PDA

View Full Version : Security and stuff



Lexxuk
07-01-05, 19:19
Well after having my hotmail account briefly taken over last night (I wont say who it was.. in public *coffcoff PM coffcoff*) I figured what better time to discuss in this place of discussion, security and stuff.

My Hotmail password itself was 10 chars, which is more than enough you would think, nice and secure. And my password would be totally unguessable, its not a word etc.. So how did my account get taken over?

My secret question and answer. The girl that accessed my account knew enough about me to pretty much know any silly question that I could possibly think of, and having an easy one like "what is my dogs name" is rather... silly of me I guess.

So I sat down and thought, how could I make a secret question/answer that would not be totally obvious to anyone? Well, my @hotmail.com's secret question is so obscure that I do not know the answer to it, which is brilliant, no one could guess it! Not even me :lol: Unfortunatly its then pretty hard to think of a secret question/answer combination that (a) she does not know and (b) I can actually remember in case I ever do need to reset my password.

I did try thinking latterly, like sqrt(pi) which is 1.7 something or another, but no, that would just be really daft, I thought "how about putting in the Welsh for reverse and just reversing my email?" but no, (a) her mother is welsh and (b) welsh dictionarys online.

If you know my real name, which some of you do, you will be amazed at how much information is out there on the internet for you to find out about me, so school's I went to etc.. are gone, cant use them anymore (friends reunited) so how do you get out of this.

One way is to have an unrelated answer to question. For instance, the question could be "what is my cats name" and the answer "london bridge" but then you actually need to remember you put in London Bridge, which when you cant even remember your own password...

So, think of something really obscure, that is related to you and will just jog your memory about what the password is. For instance, you got a B+ in GCSE history, you could have your secret question as "B+" and answer is "history", think well out of the box.

The Email Reset function btw, is a life saver, make sure you have yours updated to a nice safe email service, ideally a real one which you access often (its how I got my account back) and only you have access to (i.e. has no password reset function)

As for password, well, obviously the longer the better, mixed in with UPPER lower and numerical, you can also mix in ASCII too, which does improve security somewhat but meh, too hard to remember where you stuck that stupid &$% in the password.

Ok, so you mix a lower, upper and numerical, so thats 26+26+10=62, in an 8 letter password thats 218,340,105,584,896 different possible combinations for someone to guess :)

Nidhogg
07-01-05, 19:38
I hope it's not the same email address used to register your game account or you could be seeing your stuff sold on EBay by now. ;) Lex has been around long enough to remember the announcement we made a long time ago, but for everyone else not of his vintage/hard of remembering:

Do not use freebie email accounts to register your game, especially ones that have "secret questions" for retrieving your password. More than one account has been hacked this way in the past.

N

Dribble Joy
07-01-05, 19:41
Question: Can I change the e-mail address for my account?

sanityislost
07-01-05, 19:43
@DJ yea in the account settings

@lexx: lol scary shit dude

SiL ..:..

Dribble Joy
07-01-05, 19:47
In the launcher window?... Cos I can't...

MkVenner
07-01-05, 19:50
you cant anymore, you used to be able to, and on the site too, but i cant find a way to do it

Lexxuk
07-01-05, 20:12
Nah I never use Hotmail email for anything important, same with gmail, its pretty much for junk email and to protect my real email from spam, though I did have to blackhole dgwebb@ so its not actually possible to recover my password from some places :angel: My forum account and neocron are both registered to my real email address.

However some people may not have the same luxury as me of having real email (though I could set up my own email server coz my ISP is lovely) so may have to use Hotmail or Gmail, both of which do have secret questions. I mean, you might think your secret question is something no one knows like "what is my fathers name" but people that *know* you IRL (and may not like you) will know that, and boom, there goes your password. So it really is worth thinking long and hard about the question, before even starting to think about the answer :D

Dribble Joy
07-01-05, 20:32
You could simply put nothing or jibberish in the entry boxes for your hotmail/gmail accounts, and then promtly forget it.

Lexxuk
07-01-05, 20:44
You could, but its recommended you change your password often, and if you actually do follow that advice its nice to know you can get your password back, so that would in theory mean you should change your secret question often too... umm.. bugger O_o Me, I use several passwords, but my @hotmail.com password is only 5 chars long, but thats cause its years old ;)

Still, am surprised no one PM'd askin who it was :lol: :lol: :lol: