Donate to Remove ads

Got a credit card? use our Credit Card & Finance Calculators

Thanks to eyeball08,Wondergirly,bofh,johnstevens77,Bhoddhisatva, for Donating to support the site

Beware 1st Feb

Formerly "Lemon Fool - Improve the Recipe" repurposed as Room 102 (see above).
stooz
Site Admin
Posts: 1455
Joined: November 3rd, 2016, 11:03 pm
Has thanked: 10 times
Been thanked: 502 times

Beware 1st Feb

#25377

Postby stooz » January 23rd, 2017, 1:33 pm

Passwords require replacing every 90 days on this site. As many of you joined 5th November, thats about then.

I would suggest you go into your control panel ahead of this time and change it. As if i'm hit with a pile of "i forgot" requests, it will take me a while to process you all :)

Alaric
Lemon Half
Posts: 6062
Joined: November 5th, 2016, 9:05 am
Has thanked: 20 times
Been thanked: 1413 times

Re: Beware 1st Feb

#25382

Postby Alaric » January 23rd, 2017, 1:42 pm

stooz wrote:Passwords require replacing every 90 days on this site.


That would be this site's implementation rather than a generic feature of phpbb. Is it really necessary?

mc2fool
Lemon Half
Posts: 7887
Joined: November 4th, 2016, 11:24 am
Has thanked: 7 times
Been thanked: 3044 times

Re: Beware 1st Feb

#25383

Postby mc2fool » January 23rd, 2017, 1:43 pm

stooz wrote:Passwords require replacing every 90 days on this site.

Why? Seems massive overkill for such a site.

Breelander
Lemon Quarter
Posts: 4179
Joined: November 4th, 2016, 9:42 pm
Has thanked: 1001 times
Been thanked: 1855 times

Re: Beware 1st Feb

#25393

Postby Breelander » January 23rd, 2017, 2:08 pm

mc2fool wrote:
stooz wrote:Passwords require replacing every 90 days on this site.

Why? Seems massive overkill for such a site.

Even TMF didn't have an expiry date for passwords. Login cookies expired, but passwords never.

AleisterCrowley
Lemon Half
Posts: 6385
Joined: November 4th, 2016, 11:35 am
Has thanked: 1882 times
Been thanked: 2026 times

Re: Beware 1st Feb

#25397

Postby AleisterCrowley » January 23rd, 2017, 2:32 pm

Given the minimal damage a single normal user could do, having an enforced reset period is probably unnecessary.

Gaggsy
Lemon Slice
Posts: 470
Joined: November 8th, 2016, 1:42 pm
Has thanked: 223 times
Been thanked: 210 times

Re: Beware 1st Feb

#25405

Postby Gaggsy » January 23rd, 2017, 3:23 pm

I had enough trouble trying to come up with a password the first time round...

"Password must be between 8 characters and 30 characters long, must contain letters in mixed case and must contain numbers."

I imagine forcing a password change will put off most lurkers like me. Is it absolutely necessary?

robbelg
Lemon Slice
Posts: 407
Joined: November 4th, 2016, 10:43 am
Has thanked: 185 times
Been thanked: 155 times

Re: Beware 1st Feb

#25410

Postby robbelg » January 23rd, 2017, 3:53 pm

As has already been said that is massive overkill and will be hugely detrimental, and as Alaric said this must surely be a configurable feature,

Stooz please make this your number one priority to change.

staffordian
Lemon Quarter
Posts: 2300
Joined: November 4th, 2016, 4:20 pm
Has thanked: 1895 times
Been thanked: 870 times

Re: Beware 1st Feb

#25413

Postby staffordian » January 23rd, 2017, 4:02 pm

I too think enforced password changes are unnecessary.

Please reconsider.

Staffordian

PinkDalek
Lemon Half
Posts: 6139
Joined: November 4th, 2016, 1:12 pm
Has thanked: 1589 times
Been thanked: 1801 times

Re: Beware 1st Feb

#25414

Postby PinkDalek » January 23rd, 2017, 4:05 pm

It seems the 90 day forced password change option has been selected by stooz but can be amended or disabled, if I've understood this correctly:

https://www.phpbb.com/support/docs/en/3 ... al_server/

Extract:

"FORCE PASSWORD CHANGE

It is always ideal to change passwords once in a while. With this setting, you can force your users to change their passwords after a set number of days that their passwords have been used.

Only integers can be entered in the text box, which is located next to the DAYS label. This integer is the number of days that, after which, your users will have to change their passwords. If you would like to disable this feature, enter a value of "0"
."

Itsallaguess
Lemon Half
Posts: 9129
Joined: November 4th, 2016, 1:16 pm
Has thanked: 4140 times
Been thanked: 10025 times

Re: Beware 1st Feb

#25415

Postby Itsallaguess » January 23rd, 2017, 4:08 pm

staffordian wrote:
I too think enforced password changes are unnecessary.

Please reconsider.

Staffordian


I've got to agree with that, and would go further to suggest that keeping such functionality active would lead to some users actually migrating away from the board. We've all got enough passwords in our lives, and I can't really see the benefit of a 90-day-rule for a bulletin board. I've had the same password with my bank for over 15 years now! :D

I'd suggest turning off all requirements to change a password once set-up, other than allowing a user to do so if they wish to themselves.

