7 Pages V  1 2 3 > »   
Closed TopicStart new topic
> Login security changes, You shall not pass

 
post Feb 21 2015, 13:52
Post #1
Tenboro

Admin




Due to a large increase to the number of brute-force login attempts against member accounts, there have been some hardening changes made to the login mechanism to thwart this. For most of you this will never come into play, but if you fail multiple login attempts or connect from what the site considers a suspect IP, you will now also have to solve a captcha for every login attempt. Hosts that fail a large number of attempts may be shut out entirely.

Note that if you are using a weak password, one that closely resembles your login username, or one that you've reused on other sites, you may want to change it just to be safe.

If you keep getting 7-day bans, your account is likely compromised, and you need to reset your password to restore functionality.
User is online!Profile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 21 2015, 14:28
Post #2
xmagus



Big, Bad and Horny
*******
Group: Members
Posts: 1,042
Joined: 16-July 12
Level 424 (Godslayer)


Hmm, interesting.

Will there be a move towards using SSL/TLS on the various EH-operated sites (which, presumably, might mean enabling SSL on H@H as well) at some stage?


--------------------
Come visit my shop! (Massive update 16 May 2013) Might be something that interests you there. Lowest prices guaranteed by way of matching. Low-level players are sure to get something good!

Loving my Magnificent Fiery Mace of the Battlecaster.

This Exquisite Ethereal Estoc of Slaughter is courtesy of ChosenUno. All Hail Uno, creator of the Riddle Limiter!
User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 21 2015, 14:32
Post #3
Tenboro

Admin




QUOTE(xmagus @ Feb 21 2015, 13:28) *
Will there be a move towards using SSL/TLS on the various EH-operated sites (which, presumably, might mean enabling SSL on H@H as well) at some stage?


Probably not for H@H, at least not before HTTP/2 is implemented, but possibly for the site itself.
User is online!Profile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 21 2015, 14:41
Post #4
EsotericSatire



Look, Fat.
**********
Group: Catgirl Camarilla
Posts: 9,643
Joined: 31-July 10
Level 500 (Ponyslayer)


Pony authenticator?


--------------------
Only My Electro Mage
Staff: Staff (0.82) Staff (0.83)
Main Mjolnir Gear: Cap Robe Gloves Pants Shoes
Forgotten Fenrir: Staff Cap Robe Gloves Pants Shoes

Send +Karma to make King Marien (lvl 2250) stronger:
Battles Won: 15869



Project Preempt and Defuse: Releasing genetically engineered viruses to prevent future SARS pandemics (Ecohealth 2018 Famous last words)
User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 21 2015, 15:25
Post #5
uareader



Critter
*********
Group: Catgirl Camarilla
Posts: 5,245
Joined: 1-September 14
Level 500 (Ponyslayer)


As long as it doesn't make sad pandas even more deadly, it should be ok ph34r.gif


--------------------
*******/O\*******
/*** My fighting style ***\
O ** Equipment gallery ** O
\***** Karma link *****/
*******\O/*******

( only)My thoughts as I watch anime
User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 21 2015, 15:55
Post #6
Tenboro

Admin




QUOTE(EsotericSatire @ Feb 21 2015, 13:41) *

Pony authenticator?


Not really usable for a login page since the chance for success by picking randomly is too large.
User is online!Profile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 21 2015, 16:16
Post #7
derpderp2



Casual Poster
***
Group: Gold Star Club
Posts: 207
Joined: 30-August 12
Level 434 (Godslayer)


just got to remember your password i guess tongue.gif
User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 21 2015, 16:31
Post #8
tetron



Certified Retard!
*********
Group: Gold Star Club
Posts: 5,583
Joined: 30-July 14
Level 483 (Godslayer)


Does nobody use the "Remember Me" option? huh.gif


--------------------
The statement below is true.
The statement above is false.

--------------------
User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 21 2015, 17:51
Post #9
kainord



Missing Time
*******
Group: Gold Star Club
Posts: 2,193
Joined: 10-July 10
Level 500 (Dovahkiin)


I use the remember me option, so i forgot my password smile.gif it would suck to need a relog now smile.gif
But security upgrades are always a good news, for me at least.


--------------------
User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 21 2015, 18:00
Post #10
Binglo



Y'all got anymore of them tags?
**********
Group: Global Mods
Posts: 9,671
Joined: 16-December 09
Level 455 (Godslayer)


Big T, keeping us all safe.


--------------------
Treat others like you want to be treated.

Want to suggest a new tag? Read this.

_______________________________________________________________
User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 21 2015, 18:03
Post #11
Spectre



The Bell Tolls for All.
**********
Group: Global Mods
Posts: 8,354
Joined: 8-February 06
Level 269 (Godslayer)


Probably what happened to bunbun a couple nights ago... *shrug*


--------------------
QUOTE
Spectre: you're crying on the inside aren't you?
BunBun: slightly
BunBun: it's kind of like
BunBun: a tear ran down my face
BunBun: and you licked it off and laughed
Spectre: XDD

When you do things right, people won’t be sure you’ve done anything at all.

