Stamp Community Family of Web Sites
Thousands of stamps, consistently graded, competitively priced and hundreds of in-depth blog posts to read








Stamp Community Forum
 
Username:
Password:
Save Password
Forgot your Password?

This page may contain links that result in small commissions to keep this free site up and running.

Welcome Guest! Registering and/or logging in will remove the anchor (bottom) ads. It's Free!

Stamporama Website Hacked

Previous Page
 
To participate in the forum you must log in or register.
Author Previous TopicReplies: 28 / Views: 5,417Next Topic
Page: of 2
Pillar Of The Community
Learn More...
United States
3046 Posts
Posted 10/04/2015   7:34 pm  Show Profile Bookmark this reply Add apastuszak to your friends list  Get a Link to this Reply

Quote:
Lots of techno babble, all of which I know all about.

But here's the bottom line. If your browser password extension can show you your password, a browser hack can show the hacker your password. It's that simple. Your fooling yourself if you think it isn't.


Definitely true.

But using the same password on multiple sites is a bad idea.

I had my Gawker password hacked (and it was a nice long good password) and then within hours someone was in my Google and Amazon accounts.

Plugging your machine into a network cable makes you vulnerable to attack. Ultimate security requires you to be an island.

It's up to us to decide what we're going to use. I like using a password manager, because I got burned. Others may choose a different route.

What do you recommend as best practices?
Send note to Staff  Go to Top of Page
Free Ukrainian Stamp Album and modified Mystic Stamp Album Pages - http://www.stamphacks.com
Ukrainian Philatelic and Numismatic Society Member #1212: http://www.upns.org
Eire Philatelic Association Member #2869: http://www.eirephilatelicassoc.org/
Forum Dad
Learn More...
USA
2055 Posts
Posted 10/04/2015   8:14 pm  Show Profile Bookmark this reply Add bobby131313 to your friends list  Get a Link to this Reply
I use an algorithm based on the site's domain name. It's easy to remember the procedure to build the password in my head and I can figure out the password in seconds. It's always at least 15 characters and hits "strong" on every site that has a meter.
Send note to Staff  Go to Top of Page
Pillar Of The Community
Learn More...
United States
3046 Posts
Posted 10/04/2015   9:41 pm  Show Profile Bookmark this reply Add apastuszak to your friends list  Get a Link to this Reply

Quote:
I use an algorithm based on the site's domain name. It's easy to remember the procedure to build the password in my head and I can figure out the password in seconds. It's always at least 15 characters and hits "strong" on every site that has a meter.


That's pretty slick. A have a friend who's doing that now. Of course if someone figures out your algorithm, you're in trouble, but that's pretty unlikely, unless they did a targeted attack again a dozen or so websites you visit.

One thing we both agree on is, don't use the same password om multiple sites. No need to hand a hacker the keys to the kingdom because of someone else's weak security.
Send note to Staff  Go to Top of Page
Free Ukrainian Stamp Album and modified Mystic Stamp Album Pages - http://www.stamphacks.com
Ukrainian Philatelic and Numismatic Society Member #1212: http://www.upns.org
Eire Philatelic Association Member #2869: http://www.eirephilatelicassoc.org/
Pillar Of The Community
United States
1565 Posts
Posted 10/05/2015   3:31 pm  Show Profile Bookmark this reply Add Climber Steve to your friends list  Get a Link to this Reply
My "password manager" is a notebook concealed within my house. Yes, if the place burns down, I would lose access to sites except my financial site passwords that are memorized. But a notebook can't get hacked.
Send note to Staff  Go to Top of Page
Pillar Of The Community
Canada
728 Posts
Posted 10/14/2015   07:34 am  Show Profile Bookmark this reply Add jimjung to your friends list  Get a Link to this Reply
I use Google Chrome to manage passwords. I think that google has a less chance of being hacked than anything I could setup.

I went to the SOR site to change my password when I got the email just in case it was a phishing email.
Send note to Staff  Go to Top of Page
Edited by jimjung - 10/14/2015 07:35 am
Valued Member
United States
344 Posts
Posted 10/14/2015   4:14 pm  Show Profile Bookmark this reply Add kollectorkurt to your friends list  Get a Link to this Reply
Climber Steve and I share a very secure password manager system.

  • Malicious software is ALWAYS at least one step ahead of your security software, so make sure yours is as current as possible!
  • The only computer which is 100% hack-proof is the one with its power source removed. (Then thrown into the ocean )
  • To reiterate, your best protection is to NEVER use the same password anywhere. I also advise not even using the same LOGON whenever possible.
  • Always use the maximum size password allowed and include as many character types as possible.
  • Change your passwords regularly.
  • Do not store passwords on any computer. <facepalm emoji>
  • Be aware that cloud services are attacked DAILY and are not as secure as you think. Ask Kate Upton about iCloud...
  • The best data hacks are the ones you NEVER hear about.
Send note to Staff  Go to Top of Page
Pillar Of The Community
Learn More...
United States
3046 Posts
Posted 10/14/2015   4:58 pm  Show Profile Bookmark this reply Add apastuszak to your friends list  Get a Link to this Reply

Quote:
Change your passwords regularly.


