Page 1 of 2 12 LastLast
Results 1 to 15 of 19
  1. #1
    4 Star Lounger
    Join Date
    Jul 2011
    Location
    Florida
    Posts
    421
    Thanks
    192
    Thanked 30 Times in 28 Posts

    DEBACLE :Security Update for Registered Users

    Very amateurish performance for whatever caused this alert from Penton, Took numerous emails and reset attempts to get into the Lounge this evening.
    http://windowssecrets.com/forums/sho...gistered-Users

  2. #2
    Administrator
    Join Date
    Mar 2001
    Location
    St Louis, Missouri, USA
    Posts
    23,788
    Thanks
    5
    Thanked 1,085 Times in 951 Posts
    Sorry for your troubles. It seems that is not exactly unusual. I had issues too.
    Joe

  3. #3
    WS Lounge VIP
    Join Date
    Dec 2009
    Location
    Earth
    Posts
    8,430
    Thanks
    52
    Thanked 1,025 Times in 953 Posts
    I like that the password reset page is only http, not.

    cheers, Paul

  4. #4
    Silver Lounger lumpy95's Avatar
    Join Date
    Feb 2013
    Location
    Mojave Desert CA
    Posts
    1,964
    Thanks
    277
    Thanked 193 Times in 160 Posts
    Yeah, quite an ordeal. I immediately assumed that WS forum got hacked and sent an email to editor for WS but never got a reply, so eventually went through the "Song and Dance" of resetting after opening the site and seeing the post there.

  5. #5
    WS Lounge VIP access-mdb's Avatar
    Join Date
    Dec 2009
    Location
    Oxfordshire, UK
    Posts
    1,810
    Thanks
    151
    Thanked 168 Times in 161 Posts
    It took me three attempts before it emailed me with the temporary password. Not very good.
    Power corrupts. Absolute power is kinda neat though.

  6. #6
    4 Star Lounger
    Join Date
    Jul 2011
    Location
    Florida
    Posts
    421
    Thanks
    192
    Thanked 30 Times in 28 Posts
    Quote Originally Posted by access-mdb View Post
    It took me three attempts before it emailed me with the temporary password. Not very good.
    You got off lightly

  7. #7
    Administrator
    Join Date
    Jun 2010
    Location
    Portugal
    Posts
    12,548
    Thanks
    152
    Thanked 1,400 Times in 1,222 Posts
    I had no troubles resetting mine. First attempt, no issues at all.
    Rui
    -------
    R4

  8. #8
    Super Moderator satrow's Avatar
    Join Date
    Dec 2009
    Location
    Cardiff, UK
    Posts
    4,624
    Thanks
    299
    Thanked 599 Times in 498 Posts
    No trouble resetting mine either.

    I was a little annoyed at the timing though, as it was only 18 hours since my last password change.

  9. #9
    Super Moderator jwitalka's Avatar
    Join Date
    Dec 2009
    Location
    Minnesota
    Posts
    6,861
    Thanks
    119
    Thanked 812 Times in 727 Posts
    I suspect the difficulty of resetting is a function of the number of email addresses you have and if you remember which one you used to sign up for the lounge with. It took me a couple of attempts.

    Jerry

  10. #10
    4 Star Lounger
    Join Date
    Jul 2011
    Location
    Florida
    Posts
    421
    Thanks
    192
    Thanked 30 Times in 28 Posts
    Quote Originally Posted by jwitalka View Post
    I suspect the difficulty of resetting is a function of the number of email addresses you have and if you remember which one you used to sign up for the lounge with. It took me a couple of attempts.

    Jerry
    Not in my case.
    I was told about 6 separate times that they'd emailed me, but received nothing.
    The fact that several other members had problems demonstrates the system for dealing with these sort of issues is flawed; that was the point of my Thread, not to generate a straw-poll of individual experiences.

  11. #11
    Administrator
    Join Date
    Jun 2010
    Location
    Portugal
    Posts
    12,548
    Thanks
    152
    Thanked 1,400 Times in 1,222 Posts
    Quote Originally Posted by Trev View Post
    Not in my case.
    I was told about 6 separate times that they'd emailed me, but received nothing.
    The fact that several other members had problems demonstrates the system for dealing with these sort of issues is flawed; that was the point of my Thread, not to generate a straw-poll of individual experiences.
    I'm not sure there is a system to deal with this. As far as I can tell, this is a regular VBulletin forum, and only regular forum functionality was used (lost password recovery, email, etc.). I can't explain the issues with the email, but that is a bit unexpected considering notifications and regular password recovery don't seem to have any problems. We cannot state, either, that there was any huge increase in password reset requests that could affect the performance of the forum.

