Password Security Suggestion

Category: Zone BBS Suggestions and Feedback

Post 1 by illumination (Darkness is history.) on Monday, 04-May-2009 18:20:29

Recently, we had someone hack into someone else's account. It was obviously because that person had an easy password, a password in which a person could easily hack into that account. I think we should modify the system to where it will not accept easy passwords, but instead, passwords with letters and numbers, perhaps. This way, hacking will not be as much of a problem as it is now.

Post 2 by Big Pawed Bear (letting his paws be his guide.) on Monday, 04-May-2009 18:23:03

hmm, yeah, good one that.

Post 3 by SunshineAndRain (I'm happily married, a mom of two and a fulltime college student.) on Monday, 04-May-2009 22:46:17

People should just come up with harder passwords if they don't want their account hacked. I hate passwords with alphanumeric characters.

Post 4 by illumination (Darkness is history.) on Monday, 04-May-2009 22:49:40

I don't like them either, but people don't always comply to that. It's better for a system to not accept those kinds of passwords than to just make it a rule that you shouldn't create an easy password.

Post 5 by laced-unlaced (Account disabled) on Tuesday, 05-May-2009 7:17:44

agree with post 1 and 2, it would be nice to have a system say if you enter something in the password field under neath it can detect how weak or strong it is.


really like it

Post 6 by Brooke (I just keep on posting!) on Tuesday, 05-May-2009 9:15:36

Not a bad idea. Ideally, people should know to make their passwords difficult, but a lot of people don't do it.

Post 7 by Thunderstorm (HotIndian!) on Tuesday, 05-May-2009 9:57:32

easy or tough. whatever as long as if someone's not sharing their password to any other friends/relatives, I'm sure this problem will get reduced. I'm sure password with various tricks and technicks will make it stronger. but while you're sharing it with someone, there's no use of having such a strong password as well.

Just my opinion.

Raaj.

Post 8 by Izzito (This site is so "educational") on Tuesday, 05-May-2009 10:02:27

or people could just be smarter about there passwords and not make it difficult for the rest of us

Post 9 by TylerK (This site is so "educational") on Tuesday, 05-May-2009 20:38:37

I like the idea. It's common sense to not use passwords that are words that can be looked up in the dictionary. Here are some tips for strong passwords:

Post 10 by illumination (Darkness is history.) on Tuesday, 05-May-2009 21:19:05

Tyler, how do you create lists like that? I like how you organized that.

Post 11 by b3n (I'm going for the prolific poster awards!) on Tuesday, 05-May-2009 22:35:35

Its a nice idea but for something truely secure you'd need 15 charactas; to be honest I voat that we just leave it up to the users.

Post 12 by robbiec12345 (Good night and Farewell ) on Wednesday, 06-May-2009 11:19:44

i know sites like live journal have strict guidelines on acceptable passwords! also, perhaps there could be a system where u are prompted to change ur password every 30 days or something like that!

just a suggestion

Post 13 by blindndangerous (the blind and dangerous one) on Wednesday, 06-May-2009 13:38:56

TO make the list...
ess then sign ul greater then.
less then li greater <text>
ess then li greater then <text>
less then slash ul greater then

Post 14 by TylerK (This site is so "educational") on Wednesday, 06-May-2009 14:53:16

Don't forget the less than slash li greater than. That goes after <text>.

Post 15 by wildebrew (We promised the world we'd tame it, what were we hoping for?) on Wednesday, 06-May-2009 15:41:45

It's not like we keep bank information or credit cards here, we don't even disclose our real names. I log on here because it's easy and with a password change requirement one runs the obvious risk of writing down passwords to remember them, rendering the complexity of the password useless if only someone finds the list.
I think most cases of perceived hacking on the site are probably from a user giving his/her password to another user. To minimize "hacking" and the only thing I would suggest implementing is a 3-try password, which would result in a locked account and require the person to email the community leader or admin to have the account restored, email would have to come from the address listed in the user's own profile, else it's not valid.
And, honestly, I don't think any change is really necessary, but it would satisfy the more paranoid users on here.

Post 16 by CrazedMidget (Sweet fantacy's really do come in small packages!) on Wednesday, 06-May-2009 18:13:04

This is a good idea, recently someone hacked my account, and i have no clue how they got my password..