I never understood why people think this is a required security practice. If you use a unique password on every site, there is no need to change your password unless it is compromised.
Send note to Staff  Go to Top of Page
Free Ukrainian Stamp Album and modified Mystic Stamp Album Pages - http://www.stamphacks.com
Ukrainian Philatelic and Numismatic Society Member #1212: http://www.upns.org
Eire Philatelic Association Member #2869: http://www.eirephilatelicassoc.org/
Valued Member
United States
344 Posts
Posted 10/15/2015   08:33 am  Show Profile Bookmark this reply Add kollectorkurt to your friends list  Get a Link to this Reply

Quote:
I never understood why people think this is a required security practice.

Required? Of course not - BUT - as an IT Security Professional, I am 100% behind this as a "best practice" policy!
Strong, unique passwords are required. (IMLTHO )


Quote:
...there is no need to change your password unless it is compromised.

umm... by the time one finds out about a compromise, it is too late. Sorta like "Closing the barn door after the horse has bolted."


As to making changes, please note that I say "regularly" without any sort of time frame. I have passwords which I have never changed because there is no sensitive personal data behind them. There are passwords which I change on a monthly or quarterly schedule.
Send note to Staff  Go to Top of Page
Pillar Of The Community
Learn More...
United States
3046 Posts
Posted 10/15/2015   08:38 am  Show Profile Bookmark this reply Add apastuszak to your friends list  Get a Link to this Reply
I dunno. Password changes are about as effective as antivirus software these days. Just like AV software being completely unable to stop zero day exploits (cause they're zero day, no one knows about them!), when a password leaks online, it's used pretty fast, because they know people will change them.

The bigger danger in my opinion is letting people have your credit card and watch them walk away with it. I've had my credit card tagged twice this way.

Chipped credit cards are finally coming to the US, but we're not doing chip and pin, like the rest of the world. We're doing chip and SIGN. Stupid on so many levels...
Send note to Staff  Go to Top of Page
Free Ukrainian Stamp Album and modified Mystic Stamp Album Pages - http://www.stamphacks.com
Ukrainian Philatelic and Numismatic Society Member #1212: http://www.upns.org
Eire Philatelic Association Member #2869: http://www.eirephilatelicassoc.org/
Moderator
Learn More...
United States
12330 Posts
Posted 10/15/2015   12:32 pm  Show Profile Bookmark this reply Add 51studebaker to your friends list  Get a Link to this Reply
I'm with kollectorkurt… The only secure computer is powered off, sitting in a lead safe, with armed guards around it. Security requires the three 'P's; Product, People, and Procedures. You can't implement one or two of them and expect to be really secure, it takes attention to all three.

'Products' include things like a good firewall, an AV application, and staying current on OS and browser updates. 'People" is the human aspects; this means that you don't do things like select easy passwords such as 123 or your birthday date. And 'Procedures' means that you follow good security practices like regularly changing passwords and not doing things like posting your email address anywhere online. (Note: to check to see if your email address is posted anywhere online simply Google your address with quotes around it like "joe@anywhere.com".)
Don
Send note to Staff  Go to Top of Page
Pillar Of The Community
United States
1017 Posts
Posted 10/15/2015   5:08 pm  Show Profile Bookmark this reply Add billsey to your friends list  Get a Link to this Reply

Quote:
I'm with kollectorkurt… The only secure computer is powered off, sitting in a lead safe, with armed guards around it.


Needless to say, one of the guards will figure out how to steal it. :)
Send note to Staff  Go to Top of Page
Forum Dad
Learn More...
USA
2055 Posts
Posted 10/15/2015   6:44 pm  Show Profile Bookmark this reply Add bobby131313 to your friends list  Get a Link to this Reply
If you use strong passwords changing them is pointless. A hacker trying to hack your password couldn't possibly care less if you changed your password yesterday, last week, or every day since the beginning of the internet. All he cares about is what it is right now and how many times or when you changed it last doesn't make his job any easier or harder.
Send note to Staff  Go to Top of Page
Moderator
Learn More...
United States
12330 Posts
Posted 10/16/2015   04:18 am  Show Profile Bookmark this reply Add 51studebaker to your friends list  Get a Link to this Reply

Quote:
If you use strong passwords changing them is pointless. A hacker trying to hack your password couldn't possibly care less if you changed your password yesterday, last week, or every day since the beginning of the internet. All he cares about is what it is right now and how many times or when you changed it last doesn't make his job any easier or harder.


I am not sure I completely agree with this… My opinion is that periodically changing passwords is a good idea, especially if I have been traveling and have used several public networks. And while I don't often change my passwords for a site like SCF I do change those which contain my financial info. And I would certainly recommend that any person who is likely to be a target of hacking (i.e Hilary Clinton or Beyonce) to change passwords periodically.

The justification is that it can potentially limit the amount of time another person might have access to your account. Not all hackers make themselves known right away, they may lurk for several months waiting until you have more money in your account or until you post those naked pictures of yourself!
Don
Send note to Staff  Go to Top of Page
Page: of 2 Previous TopicReplies: 28 / Views: 5,417Next Topic  
Previous Page
 
To participate in the forum you must log in or register.

Go to Top of Page

Disclaimer: While a tremendous amount of effort goes into ensuring the accuracy of the information contained in this site, Stamp Community assumes no liability for errors. Copyright 2005 - 2026 Stamp Community Family - All rights reserved worldwide. Use of any images or content on this website without prior written permission of Stamp Community or the original lender is strictly prohibited.
Privacy Policy / Terms of Use    Advertise Here
Stamp Community Forum © 2007 - 2026 Stamp Community Forums
It took 0.24 seconds to lick this stamp. Powered By: Snitz Forums 2000 Version 3.4.05