Home

TheSinner.net

Why do we have to change our passwords?

This message board is for discussing anything in any way remotely connected with St Andrews, the University or just anything you want. Welcome!

Why do we have to change our passwords?

Postby Thackary on Fri Feb 03, 2006 10:30 am

Because apparently someone got hold of the entire list of usernames and passwords. Oops.

Admittedly, they're encrypted, but let's face it - that's only going to delay the process of cracking them.

So - if you haven't changed your password already, you might want to think about doing it sometime soon. Especially if you use that password for other stuff.

And do follow IT Services' instructions about choosing a complex password. It may be difficult to remember at first, but hey - so's tying your shoelaces, and most of you have got that one cracked...


edit: Please note that it is your ITS password that you need to change, not your Sinner password.
Thackary
 
Posts: 3034
Joined: Thu Jan 01, 1970 12:00 am

Re:

Postby Haunted on Fri Feb 03, 2006 10:32 am

Quoting thackary from 10:30, 3rd Feb 2006
Because apparently someone got hold of the entire list of usernames and passwords. Oops.


How did that happen?
Genesis 19:4-8
Haunted
User avatar
 
Posts: 3171
Joined: Tue Dec 23, 2003 2:05 am

Re:

Postby BackwardsMan on Fri Feb 03, 2006 10:39 am

Gee, thanks. Good old Sinner
BackwardsMan
 
Posts: 63
Joined: Wed Jan 22, 2003 11:24 am

Re:

Postby Me on Fri Feb 03, 2006 11:17 am

How do you do it? *Blush* I can't find it on Student Portal or Webmail :(
Me
 

Re:

Postby Thackary on Fri Feb 03, 2006 12:53 pm

You can change your password via the IT Services webpage:
http://www.st-andrews.ac.uk/its/

There's a link to "Change Passwords".

There's other useful information on there, such as the messages from ITS, which detail any other security measures you should take.
Thackary
 
Posts: 3034
Joined: Thu Jan 01, 1970 12:00 am

Re:

Postby Thackary on Fri Feb 03, 2006 1:24 pm

That's weird - my previous one contained a dictionary word, and I was allowed to change it.

Have another go!
Thackary
 
Posts: 3034
Joined: Thu Jan 01, 1970 12:00 am

Re:

Postby Dave the Explosive Newt on Fri Feb 03, 2006 1:25 pm

Quoting thackary from 10:30, 3rd Feb 2006
Because apparently someone got hold of the entire list of usernames and passwords. Oops.


How did that happen? Was the university hacked?

[hr]

This Sinner account is not affiliated with Will Watson.
Dave the Explosive Newt
 
Posts: 1470
Joined: Thu May 19, 2005 3:29 pm
Location: Cambridge

Re:

Postby Don on Fri Feb 03, 2006 3:32 pm

Has anyone else noticed that if your password is longer than 8 characters the rest is just ignored? I have a 15 character password and I can still access everything by just typing the first 8 characters of it.

[hr]

Daz, makes your whites #gggggg
Don
 
Posts: 302
Joined: Mon Nov 17, 2003 1:38 pm

Re:

Postby munchingfoo on Fri Feb 03, 2006 3:33 pm

hmm

thats an issue you should probably e-mail ITS about

That leaves a hacking search space of only 23535820(approx), not that big for a computer really.

[hr]

Anyone questioning how I post on the sinner, my new way of life, will offend my "religion" and as such will be dealt with in manners inclusive but by no means exlusive of death threats, random acts of violence, maiming of the general public not involved in this matter and finally a Jihad from all my fellow religious sinners.

For years we have been oppressed by you post nazis, the time of change is upon us.
I'm not a large water-dwelling mammal Where did you get that preposterous hypothesis? Did Steve
munchingfoo
Moderator

 
Posts: 5062
Joined: Fri Dec 06, 2002 2:09 pm

Re:

Postby Gubbins on Fri Feb 03, 2006 3:54 pm

Quoting Don from 15:32, 3rd Feb 2006
Has anyone else noticed that if your password is longer than 8 characters the rest is just ignored?


Yes, by design. ITS passwords are between 5 and 8 letters long. I think it says that when you choose one. It used to anyway.

[hr]

...but then again, that is only my opinion.
...then again, that is only my opinion.
Gubbins
 
Posts: 1210
Joined: Thu Oct 28, 2004 5:56 pm

Re:

Postby Don on Fri Feb 03, 2006 4:06 pm

Quoting Gubbins from 15:54, 3rd Feb 2006
Yes, by design. ITS passwords are between 5 and 8 letters long. I think it says that when you choose one. It used to anyway.


There isn't anything about the maximum length on the main password changing page, or in the general information, the only place it says it is in the "How to create a strong password" page, which I'm guessing not everyone will look at, I certainly never. I feel for a password to be secure it should be as long as possible, definitely longer than 8 characters.