Certainly seems to be a case of the downsides to such a requirement completely overwhelming whatever positive benefit doing so might bring, and as many people have already said - TMF managed to allow users to keep their passwords indefinitely, with no detrimental effects as far as I'm aware.

Are you open to turning the requirement off Stooz?

Glad you brought it up, mind! :D

Cheers,

Itsallaguess

kiloran
Lemon Quarter
Posts: 4112
Joined: November 4th, 2016, 9:24 am
Has thanked: 3249 times
Been thanked: 2853 times

Re: Beware 1st Feb

#25417

Postby kiloran » January 23rd, 2017, 4:12 pm

Itsallaguess wrote:
I've had the same password with my bank for over 15 years now! :D

Itsallaguess

Yes, I noticed you never change it ;)

--kiloran

6Tricia
2 Lemon pips
Posts: 244
Joined: November 4th, 2016, 11:00 am
Has thanked: 723 times
Been thanked: 103 times

Re: Beware 1st Feb

#25418

Postby 6Tricia » January 23rd, 2017, 4:13 pm

Stooz, I forgot my original password and you were brilliant sorting it out for me. Please don't make me change it again :cry: !

Tricia

Biggles
2 Lemon pips
Posts: 195
Joined: November 4th, 2016, 3:25 pm
Has thanked: 72 times
Been thanked: 34 times

Re: Beware 1st Feb

#25432

Postby Biggles » January 23rd, 2017, 4:54 pm

Ye gods, to choose a new password, I'd have to know what the old one was, and I'll never manage that!

Alaric
Lemon Half
Posts: 6062
Joined: November 5th, 2016, 9:05 am
Has thanked: 20 times
Been thanked: 1413 times

Re: Beware 1st Feb

#25433

Postby Alaric » January 23rd, 2017, 5:07 pm

Gaggsy wrote:"Password must be between 8 characters and 30 characters long, must contain letters in mixed case and must contain numbers."


Those with a working knowledge of chess openings and notation might wish to consider using these. For example "Spanish" would be e4e5Nf3Nc6Bb5. The sequence e4e5f4 was a plot point in a recent episode of the Morse prequel "Endeavour".

gryffron
Lemon Quarter
Posts: 3637
Joined: November 4th, 2016, 10:00 am
Has thanked: 557 times
Been thanked: 1611 times

Re: Beware 1st Feb

#25437

Postby gryffron » January 23rd, 2017, 5:20 pm

I always find a requirement to change passwords frequently is considerably LESS secure. Because everyone needs to write them down to remember them.

Gryff

chas49
Lemon Quarter
Posts: 1978
Joined: November 4th, 2016, 10:25 am
Has thanked: 219 times
Been thanked: 468 times

Re: Beware 1st Feb

#25439

Postby chas49 » January 23rd, 2017, 5:36 pm

I agree that it seems overkill, albeit good security practice. I presume the system doesn't store old passwords so there's presumably nothing to stop one changing it to a new password and immediately back to the previous one?

jackdaww
Lemon Quarter
Posts: 2081
Joined: November 4th, 2016, 11:53 am
Has thanked: 3203 times
Been thanked: 417 times

Re: Beware 1st Feb

#25440

Postby jackdaww » January 23rd, 2017, 5:40 pm

who on earth would want to hack into my TLF account ?

:x :x :x

jackdaww
Lemon Quarter
Posts: 2081
Joined: November 4th, 2016, 11:53 am
Has thanked: 3203 times
Been thanked: 417 times

Re: Beware 1st Feb

#25441

Postby jackdaww » January 23rd, 2017, 5:40 pm

chas49 wrote:I agree that it seems overkill, albeit good security practice. I presume the system doesn't store old passwords so there's presumably nothing to stop one changing it to a new password and immediately back to the previous one?


===

i wouldnt bet on it .

MDW1954
Lemon Quarter
Posts: 2362
Joined: November 4th, 2016, 8:46 pm
Has thanked: 527 times
Been thanked: 1011 times

Re: Beware 1st Feb

#25448

Postby MDW1954 » January 23rd, 2017, 5:56 pm

Where *is* the control panel, anyway? What does it look like? I see the little "gear cog", but it doesn't have a password option that I can see.

MDW1954

staffordian
Lemon Quarter
Posts: 2300
Joined: November 4th, 2016, 4:20 pm
Has thanked: 1895 times
Been thanked: 870 times

Re: Beware 1st Feb

#25450

Postby staffordian » January 23rd, 2017, 6:04 pm

MDW1954 wrote:Where *is* the control panel, anyway? What does it look like? I see the little "gear cog", but it doesn't have a password option that I can see.

MDW1954


Ckick on the small arrow beside your username at the top of the page (not sure if its there on every page, but it's certainly on some...)

Then go to profile, edit account settings.

Staffordian


Return to “Room 102 - Site Issues, Complaints & General Chat”

Who is online

Users browsing this forum: No registered users and 29 guests