in reply to User Editor Page and clear text passwords

The password I use to connect to PM is the random string sent to me when I first joined, so it bears no relation to any other password I normally use in my life (and I generally don't remember what it is -- my browser does that for me -- but I keep that email from PM management, just in case).

The worst-case scenario if someone steals my PM password? They submit "updates" to trash my user page, user settings and any number of the hundreds of nodes I've posted. If they are really subtle and really nasty, they alter code I've posted in malicious ways. If they are nasty and not subtle, they start using my name to do trollish things, and others start to wonder whether I've become unbalanced (bipolar/schizo/etc), until I figure out what's happening and sound the alarm.

Would that cause me any personal damage? Not really. All the code I've posted here is also stored somewhere else where I have more secure ownership and access control, and any ruffled relationships can be smoothed once the facts are known. If the website has a reliable backup, then this worst-case scenario would be resolved by locking things down for a bit, fixing things to prevent recurrence, restoring to a state that precedes the abuse, and getting back to work.

I think whatever risk there is in the PM password setup is limited to damage that may be suffered by the PM website itself, and by the community as a whole that it serves.

I'm not saying there's no cause for concern -- I'm just saying that there is no reason to feel personally threatened by the risk. PM (the website and the membership in the aggregate) bears the full weight of consequences in the event of abuse. If you or your acquaintences are feeling that you have personal things at stake here, think again.

  • Comment on Re: User Editor Page and clear text passwords

Replies are listed 'Best First'.
Re: Re: User Editor Page and clear text passwords
by BUU (Prior) on Feb 15, 2004 at 22:30 UTC
    Yes, but how much damage would destroying the trust that holds this site together do? While a security breach probably wouldn't cause nuclear war, it could potentially destroy this site, and I personally would prefer it not destroyed, thanks.
      But you don't need to capture a password to do that. All you need is to capture a cookie. And considering this site isn't using HTTPS, capturing cookies is as hard as capturing a password.

      Abigail

        Considering that a lot of people use JS in their browswers...

        1. Copy the cookie value of perlmonks.org to another cookie for mycustomserver.com
        2. Post a cute link or something and have the victim visit it at SOME time, either via cb, a node or something.
        3. On mycustomserver.com, have your home page capture the cookie and write it somewhere. Then its a matter of reusing that cookie.


        As for passwords, I haven't played much with iframes, js and capturing form fields yet, but I wouldn't be surprised if something can't be concocted.

        Just some thoughts on your comment. And what BUU is pointing out, is if someone does hack the server and gets all passwords, the site becomes useless, and everyone has to start over.


        Play that funky music white boy..
Re: Re: User Editor Page and clear text passwords
by exussum0 (Vicar) on Feb 15, 2004 at 22:31 UTC
    I think whatever risk there is in the PM password setup is limited to damage that may be suffered by the PM website itself, and by the community as a whole that it serves.
    You are an exception to the rule. For IM, I use sporte01. For yahoo messenger, i'm sporty3, but point is, 95% of the time, I use the same login all the time. Having worked for a community site company which ran 3 communities (about the same schema for each instance, marketed different) I found many MANY people to use the same login when they can. Same password, I can't say, since they were encrypted. But point is, your login tends to get reused, 'cause it's just as personal if not more personal as a password.

    Heck,.. I actually get called sporty in real life.. so what else should have I used as a login?


    Play that funky music white boy..
      White boy? I mean sporti.. I mean sportay :)