Possible Security Breach of email addresses and passwords

Status
Not open for further replies.

K7MFC

WRAA720
Joined
Nov 18, 2017
Messages
863
Location
Phx, AZ
If the attacker only had the hashed password, salting the password should exponentially increase the difficulty which would be required to decrypt a it. Would you be willing to share your root cause analysis findings of this incident when complete?

Edit: thanks for the additional information; the initial reply was just "No."
 
Last edited:

GTR8000

NY/NJ Database Guy
Database Admin
Joined
Oct 4, 2007
Messages
15,482
Location
BEE00
What is the maximum password length allowed and what characters allowed/not allowed for the new system?
A couple of years ago I ran into an issue using a password greater than 20 characters in length. I don't recall the exact details nor do I know if that length restriction still applies.
 

PrivatelyJeff

Has more money than sense
Premium Subscriber
Joined
Jun 5, 2016
Messages
1,056
Location
Kings County, CA
That’s why I encourage everyone to use a non-cloud based password manager and use the most complex password you can for each site. I couldn’t tell you my bank username/passwords because they are so complex.
 

nd5y

Member
Joined
Dec 19, 2002
Messages
11,285
Location
Wichita Falls, TX
Well after changing my password I can't log in to the wiki.
I get a blank page with this url in the address bar:
Code:
https://wiki.radioreference.com/index.php?title=Special:UserLogin&action=submitlogin&type=login&returnto=Main_Page
 

eorange

♦Insane Asylum Premium Member♦
Joined
Aug 20, 2003
Messages
2,942
Location
Cleveland, OH
If the attacker only had the hashed password, salting the password should exponentially increase the difficulty which would be required to decrypt a it. Would you be willing to share your root cause analysis findings of this incident when complete?

Edit: thanks for the additional information; the initial reply was just "No."
MD5 has been known to be vulnerable for some time now, even when using a salt. The SHA-2* variants are more resistant to collisions (cracking).
 

GTR8000

NY/NJ Database Guy
Database Admin
Joined
Oct 4, 2007
Messages
15,482
Location
BEE00
Well after changing my password I can't log in to the wiki.
I get a blank page with this url in the address bar:
Code:
https://wiki.radioreference.com/index.php?title=Special:UserLogin&action=submitlogin&type=login&returnto=Main_Page
Confirmed.
 

AK9R

Lead Wiki Manager and almost an Awesome Moderator
Super Moderator
Joined
Jul 18, 2004
Messages
9,352
Location
Central Indiana
FWIW, I'm able to log into the Wiki.

Those of you who are having problems logging into the Wiki, did you change your password in your forums profile or did you change your password through your account information page on the main site?
 

nd5y

Member
Joined
Dec 19, 2002
Messages
11,285
Location
Wichita Falls, TX
I tried to change it from the Your Account Information and it failed, then I used the reset password link on the main site. I didn't use the forum or wiki.
 

AK9R

Lead Wiki Manager and almost an Awesome Moderator
Super Moderator
Joined
Jul 18, 2004
Messages
9,352
Location
Central Indiana
Remember that you need to log into the Wiki as "Nd5y". The first letter must be capitalized.
 

nd5y

Member
Joined
Dec 19, 2002
Messages
11,285
Location
Wichita Falls, TX
I tried to change it from the Your Account Information and it failed,
So when I did that I couldn't log in to the main web site, not just the wiki. After I used for forgot password reset link and made a new password is when the wiki broke.
 

blantonl

Founder and CEO
Staff member
Super Moderator
Joined
Dec 9, 2000
Messages
11,115
Location
San Antonio, Whitefish, New Orleans
I'm closing and moving to this official announcement:

 
Status
Not open for further replies.
Top