Password reset questions and feedback

Former_MSE_Andrea
Former_MSE_Andrea Posts: 9,614 Forumite
Combo Breaker First Post I've helped Parliament Rampant Recycler
edited 14 February 2018 at 12:08PM in Site feedback
Hi

Sorry for the lack of notice to the password reset – we should have told you, but we didn’t want to draw attention to the spam creators.

We wanted to clamp down on the amount of spam that gets posted to the forum, and one of the many measures taken was to ask everyone to reset their password, and thus help weed out the bots and disposable accounts.

We’re sorry for the inconvenience caused, but hopefully most managed to easily reset theirs.

If you can’t remember your password you can get a reset link sent to the email you used to register your account.

If you've changed your email address please update it in your user profile settings. If you're having problems updating it e.g., you no longer have access to the email account you registered with please email the Forum Team telling us your original email address.

As an extra measure we’ve also put in place a 90 day time limit for password expiry, and would appreciate your feedback.
Could you do with a Money Makeover?


Follow MSE on other Social Media:
MSE Facebook, MSE Twitter, MSE Deals Twitter, Instagram
Join the MSE Forum
Get the Free MoneySavingExpert Money Tips E-mail
Report inappropriate posts: click the report button
Point out a rate/product change
Flag a news story: news@moneysavingexpert.com
«13456715

Comments

  • alanq
    alanq Posts: 4,216 Forumite
    Combo Breaker First Post
    edited 14 February 2018 at 11:37AM
    "90 day time limit"? Why have we been forced to change after 5 days?
  • You want to clamp down on spam?

    Everyone changed their passwords 5 days ago!

    And now everyone has to change again???!!!

    How much spam is this site getting?

    And how long before the next password change is mandatory?
  • A 90 day expiry on passwords is silly and serves no benefit whatsoever that I can see. How does forcing normal users to change their passwords cut down on spam?
  • Pollycat
    Pollycat Posts: 34,681 Forumite
    Name Dropper First Anniversary First Post Savvy Shopper!
    Andrea
    A number of posters have expressed concern about security issues of being requested to reset passwords
    using a non-secure connection.
    Copied from another (now closed) thread 4 days ago:
    So to "ensure our security" you ask us to set a new password using a non-secure connection.
    That sounds crazy (at least to me).

    Andrea - perhaps you could comment on the security concerns expressed by a number of posters.
    Originally Posted by frankennsteiny viewpost.gif
    But our security isn't coming first when we are being asked to put a new password in over an unsecure connection leaving us open to hackers.

    This is taken from Chrome and is the same for firefox surely a massive site like mse should be a lot more secure.

    rzP3Kj6ct8WH1Ez2S5wV6HCXQVJZg4z0dppd Info or Not secure
    The site isn't using a private connection. Someone might be able to see or change the information you send or get through this site.
    You might see a "Login not secure" or "Payment not secure" message. We suggest that you don't enter sensitive details, like passwords or credit cards.
    On some sites, you can visit a more secure version of the page:

    • Select the address bar.
    • Delete http://, and enter https:// instead.
    If that doesn't work, contact the site owner to ask that they secure the site and your data with HTTPS.
    Don't you think it's now an appropriate time to comment on this security aspect as well as the password reset one?
    Thanks
  • spadoosh
    spadoosh Posts: 8,732 Forumite
    Name Dropper Photogenic First Anniversary First Post
    Theres 3 spam posts on the first page when you click 'new posts' (all boards).
  • Cornucopia
    Cornucopia Posts: 16,154 Forumite
    First Anniversary Name Dropper First Post Photogenic
    If possible, I think it would be more appropriate to base the password reset time on a user's length of time with MSE.

    i.e. a newbie might be asked to reset their password every 60 days (and this could reduce the burden on the system of forgotten newbie accounts). Someone with at least 1 year's membership gets 120 day cycles, 3 years or more gets 360 day cycles.

    Overall, though, I'm not sure I see the connection between this and Spam. I understand, though, that you may not want to give away too much information about it.
  • chesky
    chesky Posts: 1,341 Forumite
    First Anniversary First Post
    I am not what you might call very techie, however if the idea of resetting the passwords (twice) was to curtail the spam, it does not seem to be working. There were 20 spam postings on the credit card board this morning. So, what next?
  • redux
    redux Posts: 22,976 Forumite
    Name Dropper First Anniversary First Post
    edited 14 February 2018 at 12:07PM
    MSE_Andrea wrote: »
    We wanted to clamp down on the amount of spam that gets posted to the forum, and one of the many measures taken was to ask everyone to reset their password, and thus help weed out the bots and disposable accounts.

    As I've said a couple of time before, investigate improving the captcha mechanism on sign-up.

    On another forum I am on, a couple of years ago there were increases in numbers of spam posts (pre-moderated there, so not as bad for all readers), and I was spending about an hour an evening clearing up and banning accounts. I sent a message to admin, he changed the captcha, and spam dropped to 3 or 4 a week.

    I just looked on a website for one of the spambot programmes. They are boasting about improvements in solving captchas, so even this should be a clue that this is something worth looking at here.
  • Can't see how forcing a password change would have much an effect on the spam posts. The usual way forum spammers work is to register, post and (I hope) have their account deactivated by site admin all within a few hours of each other.
  • suki1964
    suki1964 Posts: 14,313 Forumite
    Name Dropper Photogenic First Anniversary First Post
    The boards are awash with spam again

    So I guess this isn't working
This discussion has been closed.
Meet your Ambassadors

Categories

  • All Categories
  • 343.2K Banking & Borrowing
  • 250.1K Reduce Debt & Boost Income
  • 449.7K Spending & Discounts
  • 235.3K Work, Benefits & Business
  • 608K Mortgages, Homes & Bills
  • 173.1K Life & Family
  • 247.9K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 15.9K Discuss & Feedback
  • 15.1K Coronavirus Support Boards