x
This website is using cookies. We use cookies to ensure that we give you the best experience on our website. More info. That's Fine
HPC:Factor Logo 
 
Latest Forum Activity

Security Changes: Please Update Your Password

C:Amie Page Icon Posted 2022-10-07 2:38 PM
#
Avatar image of C:Amie
Administrator
H/PC Oracle

Posts:
17,976
Location:
United Kingdom
Status:
TLDR: Please Head to Forums > Your Settings > Change Your Password and reset your password otherwise you may find that parts of the site do not work (and I'll force you to do it sooner or later anyway).

Long version:
Back in the Spring when I was finishing up the code for HPC:Factor's online Windows CE Installer file generator "CabMaker" ( https://cabmaker.hpcfactor.com/ ). I discovered that the company who originally coded the forums software that the site uses made a number of security gaffes in their log-on processes.

I am not going to go into too much detail in the public domain as it may impact other sites.

Regardless, it became necessary to fix the problem and while I was there, to update the security. This work has now been done. All new user accounts to the site will be created using the new, significantly stronger and patched security model.

In the short-term, all existing user accounts on the site will continue to work as normal however as your passwords are one-way encrypted it is not possible for me to automatically switch you over to the new mechanism. Therefore, to slip over to the new model, you will need to manually change your password. Doing so will switch you over to the new model and will fully delete the original, flawed (but still encrypted) password information.

I have used the opportunity to also increase the minimum password length and complexity from 10 characters as it has been for the last decade up to 12. Additionally you will now require at least three of: Uppercase, Lowercase, Number and Special Character.

While the main site will run in hybrid mode. Until such time that you change your password, you will not be able to log into CabMaker ( https://cabmaker.hpcfactor.com/ ).

I would like to stress in the clearest terms possible: This has NOT been done in response to any hack, crack or compromise. There is nothing to suggest that you account is at risk. This is simply a precautionary measure and a proactive response to my becoming aware of a problem.

After this has been shaken out for a few months, I will likely force all old-method users to change their password at sign-in - although that functionality is going to have to be written into the forums from scratch too!


Thanks for your understanding in this matter. If you have any questions, please post them here along with any problems. Should you wind up locked out of the site completely for some reason as a result of these changes, please contact the webmaster.
 Top of the page Quote Reply
CE Geek
CE Geek Page Icon Posted 2022-10-08 12:55 AM
#
Status:
I tried to change my password according to the instructions, but now when I try to log in it says there was an error in my username or password. (I even tried the "Forgot Password" link to try to reset it again, but I got the same outcome. Feels really weird to post as a guest after 17 1/2 years as a member and 15 as a mod.)
 Top of the page Quote Reply
torch Page Icon Posted 2022-10-08 2:38 AM
#
Avatar image of torch
Subscribers
H/PC Guru

Posts:
5,713
Location:
United States 
Status:
Until camie wakes up try alternating cases like ce geek and CE Geek

But like don’t lock yourself out. I was just thinking haha

I’m wondering if the changeover is different because your username is mixed case. Mine is all lowercase

Edited by torch 2022-10-08 2:51 AM
 Top of the page Quote Reply
C:Amie Page Icon Posted 2022-10-08 9:25 AM
#
Avatar image of C:Amie
Administrator
H/PC Oracle

Posts:
17,976
Location:
United Kingdom
Status:
If you are locked out, please try: https://www.hpcfactor.com/forums/forgot-password.asp

I just reset mine and it is working there. I'm about to re-test the Your Settings form

Edit: Oop, looks like I had a special moment the last time I saved the your settings code. I think I must have ctrl + s'd to save at some point, missed the ctrl and wound up with a random S getting saved back in the source. It was erroring. Sorry all.
 Top of the page Quote Reply
CE Geek Page Icon Posted 2022-10-08 6:29 PM
#
Avatar image of CE Geek
Global Moderator
H/PC Oracle

Posts:
12,667
Location:
Southern California
Status:
Okay, worked this time. But the same thing didn't work before.
 Top of the page Quote Reply
C:Amie Page Icon Posted 2022-10-08 6:32 PM
#
Avatar image of C:Amie
Administrator
H/PC Oracle

Posts:
17,976
Location:
United Kingdom
Status:
If you got a fault page, it would have been because of my typo. If you didn't... I'm clueless.
 Top of the page Quote Reply
Rich Hawley Page Icon Posted 2022-10-08 8:51 PM
#
Avatar image of Rich Hawley
Global Moderator
H/PC Guru

Posts:
7,188
Location:
USA
Status:
I would rather give you a sample of my blood than change my password...
 Top of the page Quote Reply
C:Amie Page Icon Posted 2022-10-08 9:35 PM
#
Avatar image of C:Amie
Administrator
H/PC Oracle

Posts:
17,976
Location:
United Kingdom
Status:
Which wrist do you want it in?
 Top of the page Quote Reply
Jump to forum:
Seconds to generate: 0.156 - Cached queries : 65 - Executed queries : 8