• Starting today August 7th, 2024, in order to post in the Married Couples, Courting Couples, or Singles forums, you will not be allowed to post if you have your Marital status designated as private. Announcements will be made in the respective forums as well but please note that if yours is currently listed as Private, you will need to submit a ticket in the Support Area to have yours changed.

URGENT! CF had a security loophole, so all members must change their passwords!

Freodin

Devout believer in a theologically different God
Mar 9, 2002
15,713
3,762
Germany, Bavaria, Middle Franconia
Visit site
✟260,281.00
Faith
Atheist
nyj said:
Wow... you got me beat. My password was only 12611 days old.

No, I don´t think I got you beat. If others had that number, too, it´s more likely I did not remeber it correctly.

I only remembered that it had 5 numbers, started with a 1 and contained a 6.

So my message will have been 12611 as well.

But I am relieved - now I only logged in for the first time when I was six months old - instead of -5.

 
Upvote 0

seebs

God Made Me A Skeptic
Apr 9, 2002
31,917
1,530
20
Saint Paul, MN
Visit site
✟70,235.00
Faith
Seeker
Marital Status
Married
Politics
US-Republican
Ooh, that's a good thing to know. I changed my password, and then when I had to change it again, changed it back, figuring I'd have a "new cookie".

(Amazingly, at least on tests, I am reported as being fairly smart, and I do a lot of computer stuff, and even some security stuff. You'd think I could apply this, but Noooooo.)
 
Upvote 0

Krazeekkc

Irregular Nonconformist
Oct 2, 2003
1,064
30
33
Oregon, USA
Visit site
✟16,491.00
Faith
Non-Denom
I got "your password is 256 days old"! So yay I'm unique! 256! lol
 
Upvote 0

crazyfingers

Well-Known Member
May 17, 2002
8,733
329
Massachusetts
Visit site
✟33,923.00
Faith
Atheist
Marital Status
Married
Politics
US-Democrat
I'm wondering if there has also been a change in how CF sets cookies. I ask
because ever since I was required to changed my password, I have been unable to save cookies for auto-login under "Remember me".

I use Mozilla Firefox and have my cookies set to always and normal and my password manager to remember passwords. Despite this, all of the CF cookies are marked "For current session only" and delete once I close the browser.

I have reset my password a second time, though the system has not asked me to do so yet.

BTW, I have no problem with the "remember me" passwords on other vb3 boards. For example, I've cleared my cookies for Internet Infidels www.iidb.org and re-logged in. Those new cookes are marked to remain valid for a year.

This problem is unique to CF and started when I had to change my password.

Sorry if this has already been discussed. I have looked and have not found mention of this issue.
 
Upvote 0

Erwin

Well-Known Member
May 13, 2015
201,108
1,803
✟216,037.00
Hi cf, good to see you on CF.

CF uses the default vB3 cookie system.

I suspect your cookie got corrupted in the changing of passwords. You can also get cookie problems if you've logged into CF using different domains or using the root domain - for example, logging in at christianforums.com, then again using www.christianforums.com, can cause cookie problems.

Our FAQ comments on this. You can delete ALL cookies in your browser, and log in again. Or, at least, delete all cookies in your browser attached to CF domains.
 
Upvote 0

crazyfingers

Well-Known Member
May 17, 2002
8,733
329
Massachusetts
Visit site
✟33,923.00
Faith
Atheist
Marital Status
Married
Politics
US-Democrat
Hi Erwin, Thanks for the response.

Erwin said:
Hi cf, good to see you on CF.

CF uses the default vB3 cookie system.

I suspect your cookie got corrupted in the changing of passwords.

Yes. Though I've logged in and out multiple times so the cookies have been created and destroyed multiple times now. I have check the cookie manager and confirned that they are there or are not there as appropriate. However when they do exist, they are marked as on-sessio-only whereas my other cookies are all marked as having a year's life.

You can also get cookie problems if you've logged into CF using different domains or using the root domain - for example, logging in at christianforums.com, then again using www.christianforums.com, can cause cookie problems.

I always use the same bookmark to open CF. It opens to the main index.


Our FAQ comments on this. You can delete ALL cookies in your browser, and log in again. Or, at least, delete all cookies in your browser attached to CF domains.

Well, deleting the cookies isn't the problem. The problem is that they auto-delete when the browser session is closed. They are being created as one-session-only cookies and auto-delete on browser closure.

This means of course that I have to manually log-in every time I visit CF with a new browswer session.

I would suspect that something was wrong with my own settings if I had this problem with other vB3 boards. However I'm unable to reproduce the effect on any other board. This problem only happens on CF and only started after I was notified that I had to change my password.

So I wondered of there was something different about how CF was set up.

In any case, since this doesn't ring a bell with you, I'll continue to look for a solution from my side.
 
Upvote 0

alaurie

Welcome, Preston!!!
Feb 21, 2004
2,474
156
✟19,056.00
Faith
Methodist
Marital Status
Private
Politics
US-Republican
Mϋzikdϋde said:
...This happens all the time on the internet. People gain entry into places by exploiting someone's information but they are ususally NOT after the person whose info they are using. The information is just a conduit to reach a different goal.
....Sure, it happens all the time but is it legal?
 
Upvote 0

Mϋzikdϋde

Simply Fabulous
Sep 19, 2002
3,970
258
61
Colorado Springs
Visit site
✟28,025.00
Faith
Christian
Marital Status
Married
Allye said:
....Sure, it happens all the time but is it legal?
I'll assume the question is rhetorical. I'll also assume you didn't mean to imply that I think it's ok. The mention of that fact that it's a common practice shouldn't be misconstrued as condoning the act. Even if it weren't illegal, (a felony in some cases) it would still be wrong.
 
Upvote 0

Erwin

Well-Known Member
May 13, 2015
201,108
1,803
✟216,037.00
Odd... do you click the "Remember Me" box when you log in? Because you need to do that to create a cookie that is permanent.
 
Upvote 0

September

Regular Member
Oct 7, 2003
257
15
62
Saskatchewan, Canada
Visit site
✟477.00
Faith
Anglican
Erwin said:
Odd... do you click the "Remember Me" box when you log in? Because you need to do that to create a cookie that is permanent.
I'm having exactly the same problem as crazyfingers, and yes, I have checked the "Remember Me" box. But I still have to enter my password every time I return.
 
Upvote 0