Tweak to changing of password

Suggestions that have been archived.

Moderator: Community Team

Post Reply
Shrinky
Posts: 403
Joined: Fri Aug 03, 2007 3:02 am
Location: As my flag says

Tweak to changing of password

Post by Shrinky »

Specifics:Currently when one changes their password, no email is sent to them to confirm that they really want to change the password. Makes it easy for hackers to render an account useless.

Suggestion: Send a confirmatory mail to email account provided upon sign up and only when user has confirmed that mail, then change password.
Let's say a hacker has hacked into cc account but has not yet hacked into your email account(assuming one is not stupid enough to keep same password for both!), so if hacker changes pw on cc, the confirmation mail gets sent and user will know that someone has hacked into account because he/she will definitely know that he/she did NOT change the pw at any point of time!

This will improve the following aspects of the site: Better account security
Highest Score-2505 (18/07/2010)
User avatar
Woodruff
Posts: 5093
Joined: Sat Jan 05, 2008 9:15 am

Re: Tweak to changing of password

Post by Woodruff »

Shrinky wrote:Specifics:Currently when one changes their password, no email is sent to them to confirm that they really want to change the password. Makes it easy for hackers to render an account useless.

Suggestion: Send a confirmatory mail to email account provided upon sign up and only when user has confirmed that mail, then change password.
Let's say a hacker has hacked into cc account but has not yet hacked into your email account(assuming one is not stupid enough to keep same password for both!), so if hacker changes pw on cc, the confirmation mail gets sent and user will know that someone has hacked into account because he/she will definitely know that he/she did NOT change the pw at any point of time!

This will improve the following aspects of the site: Better account security


If this is the case currently, then this definitely seems like a smart move. Particularly when given the concept of "sitters".
...I prefer a man who will burn the flag and then wrap himself in the Constitution to a man who will burn the Constitution and then wrap himself in the flag.
User avatar
TheForgivenOne
Posts: 5998
Joined: Fri May 15, 2009 8:27 pm
Gender: Male
Location: Lost somewhere in the snow. HELP ME

Re: Tweak to changing of password

Post by TheForgivenOne »

I 100% support this
Image
Game 1675072
2018-08-09 16:02:06 - Mageplunka69: its jamaica map and TFO that keep me on this site
User avatar
JoshyBoy
Posts: 3750
Joined: Mon May 26, 2008 6:04 pm
Gender: Male
Location: In the gym. Yeah, still there.

Re: Tweak to changing of password

Post by JoshyBoy »

I fully support this idea. Simple things done well... I like.
drunkmonkey wrote:I honestly wonder why anyone becomes a mod on this site. You're the whiniest bunch of players imaginable.

Ron Burgundy wrote:Why don't you go back to your home on Whore Island?
User avatar
iamkoolerthanu
Posts: 4119
Joined: Sun Dec 31, 2006 6:56 pm
Gender: Male
Location: looking at my highest score: 2715, #170

Re: Tweak to changing of password

Post by iamkoolerthanu »

This would be a great addition. :)
Shrinky
Posts: 403
Joined: Fri Aug 03, 2007 3:02 am
Location: As my flag says

Re: Tweak to changing of password

Post by Shrinky »

quick question, how exactly are these suggestions passed on to lack?
Does a suggestion require a minimum number of support from fellow players before it is passed further up the ladder?
Highest Score-2505 (18/07/2010)
User avatar
TheForgivenOne
Posts: 5998
Joined: Fri May 15, 2009 8:27 pm
Gender: Male
Location: Lost somewhere in the snow. HELP ME

Re: Tweak to changing of password

Post by TheForgivenOne »

It's done by our best judgement. If a topic gets quite a bit of support, we will sticky it, and or put it on "Last Call", as seen with Adjacent Attacks and Upping the limit to 12 players
Image
Game 1675072
2018-08-09 16:02:06 - Mageplunka69: its jamaica map and TFO that keep me on this site
Shrinky
Posts: 403
Joined: Fri Aug 03, 2007 3:02 am
Location: As my flag says

Re: Tweak to changing of password

Post by Shrinky »

ok, thanks
Highest Score-2505 (18/07/2010)
User avatar
JoshyBoy
Posts: 3750
Joined: Mon May 26, 2008 6:04 pm
Gender: Male
Location: In the gym. Yeah, still there.

Re: Tweak to changing of password

Post by JoshyBoy »

To be honest this looks like a really basic, simple, and easy suggestion to implement idea. Therefore I am going to "sticky" it and make it a [Last Call] for a couple of days, then should be able to submit it and it should get done no problem.

Cheers, JB ;)
drunkmonkey wrote:I honestly wonder why anyone becomes a mod on this site. You're the whiniest bunch of players imaginable.

Ron Burgundy wrote:Why don't you go back to your home on Whore Island?
User avatar
Rocketry
Posts: 1416
Joined: Wed May 16, 2007 5:33 pm
Gender: Male
Location: Westminster
Contact:

Re: Tweak to changing of password [Last Call]

Post by Rocketry »

Hmm...

