• WANTED: Happy members who like to discuss audio and other topics related to our interest. Desire to learn and share knowledge of science required. There are many reviews of audio hardware and expert members to help answer your questions. Click here to have your audio equipment measured for free!

Warning: change your password please!

martijn86

Active Member
Joined
Aug 30, 2019
Messages
277
Likes
985
Location
The Netherlands

NiagaraPete

Major Contributor
Forum Donor
Joined
Jun 23, 2021
Messages
2,199
Likes
1,962
Location
Canada
Just use double step verification, easy and secure.
 

Wicky

Active Member
Joined
Jun 8, 2021
Messages
192
Likes
218
Location
London
Ok, so just scrolled through the comments (rather quickly) didn't see the below advice...

If there is a chance passwords have compromised here suggest that not only users change their password here but also

any other site where they may have used the same password

thanks folks!
 

Canuck57

Addicted to Fun and Learning
Forum Donor
Joined
Jan 20, 2019
Messages
558
Likes
1,270
Location
Fergus, ON Canada
changed
 

dananski

Member
Joined
Feb 4, 2022
Messages
77
Likes
73
Cheers for the prompt heads up Amir, much appreciated.

Sounds like the site is being targeted but it is only being hit on an individual-by-individual level thus far. I trust only a salted hash is stored behind the scenes, rather than our whole passwords, to limit impact if there were a data breach?
 

Kuppenbender

Active Member
Forum Donor
Joined
Aug 12, 2020
Messages
121
Likes
365
Location
UK
Thats actually the safest way to keep passwords.
Even if somebody breaks into your home, the last thing he is going to look for is notepad with your passwords :)
Just remember to keep it in the drawer, and don’t use one with this on the cover:
9C7E9C46-D883-41A4-B0CC-49DF6479DB1B.jpeg
 

Doodski

Grand Contributor
Forum Donor
Joined
Dec 9, 2019
Messages
21,576
Likes
21,862
Location
Canada
I use a Kingston hardware encrypted thumb drive. After some failed attempts to enter a password it auto reformats and wipes the data.
 

Nango

Major Contributor
Joined
Aug 6, 2018
Messages
1,472
Likes
986
Location
D:\EU\GER\Rheinhessen
Also, adding a year and/or an exclamation mark at the end isn't going to save you.

Normally (if you're not a specific target) they just run the 10K most popular passwords (available to the public on GitHub) and a script that tries all the variations on those with capitals, numbers and special characters added. That's automated guessing and pretty fast, it'll give you some positives from a large database.

If you are a specific target because your account has greater value, trying to crack a password becomes an option. They'll try to brute-force all possible combinations of characters. On top of not being easy to guess, the length of a password now becomes important. Every extra character increases the number of possibilities exponentially. If we only count for letters, 26*10⁴ combinations are a lot faster to crunch than 26*10⁸. That's why passphrases are pretty effective if you need a long password that you can remember.

Passwords-chart-1384x727.jpg


Control leaked e-mail. The easiest scam is just spamming a leaked e-mail address. No password involved. You can add a note to the e-mail adress you use to make an account. For example [email protected] has +asr added. The e-mail is still being delivered to [email protected]. However, if you get spam, you can see where is is directed to. If it is directed to +asr, ASR had willingly or unwillingly leaked your e-mail address. You can simply block all mail that's directed at the +asr combo, notify the sites owner and register a new e-mail (+asr2 for example) at the website.
For non specific targets, if your password is compromised as well, they'll likely try to login to your PayPal with the +asr e-mail. Even if your password isn't unique, that'll fail. But please, use unique passwords!

If you're the type of Audio enthousiast who has a NAS or home server to store their music, you can host your own Bitwarden server with Vaultwarden. This way your data is stored locally with open source software.

Safe browsing!
Is this standard with the "+", does it apply everywhere???
 

theREALdotnet

Major Contributor
Joined
Mar 11, 2022
Messages
1,197
Likes
2,066
Are there plans for ASR to adopt PassKeys? The client-side infrastructure seems to be in place now (or rolling out) for all major platforms.
 

sarumbear

Master Contributor
Forum Donor
Joined
Aug 15, 2020
Messages
7,604
Likes
7,323
Location
UK
Life is short. Two Factor is for things that are very important, not for forums and such IMO. Just get a good, unique password and then just breeeeeathe.
Unless you are like me, whose login is hijacked by someone who were selling equipment through my profile…
 

AdamG

Helping stretch the audiophile budget…
Moderator
Forum Donor
Joined
Jan 3, 2021
Messages
4,742
Likes
15,691
Location
Reality
FYI Alert: Additional Accounts have been compromised. When identified we Perm Ban the account. For any members who have been compromised. Once you have regained ownership of your computer security. Send an Email to Amir at [email protected]

Include your ASR Username and the email address you used to register your account, if different from the account you send the email with. Amir will reset your password and provide you instructions on how to regain control over your account.

Good luck to those affected.
 

xaviescacs

Major Contributor
Forum Donor
Joined
Mar 23, 2021
Messages
1,501
Likes
1,980
Location
La Garriga, Barcelona
Unless you are like me, whose login is hijacked by someone who were selling equipment through my profile…
After changing my password I've checked my last messages to see if someone is selling cooking ware with my account.

Good luck to everyone. Be safe, be aware...
 

HarmonicTHD

Major Contributor
Joined
Mar 18, 2022
Messages
3,326
Likes
4,835
Hah. Next time I have a brain fart and post BS I have a good excuse - musta been hacked.
 

_thelaughingman

Major Contributor
Forum Donor
Joined
Jan 1, 2020
Messages
1,362
Likes
2,042
openssl rand -base64 20

Yup that’ll do!!
 
Top Bottom