How on earth have you got access to this confidential information?
Err... he owns NorthStandChat. He doesn't even need the passwords to access anything he wants.
How on earth have you got access to this confidential information?
How do you know? Are you storring our passwords unencrypted?37 members of NSC have their password set to be the same as their username.
Err... he owns NorthStandChat. He doesn't even need the passwords to access anything he wants.
This was my thoughts, surely you only store a hash of the password not clear text, what a scandalous infringement of my privacy
Errr.....this doesn't mean that he should have unencrypted access to this data.
You can still work it out, just hash the username and if the password hash matches the username hash then they are the same (unless you are using a very weak hashing algorithm)
this .. surely?
I'm surprised mods have access to members passwords.
Mods don't. And neither do I.
But vBulletin includes a "vulnerable password checker" which allows the admin to send an automated email to all users who have a "vulnerable password" of which the current definition is that the username and password are identical. I don't know who those 37 users are.
(Earlier versions of vBulletin allowed you to search for users by password. This meant I could for example, search for users who had 'seagulls' as their password and it would return a list of all such users. To the best of my knowledge vBulletin has never had a "show me a user's password" function. In fact, and users who have had problems accessing NSC will be able to testify, if I want to see first-hand the issues they are having, I will ask if they mind sharing their password with me so I can investigate).
Quite. Many people will have the same password for NSC, Facebook, email etc etc. Which leaves it open to abuse, especially now there's direct links between NSC and Facebook. Mods should not have access to unencrypted passwords.
I'm surprised mods have access to members passwords.
... and your fave sexual position
We know what your wearing, what your having for tea and your fave sexual position
We know what your wearing, what your having for tea and your fave sexual position
Does it include a woman?
Nice to see I've been hung, drawn and quartered before I even responded.
A couple of other points...
1. There is a big difference between mods and admins in vBulletin. I am the only person with admin powers. (But as above, neither provides access to clear text passwords, for obvious reasons).
2. You should not use the same password for multiple sites as one compromise can lead to many others.
You can use the same password but surely if that password is extremely strong than that's ok.
I tend to vary passwords though, anyone using passwords like "12345" is just stupid, or there own username.
Perhaps you should make a sticky Bozza about making stronger passwords, as if 37 grown adults are using their own name is just stupid...