• Starting today August 7th, 2024, in order to post in the Married Couples, Courting Couples, or Singles forums, you will not be allowed to post if you have your Marital status designated as private. Announcements will be made in the respective forums as well but please note that if yours is currently listed as Private, you will need to submit a ticket in the Support Area to have yours changed.

URGENT! CF had a security loophole, so all members must change their passwords!

Erwin

Well-Known Member
May 13, 2015
201,108
1,803
✟216,037.00
Hi,

It has come to my attention that CF had a security loophole - it was an obscure one, but it was one that one or more hackers had taken advantage of. What it allowed was for a hacker to copy a member's cookie onto their own computer, and to log on as the member.

The hacker did not get the member's password since that is encrypted - all he got was the cookie. However, with this cookie, the hacker could log in as the member. In fact, this hacker got access to staff accounts as well.

I have spoken to the hacker himself, and though his identity will remain private, this is not something I've made up. It's real.

As such, I've made it so that all members are forced to change their passwords. Once you have changed your password, this will invalidate any old cookie, and would render the hacker unable to log in as another member anymore.

The security loophole has been removed since.

This only affects people who had their cookies stolen - not all members are affected. But to play it safe, all members must have their passwords changed just in case.

My apologies for the inconvenience. I am still in shock, and still in a phase of recovering from this.

Thank you for understanding.
 

Erwin

Well-Known Member
May 13, 2015
201,108
1,803
✟216,037.00
For the curious members, it was that popup spoiler tag that had the security loophole. I knew about it but didn't think it could be compromised - a smart member figured it out, and used it to get access to our staff forums, and more than one staff account, and in all probability, more than one member account. Also, there may be more than one member who did this.

This is one reason why I changed the spoiler tag to a dropdown window... but obviously I was too late.

Sorry again for not fixing this earlier.

At least no real damage was done - the problem is fixed with a simple password change, so this is why all members need to do this.
 
  • Like
Reactions: OceanAngel
Upvote 0

USincognito

a post by Alan Smithee
Site Supporter
Dec 25, 2003
42,070
16,820
Dallas
✟918,891.00
Country
United States
Gender
Male
Faith
Atheist
Marital Status
Private
I got a "password over 200 days" notice last night, and just got a "password over 1 day notice" is this a bug or just part of the overall threat level response and my home computer's cookie vs. work computer?

Any indication that I'll need to change my password daily? I hope not. :cool:
 
Upvote 0

Freodin

Devout believer in a theologically different God
Mar 9, 2002
15,713
3,762
Germany, Bavaria, Middle Franconia
Visit site
✟260,281.00
Faith
Atheist
Thanks for the explanation - and the quick action to make sure this forum stays a save room for us to communicate.

I have to wonder though: the initial message I got said that my password was over 16000 days old. I know how time flies by - but I did not realize I had been om this forum for over 40 years. ;)
 
Upvote 0

HisWinterRose

WIFE & MOM
Jul 8, 2004
2,501
1,012
67
OHIO
✟81,814.00
Country
United States
Gender
Female
Faith
Christian
Marital Status
Married
Politics
US-Republican
I was sorta wondering if something was wrong when I went to get on this morning it said that my PASSWORD was 3 days old & that I needed to change it so I did and then soon after I posted it came up again and I had to change it again so ... I did so I hope that my problem is ok ... so thanks for keeping us posted !!

T- BEAR
 
Upvote 0

Mistermystery

Here's looking at you kid
Apr 19, 2004
4,220
169
✟5,275.00
Faith
Atheist
USincognito said:
I got a "password over 200 days" notice last night, and just got a "password over 1 day notice" is this a bug or just part of the overall threat level response and my home computer's cookie vs. work computer?

Any indication that I'll need to change my password daily? I hope not. :cool:
Ditto for me. Security is okay, but having to change your password 50 times a day is riddiculous.
 
Upvote 0

Steve_SandbachBaptist_UK

Well-Known Member
Jun 3, 2004
3,364
44
40
Cheshire
Visit site
✟26,293.00
Faith
Baptist
Marital Status
Single
Firstly, apologies for my email moaning, I was just peeved at having to change my password after just over a month. Secondly, very strange that some1 actually on the forums would log into other members' accounts...not christian behaviour either, but then it may have been a non-Christian.

Steve :wave:
 
Upvote 0