[hr]

Daz, makes your whites #gggggg
Don
 
Posts: 302
Joined: Mon Nov 17, 2003 1:38 pm

Re:

Postby Gubbins on Fri Feb 03, 2006 4:12 pm

Quoting Don from 16:06, 3rd Feb 2006
I feel for a password to be secure it should be as long as possible, definitely longer than 8 characters.


True. My account was created more than five years ago at the time when you went to ITS in the Terrapin Huts to set up your account. The idiot's guide they gave us said to create a password between 5 and 8 characters.

Typically my passwords are randomly generated nine-character alphanumeric strings that I commit to memory, which I feel is one of the safer ways to do it. I just keep generating them until I find one easily memorisable.

[hr]

...but then again, that is only my opinion.
...then again, that is only my opinion.
Gubbins
 
Posts: 1210
Joined: Thu Oct 28, 2004 5:56 pm

Re:

Postby Don on Fri Feb 03, 2006 4:15 pm

Quoting Gubbins from 16:12, 3rd Feb 2006

Typically my passwords are randomly generated nine-character alphanumeric strings that I commit to memory, which I feel is one of the safer ways to do it. I just keep generating them until I find one easily memorisable.


Mine are pretty much the same, except longer.

[hr]

Daz, makes your whites #gggggg
Don
 
Posts: 302
Joined: Mon Nov 17, 2003 1:38 pm

Re:

Postby flarewearer on Fri Feb 03, 2006 6:02 pm

I just make up a random, memorable word, then start randomly replacing letters out of it with similar looking numbers. It therefore bemuses me when I get told my password contains a dictionary word, as its nothing of the sort.

[hr]

image:www.magnificentoctopus.com/x/elgar.png
flarewearer
 
Posts: 4908
Joined: Tue Mar 04, 2003 11:55 pm

Re:

Postby BackwardsMan on Fri Feb 03, 2006 7:35 pm

Quoting flarewearer from 18:02, 3rd Feb 2006
randomly replacing letters out of it with similar looking numbers



Don't you think the hackers have thought of that too? Completely pointless.
BackwardsMan
 
Posts: 63
Joined: Wed Jan 22, 2003 11:24 am

Re:

Postby flossy on Fri Feb 03, 2006 7:49 pm

Dear Knowledgeable peeps,

I have two Webmail accounts (personal and a society one). I've changed the personal one so will the society one change automatically as I'm the owner, or do I have to change that too?

[hr]

Not to put too fine a point on it, say I'm the only bee in your bonnet
If you're not part of the solution, you're part of the substrate.
flossy
 
Posts: 996
Joined: Tue Nov 04, 2003 10:10 pm

Re:

Postby munchingfoo on Fri Feb 03, 2006 7:50 pm

It'l be automatic. You username is linked to the account, the password is not associated with the account. The password is associated with the username so provided you login using the same username there should be no issues.

[hr]

Anyone questioning how I post on the sinner, my new way of life, will offend my "religion" and as such will be dealt with in manners inclusive but by no means exlusive of death threats, random acts of violence, maiming of the general public not involved in this matter and finally a Jihad from all my fellow religious sinners.

For years we have been oppressed by you post nazis, the time of change is upon us.
I'm not a large water-dwelling mammal Where did you get that preposterous hypothesis? Did Steve
munchingfoo
Moderator

 
Posts: 5062
Joined: Fri Dec 06, 2002 2:09 pm

Re:

Postby Nickel on Fri Feb 03, 2006 10:37 pm

Quoting munchingfoo from 15:33, 3rd Feb 2006

thats an issue you should probably e-mail ITS about

That leaves a hacking search space of only 23535820(approx), not that big for a computer really.



I think they probably know that. The old password systems used to be limited to 8 characters, and once you are using one system it is a real pain to migrate to a new one.
Nickel
 
Posts: 460
Joined: Sun Nov 10, 2002 7:37 pm

Re:

Postby Fawksie on Fri Feb 03, 2006 11:03 pm

Quoting BackwardsMan from 19:35, 3rd Feb 2006
Quoting flarewearer from 18:02, 3rd Feb 2006
I just make up a random, memorable word, then start randomly replacing letters out of it with similar looking numbers


Don't you think the hackers have thought of that too? Completely pointless.


It's still a made up word. How exactly are the hackers going to think of that one?
The fox is a crafty and deceitful animal that never runs in a straight line, but only in circles.
Fawksie
Administrator

User avatar
 
Posts: 1302
Joined: Sun Sep 25, 2005 3:32 pm
Location: Edinburgh

Re:

Postby Atangaladhion on Fri Feb 03, 2006 11:29 pm

Apparently it seems to think that 1QwTysD contains a dictionary word, so I won't be using that as my password :S

[hr]

Numbers are good; functions are better.
Lars Olsen is not the second coming of Jesus Christ. Jesus Christ was the first coming of Lars Olsen.
Atangaladhion
 
Posts: 208
Joined: Thu Sep 30, 2004 12:10 pm

Next

Return to The Sinner's Main Board

Who is online

Users browsing this forum: Bing [Bot] and 25 guests