• Activity
  • Votes
  • Comments
  • New
  • All activity
  • Showing only topics in ~tildes with the tag "passwords". Back to normal view / Search all groups
    1. Minimum password issue

      My password is shorter than 8 characters. When I attempt to log in, I get a validation error telling me so. Luckily, I'm signed in already on this browser. However, when I go to the change...

      My password is shorter than 8 characters. When I attempt to log in, I get a validation error telling me so.

      Luckily, I'm signed in already on this browser. However, when I go to the change password page and attempt to make my password longer, I get a validation error telling me my old password is shorter than 8 characters, and it prevents submitting the form.

      8 votes
    2. Are tildes passwords salted?

      I was reading over tildes' privacy policy and saw that passwords are stored hashed, but are they salted as well?...

      I was reading over tildes' privacy policy and saw that passwords are stored hashed, but are they salted as well?

      https://defaultnamehere.tumblr.com/post/163734466355/operation-luigi-how-i-hacked-my-friend-without#fnref:salted

      not that tildes is big enough atm to have big public database breaches, but in the future it's a good idea to store passwords with a secure salting system, especially to help users that might have common passwords like "Diane" in the Tumblr post.

      26 votes
    3. Password recovery / reset email clarity issues

      Hi there. The account recovery page mentions that password resets are performed by emailing a specific Tildes address from your own specified recovery address. But as far as I can see, that Tildes...

      Hi there. The account recovery page mentions that password resets are performed by emailing a specific Tildes address from your own specified recovery address. But as far as I can see, that Tildes reset address that's supposed to be sent to.. is unlisted anywhere on the website. I could be mistaken, of course, but in any case it's not easily visible. Also unlisted is what string should be placed in the Subject field, alongside any body content this sent email should contain.

      As to the reason for the inquiry:

      So when I registered for Tildes, I generated a password and stored it in my KeePass database like a responsible person. Except... like an idiot, I restarted my computer at some point without remembering to actually save my KP database (I promise this is only like the second time this has happened in 2 years or so), so I'm in the curious position of still being logged in but not actually being able to change my password. Naturally, I explored account recovery options, and registered my email address with the recovery page, but as I described above, I can't seem to find the address I'm supposed to send an email to in order to reset my password as part of the recovery process.

      6 votes
    4. The password compromised feature is great

      I just joined the site less than an hour ago and when I registered I tried to use my normal password that I use on a lot of sites (I know, I know) and it wouldn't let me register because the...

      I just joined the site less than an hour ago and when I registered I tried to use my normal password that I use on a lot of sites (I know, I know) and it wouldn't let me register because the password has shown up in a data breach. I double checked on https://haveibeenpwned.com/ and sure enough, my password was compromised at some point. So now I know I need to go back and change my password on a hell of a lot of sites.

      Anyway, thank you. I've never seen that feature on a site before and it saved my ass before an account of mine was really compromised.

      26 votes
    5. Password reset

      I don't need to reset my password, and I really appreciate the way that it is done to maximize anonymity. However, I think there is a bit of a problem with how it is done in terms of users getting...

      I don't need to reset my password, and I really appreciate the way that it is done to maximize anonymity. However, I think there is a bit of a problem with how it is done in terms of users getting locked out.

      If you're locked out, as far as I can tell, there is no way to view the email hint associated with your account. It seems a bit counter intuitive to me that in order to see the hint for how to regain access to your account, you have to already have that access! I also think that it won't work in the case that someone has been away for a few months and has forgotten their password. I'm not sure what a good way of displaying the hint would be, however, since if it is done by username anyone who has seen your posts can look at your password hint.

      Hopefully with a bit of discussion we can cook something up that can solve this catch 22!

      11 votes