    So, I am sorry, your assumption doesn't really seem correct. I have no explanation for the differences in performance, but I cannot agree with assigning responsibility to the Lounge software that easily,
    Rui
    -------
    R4

  12. #12
    4 Star Lounger
    Join Date
    Jul 2011
    Location
    Florida
    Posts
    421
    Thanks
    192
    Thanked 30 Times in 28 Posts
    Quote Originally Posted by ruirib View Post
    I'm not sure there is a system to deal with this. As far as I can tell, this is a regular VBulletin forum, and only regular forum functionality was used (lost password recovery, email, etc.). I can't explain the issues with the email, but that is a bit unexpected considering notifications and regular password recovery don't seem to have any problems. We cannot state, either, that there was any huge increase in password reset requests that could affect the performance of the forum.

    So, I am sorry, your assumption doesn't really seem correct. I have no explanation for the differences in performance, but I cannot agree with assigning responsibility to the Lounge software that easily,
    I thiny you are missing the point here.
    I was informed that:-
    Penton is investigating an alleged exfiltration of user information from certain technology market properties that Penton acquired from iNET last year, including Hot Scripts, Mac Forums, and Web Hosting Talk. Since becoming aware of these allegations, we have been working around the clock to investigate and mitigate any potential risk to our users and have hired a security firm to assist us in our investigation.
    which somewhat alarmed me and so I followed the instructions to reset my password.
    The fact that the resetting took 8 separate attempts was my reason for this Thread.
    So don't comment on my "assumption" being incorrect, I have made NO assumptions.

  13. #13
    Administrator
    Join Date
    Jun 2010
    Location
    Portugal
    Posts
    12,548
    Thanks
    152
    Thanked 1,400 Times in 1,222 Posts
    Quote Originally Posted by Trev View Post
    I thiny you are missing the point here.
    So don't comment on my "assumption" being incorrect, I have made NO assumptions.
    You have, here:

    Quote Originally Posted by Trev View Post
    The fact that several other members had problems demonstrates the system for dealing with these sort of issues is flawed; that was the point of my Thread, not to generate a straw-poll of individual experiences."
    I told you there is no system to deal with it, nothing but regular forum resources and functionality that is used every single day by many users. As far as we know, those features work reasonably well, or we would have known long before if they didn't. Nothing like every single day of testing in real life conditions to know if what you have in place works or not.

    Plus, you complain about something that is, most likely, totally out of our control - the moment an email leaves the sending server, it may reach its destination or it may not. If it doesn't, there are many possible causes, but very few of them under the control of the sender.

    So, while I understand the that trying 8 times is bad (and you said they were 6 to begin with, are you still trying and counting?), for all we know, it could be your email provider that is to blame. It could even be our own email server that had issues, there is no way to know. In fact, considering we had hundreds of users changing passwords, the fact that only a few experienced problems for which no cause can be attributed with certainty, makes me feel that the forum features, those that are stress tested by real use, every day, worked pretty acceptably.

    Most problems, and I have helped a few users to reset their passwords - quite a few, actually - resulted from users that could not remember the email address they had used to register or no longer had access to it. Of those I helped, as far as I know, once they were informed of the email address associated with their accounts, they were able to reset their password without any problems.

    So, while this is no "straw poll" of individual experiences, this is a discussion on the Lounge features to handle "these sort of issues". It is therefore my responsibility, as Lounge admin, to set the record straight on how the Lounge software handled the situation and, despite a few problems, I think it handled it quite well. Yours is probably the worst record - 6 to 8 attempts to reset the password.
    That is bad and I am sorry it took so long, I am just no so sure about the causes as you seem to be.
    Rui
    -------
    R4

  14. #14
    WS Lounge VIP Coochin's Avatar
    Join Date
    Jun 2014
    Location
    Queensland, Australia
    Posts
    2,286
    Thanks
    32
    Thanked 332 Times in 287 Posts
    Quote Originally Posted by ruirib View Post
    ...So, while this is no "straw poll" of individual experiences, this is a discussion on the Lounge features to handle "these sort of issues". It is therefore my responsibility, as Lounge admin, to set the record straight on how the Lounge software handled the situation and, despite a few problems, I think it handled it quite well. Yours is probably the worst record - 6 to 8 attempts to reset the password.
    That is bad and I am sorry it took so long, I am just no so sure about the causes as you seem to be...
    I was able to reset my WSL password at first attempt; probably because I'd recorded the email address I used for WSL in the first instance.

    Maybe you other blokes need to keep records of email addresses for websites you access???
    Computer Consultant/Technician since 1998 (first PC was Atari 1040STE in 1988).
    Most common computing error is EBKAC: Error Between Keyboard And Chairback
    Confuscius said: "no use running harder if you're on the wrong road" and "any problem once correctly understood is already half-solved".

  15. #15
    Super Moderator
    Join Date
    Aug 2012
    Location
    Durham UK
    Posts
    6,961
    Thanks
    159
    Thanked 917 Times in 875 Posts
    My problem was that it didn't recognize my email and I was invited to report it to the Admins, to which Rui responded and from there it went smoothly.

Page 1 of 2 12 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •