AmberCutie's Forum
An adult community for cam models and members to discuss all the things!

Friendly reminder on Password security

  • ** WARNING - ACF CONTAINS ADULT CONTENT **
    Only persons aged 18 or over may read or post to the forums, without regard to whether an adult actually owns the registration or parental/guardian permission. AmberCutie's Forum (ACF) is for use by adults only and contains adult content. By continuing to use this site you are confirming that you are at least 18 years of age.
Status
Not open for further replies.
Apr 19, 2013
70
149
113
So I felt like writing this due to two things; needing to reset my password on a cam site I will not name *see below why*, and reading about the massive data breach.

So this is a friendly reminder and a few comments on password security.

Longer the password the better...even if it is a common password you use and adding 123123123 onto the end or 321321321...this kind of pattern is easy to type so it shouldn't take too much longer...but it makes guessing your password harder

Don't use single word passwords *cough*password*cough* if you use a phrase like "ilikemeatballsontoast" it is a lot stronger (5+ words should be good)

Don't reuse your passwords...or if you do make sure your email accounts have strong non repeated passwords *you know the ones that you use to sign up for everything and can have password resets sent to*



So now I want to talk about the scary truth behind passwords online. If you do a password reset on a website and they send your password to your email, seriously consider if you want to continue using that website *and never NEVER use a password that you use somewhere else on there*. I say this because in this case they are lacking security 101 for passwords.

For those who do not know, when you send your password to gmail, say 123456abcd what happens is google sends it through a mathematical formula (hashing) that turns it into garbled data (one that cannot be reversed). The garbled data is what google stores on their servers, this is why they cannot send you your password...they do not know it. This concept has been around for at least 6 years in internet security.

So ask yourself this next time you reset your password "why did the website just send me my password?". There is no reason in this day and age to store user passwords and if they do, what other security problems might they have. With that said there are at least 2 cam sites that I have reset my password on (one recently) that have sent me my password.

So just a heads up, be careful about your computer security....and for those who want to know more see computerphile
http://www.youtube.com/watch?v=8ZtInClXe1Q
http://www.youtube.com/watch?v=b4b8ktEV4Bg

*rant over*
 
Greggory said:
Don't reuse your passwords...or if you do make sure your email accounts have strong non repeated passwords *you know the ones that you use to sign up for everything and can have password resets sent to*

That one is important - at work we always look for lists of stolen passwords and try to match them with accounts in our products and we usually get matches on at least 10% of the entries from the lists (if not much more!).

Another hint: if a site allows two-step authentication (using SMS, an app [like Google's Authenticator], or a 'dongle' [RSA security key, yubikey]) , enable it. It is a bit of a pain in the ass to need that token/app/SMS, but it prevents anyone that gets only your username and password from getting into your account .
 
  • Like
Reactions: LadyLuna
I'm a big fan of Duo Security's setup for two factor auth. I can approve my logins from the notification tray on Android, which makes it a tad more convenient.
 
Status
Not open for further replies.