MartinB Posted June 6, 2023 Share Posted June 6, 2023 I'm not sure 8 characters is still considered "good" in 2023 😟 2 Quote Link to comment Share on other sites More sharing options...
Woodinblack Posted June 6, 2023 Share Posted June 6, 2023 No, but it is still better than some of the alternatives. Quote Link to comment Share on other sites More sharing options...
asingardenof Posted June 6, 2023 Share Posted June 6, 2023 It's the websites that say a password can't be more than 20 characters and can't contain any special characters that make me stabby. 4 Quote Link to comment Share on other sites More sharing options...
wintoid Posted June 6, 2023 Share Posted June 6, 2023 https://xkcd.com/936/ 6 Quote Link to comment Share on other sites More sharing options...
velvetkevorkian Posted June 6, 2023 Share Posted June 6, 2023 You can check whether your email has been leaked in a previous breach on https://haveibeenpwned.com/ Spoiler: it probably has. 1 Quote Link to comment Share on other sites More sharing options...
scrumpymike Posted June 6, 2023 Share Posted June 6, 2023 Read the warning message re scammers a few hours back, so immediately changed my password. Then got a lockout message because someone from London had been trying to sign in on my account, presumably just before I changed it! Thanks for your vigilance Woodinblack 👍 Beware, the barbarians are at the gates! 1 Quote Link to comment Share on other sites More sharing options...
Kev Posted June 6, 2023 Share Posted June 6, 2023 52 minutes ago, MartinB said: I'm not sure 8 characters is still considered "good" in 2023 😟 Bugger, I just crafted the perfect 73 character password. 2 Quote Link to comment Share on other sites More sharing options...
lemonstar Posted June 6, 2023 Share Posted June 6, 2023 I use the free Bitwarden - to generate, store and automatically paste in passwords - it works across Windows, Android, iOs. I have changed mine just for the sheer hell of it. As @velvetkevorkian suggested - it's worth checking https://haveibeenpwned.com/ - it's very possible the same username and password have been harvested from another site that he was using. The question that has to be asked is - has BC been hacked (unlikely as only one incident [so far]) - this is why maintaining sites (as I've found) can be a PITA - you have to keep on top of security updates and sometimes the updates don't always work out. Worse than that - depending on how extensive the site security patch is - any hand crafted changes to the code have to be redone - it's not always simple and problem free. Quote Link to comment Share on other sites More sharing options...
lemonstar Posted June 6, 2023 Share Posted June 6, 2023 4 hours ago, RikiB said: Oh yeah we could’ve just sent him money doh. oh well it’s set up now and I’ll share it with my friends as £5 here and there will add up. if you guys could do the same . I stuck some pennies in fwiw. 1 Quote Link to comment Share on other sites More sharing options...
JoeEvans Posted June 6, 2023 Share Posted June 6, 2023 (edited) A ten digit password still has a crazy number of possible combinations, maybe 68 to the power of ten, depending on which special characters are allowed. Not sure that really long, complex passwords add much - the crucial thing is that they're all different. Edit - a couple of billion billion combinations, if I've understood my calculator's shorthand correctly. Edited June 6, 2023 by JoeEvans Quote Link to comment Share on other sites More sharing options...
scrumpymike Posted June 6, 2023 Share Posted June 6, 2023 Just donated a tenner via the group fund set up by RikiB. 2 Quote Link to comment Share on other sites More sharing options...
pluckedout Posted June 6, 2023 Share Posted June 6, 2023 (edited) 1 hour ago, JoeEvans said: A ten digit password still has a crazy number of possible combinations, maybe 68 to the power of ten, depending on which special characters are allowed. Not sure that really long, complex passwords add much - the crucial thing is that they're all different. Edit - a couple of billion billion combinations, if I've understood my calculator's shorthand correctly. All conceivable 10 character passwords can still be brute forced by a basic desktop computer in less than a day. And cracking an account is even easier than that if you use a rainbow table (a dictionary file with not just the contents of all the words in a dictionary but misspellings too and prioritised based on the most common length (6-10)). Passwords is one area where length really does matter. Combining three or four random words is a good way of doing this, or using a line from a film/song/book. Edited June 6, 2023 by pluckedout 1 Quote Link to comment Share on other sites More sharing options...
daveybass Posted June 6, 2023 Share Posted June 6, 2023 Tenner in the pot from me, hope it all softens the blow and shows what a decent bunch of people we are 1 Quote Link to comment Share on other sites More sharing options...