What about if someone signs up to CC a work email address or a temporary email address, and then that account becomes invalid for whatever reason (e.g. they leave that job or the temporary email address expires,) and then they want to change their password? The email would go to an address they were unable to access so they could never change their password.

Rocket.
Image
- CC's Most Wanted - 2401
slowreactor
Posts: 1356
Joined: Tue Jan 20, 2009 3:34 pm
Gender: Male
Location: Ithaca, NY

Re: Tweak to changing of password [Last Call]

Post by slowreactor »

Rocketry wrote:Hmm...

What about if someone signs up to CC a work email address or a temporary email address, and then that account becomes invalid for whatever reason (e.g. they leave that job or the temporary email address expires,) and then they want to change their password? The email would go to an address they were unable to access so they could never change their password.

Rocket.


You can change your e-mail address:

Control Panel -> Profile -> Edit Account Settings.
then put in your new e-mail under "E-mail address".
User avatar
MrBenn
Posts: 6880
Joined: Wed Nov 21, 2007 9:32 am
Location: Off Duty

Re: Tweak to changing of password [Last Call]

Post by MrBenn »

How about a simpler suggestion; rather than requiring a confirmation link to be verified before the pw is changed, why not just send an email to the registered email address with the new password?

You should only need to verify a new email address, as that is more of an "identity" change, as opposed to a "security" change
Image
PB: 2661 | He's blue... If he were green he would die | No mod would be stupid enough to do that
Dako
Posts: 3987
Joined: Sun Aug 26, 2007 9:07 am
Gender: Male
Location: St. Petersburg, Russia
Contact:

Re: Tweak to changing of password [Last Call]

Post by Dako »

As I previously said, confirmation by email of the password change is unnecessary - you are already confirming a password change by entering previous (current) password. And if the hacker want to change the password he will change an email first.

Confirmation is needed when you are about to make a serious action you are unaware of. How can you be unaware of password change, when you enter it twice (blindfolded by * symbols) and you also enter current password. How many more confirmations do you want?

And I don't think it will be of any protection against hackers.
Image
Hornet95
Posts: 154
Joined: Sun Aug 10, 2008 2:24 pm
Location: U.S., Central Time Zone (UT-5 hrs)

Re: Tweak to changing of password [Last Call]

Post by Hornet95 »

How many times do you change your password, legit or not legit? 1-3 times per year is my guess. For the slight inconvenience of a stray e-mail, I think this would be very helpful. This should be for both password changes and e-mail address changes (sent to both the new and the old e-mail addresses). I think to be helpful, the following information should also be included in the e-mail sent:

IP address of requestor:
Time of request:

And you should be locked out from making any further changes in those two items only for 24 hours.
Shrinky
Posts: 403
Joined: Fri Aug 03, 2007 3:02 am
Location: As my flag says

Re: Tweak to changing of password [Last Call]

Post by Shrinky »

Dako wrote:As I previously said, confirmation by email of the password change is unnecessary - you are already confirming a password change by entering previous (current) password. And if the hacker want to change the password he will change an email first.

Confirmation is needed when you are about to make a serious action you are unaware of. How can you be unaware of password change, when you enter it twice (blindfolded by * symbols) and you also enter current password. How many more confirmations do you want?

And I don't think it will be of any protection against hackers.


You got a point there. But let's look at it from the angle of an account sitter now.

IF say one of them suddenly turned rogue, then going by the current method of changing password, account is compromised. But if we go by the new method, then account is not entirely compromised as one more check needs to be done before password is changed.

Agreed that once a hacker is set upon doing something, it's very hard to stop him/her. But not so with a rogue account sitter.

MrBenn wrote:How about a simpler suggestion; rather than requiring a confirmation link to be verified before the pw is changed, why not just send an email to the registered email address with the new password?

You should only need to verify a new email address, as that is more of an "identity" change, as opposed to a "security" change


That sounds good. As email id can also be changed along with password, it would be more useful to send email to registered email id informing of the changes that have taken place.
Highest Score-2505 (18/07/2010)
Dako
Posts: 3987
Joined: Sun Aug 26, 2007 9:07 am
Gender: Male
Location: St. Petersburg, Russia
Contact:

Re: Tweak to changing of password [Last Call]

Post by Dako »

Simple question. Is your password from CC is the same one as from your email? How many passwords do you have?
[[My answer: not, not the same, and I have 7-9 different passwords lol.]]

And one more thing - sitting is considered as account sharing (thou it is approved as of now) and is a password giveaway - security leak. I am sure when lack implements some kind of sitting interface your password will be yours only.
Image
User avatar
BigBallinStalin
Posts: 5151
Joined: Sun Oct 26, 2008 10:23 pm
Location: crying into the dregs of an empty bottle of own-brand scotch on the toilet having a dump in Dagenham
Contact:

Re: Tweak to changing of password [Last Call]

Post by BigBallinStalin »

I'm glad you gentlemen are hammering out the details, but I'd like congratulate Shrinky for getting the ball rolling on this tremendous suggestion for the improvement of CC security.
User avatar
Rocketry
Posts: 1416
Joined: Wed May 16, 2007 5:33 pm
Gender: Male
Location: Westminster
Contact:

Re: Tweak to changing of password [Last Call]

Post by Rocketry »

slowreactor wrote:
Rocketry wrote:Hmm...

What about if someone signs up to CC a work email address or a temporary email address, and then that account becomes invalid for whatever reason (e.g. they leave that job or the temporary email address expires,) and then they want to change their password? The email would go to an address they were unable to access so they could never change their password.

Rocket.


You can change your e-mail address:

Control Panel -> Profile -> Edit Account Settings.
then put in your new e-mail under "E-mail address".


Maybe I'm missing the point... I thought the whole point of this suggestion was that the change password confirmation goes to the original signup email address. If it goes to the email you currently have registered then I guess this wouldnt work... a hacker could just firstly change the hackees (word!) email and then change the password causing the verification to go to the new email they have chosen. I'm not against higher security but I just don't understand why this would help.

Rocket.
Image
- CC's Most Wanted - 2401
Commander9
Posts: 757
Joined: Fri Aug 22, 2008 1:51 am
Gender: Male
Location: In between Lithuania/USA.
Contact:

Re: Tweak to changing of password [Last Call]

Post by Commander9 »

Great idea! If a confirmation email is sent both for email and pw change, it does improve things by quite a bit (not that it's completely safe, but still). I'm in for this one.
But... It was so artistically done.
User avatar
natty dread
Posts: 12877
Joined: Fri Feb 08, 2008 8:58 pm
Location: just plain fucked

Re: Tweak to changing of password [Last Call]

Post by natty dread »

Rocketry wrote:
Maybe I'm missing the point... I thought the whole point of this suggestion was that the change password confirmation goes to the original signup email address. If it goes to the email you currently have registered then I guess this wouldnt work... a hacker could just firstly change the hackees (word!) email and then change the password causing the verification to go to the new email they have chosen. I'm not against higher security but I just don't understand why this would help.

Rocket.


Well ofcourse next would be implemented a feature where, when you change your email, it will be sent to your password for verification.

Oh wait...
Image
User avatar
Little Witt
Posts: 560
Joined: Mon Mar 02, 2009 12:03 am
Gender: Male
Location: USA

Re: Tweak to changing of password [Last Call]

Post by Little Witt »

i think this is a good idea but as rocketry said the hacker could just change the e-mail address

then change the password which would be true but what would get ride of that problem might

be that CC sends a code by e-mail and would only send it to you once and that when you sign up, (so you would have to wright it down or something). and the only way you can change your

PW is to type in the code CC sent you and typing in your old and new password, so even if they did change your e-mail address they wouldn't know the code sent to you so there would be no way to change your password with out the code.

Do you think that would work?

LW
Shrinky
Posts: 403
Joined: Fri Aug 03, 2007 3:02 am
Location: As my flag says

Re: Tweak to changing of password [Last Call]

Post by Shrinky »

Little Witt wrote:i think this is a good idea but as rocketry said the hacker could just change the e-mail address

then change the password which would be true but what would get ride of that problem might

be that CC sends a code by e-mail and would only send it to you once and that when you sign up, (so you would have to wright it down or something). and the only way you can change your

PW is to type in the code CC sent you and typing in your old and new password, so even if they did change your e-mail address they wouldn't know the code sent to you so there would be no way to change your password with out the code.

Do you think that would work?

LW


Only thing against this is that it's too much of a bother for ppl to write the code down somewhere and then expect them to be able to find it again a long long time later.
That would just complicate things more for ppl and i dont think they'd like that :?
Highest Score-2505 (18/07/2010)
Dako
Posts: 3987
Joined: Sun Aug 26, 2007 9:07 am
Gender: Male
Location: St. Petersburg, Russia
Contact:

Re: Tweak to changing of password [Last Call]

Post by Dako »

I think this issue will not be implemented because it is part of the forum. And if you want to have nice updated of the forums (remember last one - quick reply) to be available - you cannot code the forum yourself. So I am sure this will not be implemented by lackattack. It will be much easier to post on phpBB3 forums and propose it there - but not on CC.

It may be in submitted suggestions, but no one will code it, believe me.
Image
User avatar
TheForgivenOne
Posts: 5998
Joined: Fri May 15, 2009 8:27 pm
Gender: Male
Location: Lost somewhere in the snow. HELP ME

Re: Tweak to changing of password [Last Call]

Post by TheForgivenOne »

Unstickied this
Image
Game 1675072
2018-08-09 16:02:06 - Mageplunka69: its jamaica map and TFO that keep me on this site
Post Reply

Return to “Archived Suggestions”