• WANTED: Happy members who like to discuss audio and other topics related to our interest. Desire to learn and share knowledge of science required as is 20 years of participation in forums (not all true). There are daily reviews of audio hardware and expert members to help answer your questions. Click here to have your audio equipment measured for free!

Warning: change your password please!

martijn86

Active Member
Joined
Aug 30, 2019
Messages
268
Likes
965
Location
The Netherlands

NiagaraPete

Major Contributor
Forum Donor
Joined
Jun 23, 2021
Messages
2,165
Likes
1,908
Location
Canada
Just use double step verification, easy and secure.
 

Wicky

Active Member
Joined
Jun 8, 2021
Messages
186
Likes
201
Location
London
Ok, so just scrolled through the comments (rather quickly) didn't see the below advice...

If there is a chance passwords have compromised here suggest that not only users change their password here but also

any other site where they may have used the same password

thanks folks!
 

Canuck57

Addicted to Fun and Learning
Forum Donor
Joined
Jan 20, 2019
Messages
502
Likes
994
Location
Fergus, ON Canada
changed
 

dananski

Member
Joined
Feb 4, 2022
Messages
72
Likes
72
Cheers for the prompt heads up Amir, much appreciated.

Sounds like the site is being targeted but it is only being hit on an individual-by-individual level thus far. I trust only a salted hash is stored behind the scenes, rather than our whole passwords, to limit impact if there were a data breach?
 

Kuppenbender

Active Member
Forum Donor
Joined
Aug 12, 2020
Messages
112
Likes
313
Location
UK
Thats actually the safest way to keep passwords.
Even if somebody breaks into your home, the last thing he is going to look for is notepad with your passwords :)
Just remember to keep it in the drawer, and don’t use one with this on the cover:
9C7E9C46-D883-41A4-B0CC-49DF6479DB1B.jpeg
 

Doodski

Grand Contributor
Forum Donor
Joined
Dec 9, 2019
Messages
19,791
Likes
19,701
Location
Canada
I use a Kingston hardware encrypted thumb drive. After some failed attempts to enter a password it auto reformats and wipes the data.
 

Nango

Major Contributor
Joined
Aug 6, 2018
Messages
1,449
Likes
955
Location
D:\EU\GER\Rheinhessen
Also, adding a year and/or an exclamation mark at the end isn't going to save you.

Normally (if you're not a specific target) they just run the 10K most popular passwords (available to the public on GitHub) and a script that tries all the variations on those with capitals, numbers and special characters added. That's automated guessing and pretty fast, it'll give you some positives from a large database.

If you are a specific target because your account has greater value, trying to crack a password becomes an option. They'll try to brute-force all possible combinations of characters. On top of not being easy to guess, the length of a password now becomes important. Every extra character increases the number of possibilities exponentially. If we only count for letters, 26*10⁴ combinations are a lot faster to crunch than 26*10⁸. That's why passphrases are pretty effective if you need a long password that you can remember.

Passwords-chart-1384x727.jpg


Control leaked e-mail. The easiest scam is just spamming a leaked e-mail address. No password involved. You can add a note to the e-mail adress you use to make an account. For example [email protected] has +asr added. The e-mail is still being delivered to [email protected]. However, if you get spam, you can see where is is directed to. If it is directed to +asr, ASR had willingly or unwillingly leaked your e-mail address. You can simply block all mail that's directed at the +asr combo, notify the sites owner and register a new e-mail (+asr2 for example) at the website.
For non specific targets, if your password is compromised as well, they'll likely try to login to your PayPal with the +asr e-mail. Even if your password isn't unique, that'll fail. But please, use unique passwords!

If you're the type of Audio enthousiast who has a NAS or home server to store their music, you can host your own Bitwarden server with Vaultwarden. This way your data is stored locally with open source software.

Safe browsing!
Is this standard with the "+", does it apply everywhere???
 

theREALdotnet

Major Contributor
Joined
Mar 11, 2022
Messages
1,050
Likes
1,729
Are there plans for ASR to adopt PassKeys? The client-side infrastructure seems to be in place now (or rolling out) for all major platforms.
 

sarumbear

Master Contributor
Forum Donor
Joined
Aug 15, 2020
Messages
7,604
Likes
7,239
Location
UK
Life is short. Two Factor is for things that are very important, not for forums and such IMO. Just get a good, unique password and then just breeeeeathe.
Unless you are like me, whose login is hijacked by someone who were selling equipment through my profile…
 

AdamG247

Our Posts are read by Thousands of daily Guests…
Moderator
Forum Donor
Joined
Jan 3, 2021
Messages
4,306
Likes
13,342
FYI Alert: Additional Accounts have been compromised. When identified we Perm Ban the account. For any members who have been compromised. Once you have regained ownership of your computer security. Send an Email to Amir at [email protected]

Include your ASR Username and the email address you used to register your account, if different from the account you send the email with. Amir will reset your password and provide you instructions on how to regain control over your account.

Good luck to those affected.
 

HarmonicTHD

Major Contributor
Forum Donor
Joined
Mar 18, 2022
Messages
2,712
Likes
3,826
Hah. Next time I have a brain fart and post BS I have a good excuse - musta been hacked.
 

_thelaughingman

Major Contributor
Forum Donor
Joined
Jan 1, 2020
Messages
1,285
Likes
1,884
openssl rand -base64 20

Yup that’ll do!!
 
Top Bottom