fails to mention that the breach was for a third party plugin. This breach is on countless sites across the internet and not just limited to ours.

Their system was compromised and they grabbed user data for us and thousands of others. We cleared our part of the breach and went this route to further security. This is also in place as many members on the internet use the same or similar passwords across all things they use.

We cannot go into detail at the moment as it is being dealt with on a legal level.

Thanks,

Kevin

1972 Chevelle, 454, 2004r, 4.10
1981 Camaro Z28, 355, TH350, 3.73
lucifershammer is offline  
post #14 of 206 (permalink) Old Jun 16th, 16, 12:49 PM Thread Starter
Administrator
Test
 
Join Date: Jan 2010
Posts: 1,099
Garage
Re: Attention - Password and Security Update

Passwords are encrypted. We do not keep passwords in plain text.

However, if your password is simple enough, having the encrypted file along with with basic info like Username and email means your password could be broken pretty easily. The new additional requirements for password complexity will patch that hole.

Kevin


To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.
Administrator is offline  
post #15 of 206 (permalink) Old Jun 16th, 16, 12:59 PM
Senior Tech Team
Chris
 
Join Date: Aug 2002
Location: Alberta, Canada
Posts: 5,947
Re: Attention - Password and Security Update

The password reset crap is super annoying. It shouldn't be reset ever year. That's the kind of stuff forced down in work atmospheres. Personally I don't see the need for the change since none of the big classic car forums seem to have a problem.

Recently Team Chevelle went through a facelift and other little changes, during this was there a new program installed that has security risks?

1971 Chevelle SS454, T56 Magnum 6 speed, 3.31 Posi

Youtube Channel.
To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.

Instagram:
To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.

Twitter:
To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.
-SS454- is offline  
Sponsored Links
Advertisement
 
Reply

Quick Reply
Message:
Options

Register Now



In order to be able to post messages on the Chevelle Tech forums, you must first register.
Please enter your desired user name, your email address and other required details in the form below.

User Name:
Password
Please enter a password for your user account. Note that passwords are case-sensitive.

Password:


Confirm Password:
Email Address
Please enter a valid email address. Note, you will be sent a confirmation request to this address.

Email Address:
OR

Log-in









Old Thread Warning
This Thread is more than 1133 days old. It is very likely that it does not need any further discussion and thus bumping it serves no purpose.
If you still feel it is necessary to make a new reply, you can still do so though.

Thread Tools Search this Thread
Show Printable Version Show Printable Version
Email this Page Email this Page
Search this Thread:

Advanced Search
Display Modes
Linear Mode Linear Mode



Posting Rules  
You may post new threads
You may post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

 
For the best viewing experience please update your browser to Google Chrome