↓ Click Me! ↓

{/assist} {Can I have it?} {Please Check it.} {Thank you.} My Uploads
User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 21 2015, 18:40
Post #12
digons



Lurker
Group: Lurkers
Posts: 1
Joined: 25-October 13
Level 5 (Beginner)


Well at least it's a good news to me.... lol
User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 21 2015, 18:55
Post #13
blue penguin



in umbra, igitur, pugnabimus
***********
Group: Global Mods
Posts: 10,027
Joined: 24-March 12
Level 500 (Godslayer)


If one wants to login from an unsafe network he can always go to / and login through there, right? (this does not prevent session hijacking, but prevent password spoofing)


--------------------
QUOTE(blue penguin @ Jun 21 2021, 17:24)
For 10 years of my life I have refused to add if-else blocks in order to support internet explorer idiocy, am not going to start doing it now in order to support google chrome's idiocy. Sorry folks. As harsh as the advice sounds my advice will be: use a browser that follows IETF standards.
User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 22 2015, 00:25
Post #14
Tenboro

Admin




QUOTE(blue penguin @ Feb 21 2015, 17:55) *
If one wants to login from an unsafe network he can always go to / and login through there, right? (this does not prevent session hijacking, but prevent password spoofing)


That is the only way to log in, the other login forms all direct you there to complete the process.
User is online!Profile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 22 2015, 00:52
Post #15
chivoef



Tragic hero
********
Group: Gold Star Club
Posts: 4,061
Joined: 12-January 10
Level 500 (Hero)


Is there some easy way to tell your account has been compromised? Just in case.

<-- paranoid
User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 22 2015, 00:55
Post #16
blue penguin



in umbra, igitur, pugnabimus
***********
Group: Global Mods
Posts: 10,027
Joined: 24-March 12
Level 500 (Godslayer)


Ops... my mistake, i haven't monitored my EH login with wireshark (or something similar) since it changed last time.

Given that the authentication takes some time the brute force attacks must have been very directed, i.e. they must have known the password (or a likehood of the password) from another source. I cannot find a hash of my password in my cookies so there must be some salt on EH side. I do not believe that whoever got the passwords got some hash to compare against.

BTW Tenb, when you change your password do all your sessions are invalidated? The session time on EH is quite long (i never managed to expire it myself, i always cleaned cookies) therefore someone that managed to get hold of an account may open a session and use it for a long time.

This post has been edited by blue penguin: Feb 22 2015, 00:59


--------------------
QUOTE(blue penguin @ Jun 21 2021, 17:24)
For 10 years of my life I have refused to add if-else blocks in order to support internet explorer idiocy, am not going to start doing it now in order to support google chrome's idiocy. Sorry folks. As harsh as the advice sounds my advice will be: use a browser that follows IETF standards.
User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 22 2015, 02:28
Post #17
mozilla browser



Nutscrape Navigator
*******
Group: Gold Star Club
Posts: 2,131
Joined: 22-December 11
Level 500 (Godslayer)


What happened to bunbun a few days ago?

Are the attacks directed (specific account names, rich/high level accounts etc ) or generally random and hitting lotsa accounts including non-existent ones?

What do they do once they get in?


--------------------
WTS Crystal packs, Precursor Artifacts, and other japtem

Dark mage: Staff Cap Robe Gloves Pants Shoes
Fire mage: Staff Cap Robe Gloves Pants Shoes
1H: Rapier Shield Helmet Armor Gauntlets Leggings Boots
User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 22 2015, 02:31
Post #18
hzqr



Savagely Still
********
Group: Gold Star Club
Posts: 4,671
Joined: 13-May 09
Level 453 (Dovahkiin)


Any educated guesses on the motive behind the mass brute-forcing?
I can think of HV and one other reason, but in both cases it would still be rather excessive
User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 22 2015, 02:36
Post #19
Maximum_Joe



Legendary Poster
***********
Group: Gold Star Club
Posts: 24,074
Joined: 17-April 11
Level 500 (Dovahkiin)


QUOTE(tiap @ Feb 21 2015, 17:31) *

Any educated guesses on the motive behind the mass brute-forcing?

China; they're coming for our hentai money!


--------------------
Try to fill your life with good things.
User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 22 2015, 02:39
Post #20
Tresik



Newcomer
*
Group: Recruits
Posts: 14
Joined: 13-March 13
Level 247 (Godslayer)


Well, as always, keeping same passwords in multiple services or otherwise easy to guess password is very bad idea. Because people tend to do that it is also good idea to sometimes remind them about that.
User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post


7 Pages V  1 2 3 > » 
Closed TopicStart new topic
1 User(s) are reading this topic (0 Guests and 0 Anonymous Users)
1 Members: Test8899

 


Lo-Fi Version Time is now: 15th October 2022 - 10:17