Woodinblack Posted June 6, 2023 Share Posted June 6, 2023 3 hours ago, lemonstar said: The question that has to be asked is - has BC been hacked no 3 hours ago, lemonstar said: - this is why maintaining sites (as I've found) can be a PITA - you have to keep on top of security updates and sometimes the updates don't always work out. Worse than that - depending on how extensive the site security patch is - any hand crafted changes to the code have to be redone - it's not always simple and problem free. the site is updated every month, there is custom code, it is often a PITA and messes up, but it needs to be done 1 hour ago, pluckedout said: All conceivable 10 character passwords can still be brute forced by a basic desktop computer in less than a day. not if there is an internet round trip time of many 100 of ms, and you get locked out after 3! 1 1 Quote Link to comment Share on other sites More sharing options...
jrixn1 Posted June 6, 2023 Share Posted June 6, 2023 7 minutes ago, Woodinblack said: not if there is an internet round trip time of many 100 of ms, and you get locked out after 3! The scenario is that the password file has been leaked. In that case, the passwords will be cracked locally, not against the live site. 1 Quote Link to comment Share on other sites More sharing options...
Stub Mandrel Posted June 6, 2023 Share Posted June 6, 2023 In brief longer passwords stronger than odd characters. 2 Quote Link to comment Share on other sites More sharing options...
PaulWarning Posted June 6, 2023 Share Posted June 6, 2023 I just use google suggestions, seems to work well. Quote Link to comment Share on other sites More sharing options...
chaypup Posted June 6, 2023 Share Posted June 6, 2023 4 hours ago, lemonstar said: I stuck some pennies in fwiw. As have I Quote Link to comment Share on other sites More sharing options...
Napalmnun Posted June 6, 2023 Share Posted June 6, 2023 8 hours ago, tauzero said: Which tonewood is right for metal? Whatever Dingwall make their basses from? 😉 Quote Link to comment Share on other sites More sharing options...
Jean-Luc Pickguard Posted June 6, 2023 Share Posted June 6, 2023 22 minutes ago, Stub Mandrel said: In brief longer passwords stronger than odd characters. I built a WordPress plugin based on that comic: https://wordpress.org/plugins/correct-horse-battery-staple/ Also I use 'correct-horse-battery-staple' as my password everywhere including basschat as it is the most secure password you can have. 😁 1 2 Quote Link to comment Share on other sites More sharing options...
oldslapper Posted June 6, 2023 Share Posted June 6, 2023 1 minute ago, Jean-Luc Pickguard said: Also I use 'correct-horse-battery-staple' as my password everywhere including basschat as it is the most secure password you can have. 😁 Aww same here. That’s lovely. 😊 1 Quote Link to comment Share on other sites More sharing options...
Stub Mandrel Posted June 6, 2023 Share Posted June 6, 2023 23 minutes ago, Jean-Luc Pickguard said: I built a WordPress plugin based on that comic: https://wordpress.org/plugins/correct-horse-battery-staple/ Also I use 'correct-horse-battery-staple' as my password everywhere including basschat as it is the most secure password you can have. 😁 It would be interesting to know how many people have actually done that. Quote Link to comment Share on other sites More sharing options...
Woodinblack Posted June 6, 2023 Share Posted June 6, 2023 1 hour ago, jrixn1 said: The scenario is that the password file has been leaked. In that case, the passwords will be cracked locally, not against the live site. But in common with a lot of sites, the passwords aren't stored, just the hashes of them and something else. If you have access to that (and I am pretty confident that no bad people do), you don't need as much time because you don't need to crack one password, you need to crack any, with passwords in different groups having different value. Or just replace the passwords entirely if you have access. It is a lot easier to social engineer your way in though. I mean if I took the email list, made a mass email saying 'hi, my name is sophie, sorry for the un-announced email, I got your email from the internet as a bass player. My dad passed away recently at the age of 60, he played this one bass all his life, he loved it as it had the same date of birth as him. It says Fender Precision Bass at the end, and it is brown fading to black at the edges, it is in good condition in an orange lined case that says Fender on it. Now I need to clear his stuff out, and was wondering if anyone would be able to give me £1500 or around there for it - would you be interested?'. Most people would ignore it, a lot of people would reply saying dont' sell it for that, but I would also have a very healthy bank account by the end of the day. 1 Quote Link to comment Share on other sites More sharing options...
Skinnyman Posted June 6, 2023 Share Posted June 6, 2023 Apparently, subscribers/customers of BA, the BBC and Boots have all been targetted in the last few days. I guess they’ll be moving on to Currys and Costco next…. 2 Quote Link to comment Share on other sites More sharing options...
ambient Posted June 6, 2023 Share Posted June 6, 2023 On 05/06/2023 at 23:30, daveybass said: I actually said I’d pay the PayPal fees and then when the scammer said no then he was told to run and jump. it’s only a few per cent extra to protect you There are several websites you can use to calculate the fees the seller will incur. I’ll just pay whatever the extra is to ensure the seller gets what they wanted while protecting myself. 1 Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.