We'd like to remind Forumites to please avoid political debate on the Forum... Read More »
We're aware that some users are experiencing technical issues which the team are working to resolve. See the Community Noticeboard for more info. Thank you for your patience.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
someone changed my password
Options

Anthillmob
Posts: 11,780 Forumite
this morning i was logged out of MSE and unable to log in using my username and password.
i know my password was correct because it is one i use on other sites (stupid i know). ive managed to get a new password emailed to me from here and have changed passwords on other sites so none correspond but would like to know if or how someone managed to change my passwrod.
thanks
i know my password was correct because it is one i use on other sites (stupid i know). ive managed to get a new password emailed to me from here and have changed passwords on other sites so none correspond but would like to know if or how someone managed to change my passwrod.
thanks
There's someone in my head, but it's not me
0
Comments
-
right so no one knows then? not even staff?
granted it is crimbo but id still like to know.There's someone in my head, but it's not me0 -
Hi Ant, I think you're not going to get a reply until after Boxing Day, when staff are back...:oBe careful who you open up to. Today it's ears, tomorrow it's mouth.0
-
Anthillmob, it's fundamentally insecure to have anyone able to see the password or to store the actual password in a database. Something like a salted hash is the way to store passwords in a database, so they can be used but not retrieved and used at other sites by anyone who gets them through some security problem.
While it is fundamentally insecure, it's not uncommon to find that passwords are stored in plain text. Any site that will tell you your password via email is not really secure. The secure way to do it is to change your password and tell you the new one, which is what you have to do if you don't store the plain text of the original password. It seems as though that is what has happened here - the more secure approach.
If any bank will tell you your current password or PIN, please complain to their security department about their insecure by design system. They aren't following prudent system design principles which have been known for decades.
The typical problem you see from one of the insecure sites is someone getting the account details, then using the email address and password at lots of other financial sites to see if they work there and transferring the money out of the account if they do.
If you don't want a password for each site, two alternative approaches are:
One high level and one low level password, high level used only for sites that let you move real money, low level for the rest. Very insecure but at least it prevents routine site logins from compromising your banking.
Adding the first or second or last or whatever letter of the site to a base password. Then simple automated use of the password at other sites will fail.0 -
Anthillmob wrote:this morning i was logged out of MSE and unable to log in using my username and password.
i know my password was correct because it is one i use on other sites (stupid i know). ive managed to get a new password emailed to me from here and have changed passwords on other sites so none correspond but would like to know if or how someone managed to change my passwrod.
thanks
I was logged out today too. Managed to get an email sent to me with a password but want to change it now as it's just a bunch of numbers.
Not sure how to do it.:hello: Never say Never :smileyhea0 -
I recommend a program like roboform that will store your usernames and passwords. It wil also create a safe password which no will be able to guess using its password generator0
-
Poppycat wrote:I recommend a program like roboform that will store your usernames and passwords. It wil also create a safe password which no will be able to guess using its password generator
I start to get mixed up with all the passwords..work ones too.
Was off work for a few days, and when back found myself trying to enter my bank password :eek:
Will need to keep a note of them all somewhere safe right enough.:hello: Never say Never :smileyhea0
This discussion has been closed.
Confirm your email address to Create Threads and Reply

Categories
- All Categories
- 350.8K Banking & Borrowing
- 253K Reduce Debt & Boost Income
- 453.5K Spending & Discounts
- 243.8K Work, Benefits & Business
- 598.6K Mortgages, Homes & Bills
- 176.8K Life & Family
- 257K Travel & Transport
- 1.5M Hobbies & Leisure
- 16.1K Discuss & Feedback
- 37.6K Read-Only Boards