We're aware that some users are experiencing technical issues which the team are working to resolve. See the Community Noticeboard for more info. Thank you for your patience.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Password update prompt

Options
1568101115

Comments

  • parkrunner
    parkrunner Posts: 2,610 Forumite
    Eighth Anniversary 1,000 Posts
    Which will happen first,

    1) we get an honest answer?
    2) this thread gets closed?
    It's nothing , not nothink.
  • System
    System Posts: 178,340 Community Admin
    10,000 Posts Photogenic Name Dropper
    I've just been prompted to update mine, as it's 110 days old! Very strange.
    This is a system account and does not represent a real person. To contact the Forum Team email forumteam@moneysavingexpert.com
  • Twopints wrote: »
    All these people so concerned about security that they haven't changed their password in over 10 years.....

    :beer:
    A strong, secure password containing a sixteen character string of small and capital letters, numbers and symbols will take a quarter of a trillion to a trillion years to crack. I think ten years is not an issue if you follow good security advice.
  • renifer7
    renifer7 Posts: 160 Forumite
    Part of the Furniture 100 Posts
    steppevos wrote: »
    The website is not even using https for the password change page. So all passwords (old and new) are send in plain text over the internet and we can keep using our existing password. So this is a complete non-action.
    I think that MoneySavingExpert may have serious problems with the upcoming Data Protection Legislations coming into force in May this year :T.
    Well, at least it made me aware that MSE doesn't take security very serious.
    Same here, was very surprised to get the warning from my browser about the unsecure connection. I do have HTTPS everywhere but I'm guessing it's not enough. Not Impressed to say the least.
    Someone mentioned there's no point in hacking someone's MSE Forum account - maybe there is, maybe there isn't, if someone happens to use the same password as here for their email address, which is ALSO here, then this is definitely a problem. :mad:
    B)
  • eschaton
    eschaton Posts: 2,094 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    The silence from MSE is deafening!
  • parkrunner
    parkrunner Posts: 2,610 Forumite
    Eighth Anniversary 1,000 Posts
    eschaton wrote: »
    The silence from MSE is deafening!

    Hardly surprising, they don't want to dig themselves any deeper.
    It's nothing , not nothink.
  • Jinhao159
    Jinhao159 Posts: 13 Forumite
    edited 12 February 2018 at 7:47PM
    No response from MSE over the weekend is maybe not too surprising. However, I would have expected something by now.

    Perhaps a request via the Data Commissioners Office. If MSE has been hacked they should have reported it.

    Someone at MSE needs to wake up and tell us what is going on.

    MORE IMPORTANTLY, MSE NEEDS TO PROVIDE A SECURE METHOD OF CHANGING PASSWORDS, ESPECIALLY AS THIS IS SUPPOSEDLY TO IMPROVE SECURITY:(

    I have tried sending a twitter message to @MartinSLewis and @MoneySavingExp along with Facebook. These didn't result in a response from Staurday so not expecting much.

    Also reported it as a technical problem.
  • jackieblack
    jackieblack Posts: 10,493 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    Twopints wrote: »
    All these people so concerned about security that they haven't changed their password in over 10 years.....

    It's a forum! It's not banking, there's no financial or personal information stored...
    Really... Even if someone did have obtain my password (which is more likely now we've had to change it using an unsecure web page than it was in the last 11 years) what's the worst that could happen? :huh:
    2.22kWp Solar PV system installed Oct 2010, Fronius IG20 Inverter, south facing (-5 deg), 30 degree pitch, no shading
    Everything will be alright in the end so, if it’s not yet alright, it means it’s not yet the end
    MFW #4 OPs: 2018 £866.89, 2019 £1322.33, 2020 £1337.07
    2021 £1250.00, 2022 £1500.00, 2023 £1500, 2024 £1350
    2025 target = £1200, YTD £690
    Quidquid Latine dictum sit altum videtur
  • poppy10_2
    poppy10_2 Posts: 6,588 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    If it's a hack MSE have a duty to let us know. Just saying this isn't a banking site doesn't mean it doesn't have to obey the law. Our email addresses are personal information and if these have been obtained by hackers then MSE are obliged to inform us
    poppy10
  • MSE_Andrea wrote: »
    Hi everyone

    As eagle-eyed regular forum members have noticed already, we're asking you all to update your passwords. You should be doing this regularly for your own peace of mind.

    Some hadn't been updated for some time and we want to make sure you change them regularly.

    Thanks for your patience. Have a great weekend.

    Andrea

    What is the point where you're not evening using HTTPS. So all logins are being sent over the network in plain text.

    Anyone using free WIFI and logging into this forum is then exposing their password and user name. Some people, no doubt, are using the same password elsewhere on the web.

    So the forced password change is pointless and also normally a sign a company has had a breach. Is there something you're not telling us?
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 350.8K Banking & Borrowing
  • 253.1K Reduce Debt & Boost Income
  • 453.5K Spending & Discounts
  • 243.8K Work, Benefits & Business
  • 598.7K Mortgages, Homes & Bills
  • 176.8K Life & Family
  • 257.1K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.