📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Is this private message from MSE?

Had a direct message on here from MSE Zorica saying:

Hi there,

As part of our Forum Redesign, we want to make sure forum users passwords are as strong as possible and our techies have asked us to get in touch to make yours more secure.
If you could you give us a hand by changing your password to something stronger when you next log in we would be very grateful.

To change your password go to your Edit Password page.

To make it stronger use a combination of upper and lowercase characters, numbers and letters.

Thanks in advance for your help

MSE Forum Team


Is this a genuine message from MSE or a scammer/spammer?
Not really comping any more as too ill - but hoping to win £1000+ in 2017 in cash prizes - watch this space!
«1

Comments

  • kazwookie
    kazwookie Posts: 14,310 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    I got this as well! and I've changed it, may be I'll do it again now
    Breast Cancer Now 100 miles October 2022 100 / 100miles
    D- Day 80km June 2024 80/80km (10.06.24 all done)
    Diabetic UK 1 million steps July 2024 to complete by end Sept 2024. 1,001,066/ 1,000,000 (20.09.24 all done)
    Breast Cancer Now 100 miles 1st May 2025 (18.05.2025 all done)
    Diabetic UK 1 million steps July 2025 to complete by end Sept 2025. 1,006,489 / 1,000,000 (10.09.25 all done)
    Sun, Sea
  • Is this a genuine message from MSE

    Yes. Please follow the instructions int he PM. Thank you.

    Ian
  • Old_Wrinkly
    Old_Wrinkly Posts: 5,182 Forumite
    Am I the only one that thinks there is more to this? ;):(

    Or is that just my extreme suspicious nature coming to the fore? :o
  • Upsidedown_Bear
    Upsidedown_Bear Posts: 18,264 Forumite
    10,000 Posts Combo Breaker
    I haven't had a message about this so I'm assuming MSE think my password is secure.
    But how do they know my password is secure as I thought they were supposed to be encrypted? If the people working at MSE can find out what your password is isn't that asking for trouble?
  • Candy53
    Candy53 Posts: 2,548 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Photogenic
    I haven't had one either, so I thought my password must be a good one, but then, I also thought how do they know?



    Candy
    What goes around, comes around.
  • hi Upsidedown Bear,
    But how do they know my password is secure as I thought they were supposed to be encrypted?

    They are encrypted. Even I cannot see your password. And would not want to. But it’s quite simple. If your password is "password", or "password123", or "password12345" then it doesn’t matter that it's encrypted on our servers. It’s not difficult to guess.
    If the people working at MSE can find out what your password is isn't that asking for trouble?

    Unfortunately there is only so much we can realistically do to make a weak password secure. And we are donig it now by getting to the root cause of the problem. Encouraging people to use stronger passwords.

    It's as simple as that really. I hope that makes sense.

    Ian
  • Mr_Ted
    Mr_Ted Posts: 1,067 Forumite
    :mad: I also have concerns about this message as when i opened it a popup window attempted to open, THIS has never happened before and makes me extremely suspicious :(

    Fortunately I have plenty of security which should stop any issues :)

    BUT I DO have concerns that this is NOT genuine, perhaps someone should explain how and why this has occurred, particularly as my password IS how it is suggested a new one should be :p

    Would it be correct to suspect that a hack has been attempted which has initiated this, as this is often the reason for such events :eek:
    Signature removed
  • Old_Wrinkly
    Old_Wrinkly Posts: 5,182 Forumite
    MSE_Ian wrote: »
    hi Upsidedown Bear,

    They are encrypted. Even I cannot see your password. And would not want to. But it’s quite simple. If your password is "password", or "password123", or "password12345" then it doesn’t matter that it's encrypted on our servers. It’s not difficult to guess.

    Unfortunately there is only so much we can realistically do to make a weak password secure. And we are donig it now by getting to the root cause of the problem. Encouraging people to use stronger passwords.

    It's as simple as that really. I hope that makes sense.

    Ian

    So how does that explain Monkeyballs getting a PM? :
    http://forums.moneysavingexpert.com/showpost.php?p=64303126
    Their password would seem to follow good practice.

    (And now Mr Ted saying a similar thing.)

    Is the PM being sent out to everyone (eventually), or just a few users that MSE considers (for some reason) to have 'less than secure' passwords?
  • StumpyPumpy
    StumpyPumpy Posts: 1,458 Forumite
    Part of the Furniture 1,000 Posts Photogenic
    MSE_Ian wrote: »
    Unfortunately there is only so much we can realistically do to make a weak password secure. And we are donig it now by getting to the root cause of the problem. Encouraging people to use stronger passwords.
    Unfortunately, I think you are adding to the problem by sending what I assume to be a filtered message (I didn't get one, and nor did a number of others going by the replies to the various threads here who seemingly have passwords that pass your cracking algorithm)

    You should really have had an alert on the forums (like the down time ones) ahead of the message so that people would know it was genuine without having to ask. This would also have helped to mitigate the numbers of people who are now posting in various threads saying they have received the message.

    These threads are a hackers delight. They now have a list of usernames with people effectively announcing that they have an insecure password that is highly susceptible to brute force cracking. Thanks. Makes it a lot more trivial to get in. You need to make removing these messages a priority then enforce password changes on those that have done so because they have blown what remained of their security sky high, thanks to your unannounced message.

    SP
    Come on people, it's not difficult: lose means to be unable to find, loose means not being fixed in place. So if you have a hole in your pocket you might lose your loose change.
  • Hi Mr Ted,
    Mr_Ted wrote: »
    i opened it a popup window attempted to open

    It's a standard feature. If you don't like it you can go to UserCP -> Edit Options, untick where it says "Show New Private Message Notification Pop-up", and click Save.

    Please bear in mind though that some modern browsers have pop-up blockers which might block these popup windows and prevent them from openning even if you have this option ticked.

    Ian
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351.7K Banking & Borrowing
  • 253.4K Reduce Debt & Boost Income
  • 454K Spending & Discounts
  • 244.6K Work, Benefits & Business
  • 600K Mortgages, Homes & Bills
  • 177.3K Life & Family
  • 258.3K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.2K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.