jamulbob
Max Output Level: -90 dBFS
- Total Posts : 3
- Joined: 2011/05/01 23:27:41
- Status: offline
Password security
Sorry about the security post in this forum but this is the one I read and I didn't find a better one. I became a registered user of cakewalk forums and provided a login name and password. Then cakewalk forums emailed to me my login name and password. Oh no! I was shocked. The password of your trusting members should never reside on your computers or anywhere in cyber space, unencrypted and plain text readable. That is a security weakness. Cakewalk should know better. Upon receiving that email I know that cakewalk plus some web based email server has that information stored in readable form just waiting for a hacker to retrieve. There is no need to do what you did. When I send my password it should first go through a one way encryption algorithm and the output of that unlocks my privileges. Never, ever, store the password itself! It doesn't take a PhD in computer sciences or human behavior to grasp the breadth of the risk. Sorry for the harsh rhetoric and I look forward to the responses.
|
KeithS
Max Output Level: -87 dBFS
- Total Posts : 182
- Joined: 2005/02/19 22:55:11
- Location: Mobile, Alabama
- Status: offline
Re:Password security
2011/05/05 11:35:13
(permalink)
jamulbob I became a registered user of cakewalk forums and provided a login name and password. Then cakewalk forums emailed to me my login name and password. Oh no! I was shocked. I look forward to the responses. My God. The cyberworld as we know it will surely come to an end if someone figures out how to log into this forum under my ID.
Keith SONAR X1d Producer Expanded (64 bit), Waves Platinum Home built PC Intel i7 2600K, ASUS P8P67 MoBo 16 Gb RAM, Windows 7 Ultimate (64 bit) TASCAM FW-1884 EEE-1394 Legacy driver PNY GeForce GTX 560Ti graphics card 2 ASUS V249H LED Monitors.
|
bluzdog
Max Output Level: -56 dBFS
- Total Posts : 1928
- Joined: 2007/10/06 17:15:14
- Location: Lakewood, Colorado
- Status: offline
Re:Password security
2011/05/05 12:34:21
(permalink)
I think the point is that if they do that with forum passwords, what do they do with user account passwords?
|
KeithS
Max Output Level: -87 dBFS
- Total Posts : 182
- Joined: 2005/02/19 22:55:11
- Location: Mobile, Alabama
- Status: offline
Re:Password security
2011/05/05 13:01:04
(permalink)
bluzdog I think the point is that if they do that with forum passwords, what do they do with user account passwords? I'm not prone to those kinds of leaps in logic but have at it.
Keith SONAR X1d Producer Expanded (64 bit), Waves Platinum Home built PC Intel i7 2600K, ASUS P8P67 MoBo 16 Gb RAM, Windows 7 Ultimate (64 bit) TASCAM FW-1884 EEE-1394 Legacy driver PNY GeForce GTX 560Ti graphics card 2 ASUS V249H LED Monitors.
|
Kalle Rantaaho
Max Output Level: -5 dBFS
- Total Posts : 7005
- Joined: 2006/01/09 13:07:59
- Location: Finland
- Status: offline
Re:Password security
2011/05/05 15:07:30
(permalink)
The OP has a point there, but every single forum I've signed in uses the same procedure. The actual risk might rise from the fact that people tend to use the same password for many purposes, like managing their energy bills on the power-companys site or other money-related traffic. How many have the same, or almost the same password for Paypal and some forum?
SONAR PE 8.5.3, Asus P5B, 2,4 Ghz Dual Core, 4 Gb RAM, GF 7300, EMU 1820, Bluetube Pre - Kontakt4, Ozone, Addictive Drums, PSP Mixpack2, Melda Creative Pack, Melodyne Plugin etc. The benefit of being a middle aged amateur is the low number of years of frustration ahead of you.
|
KeithS
Max Output Level: -87 dBFS
- Total Posts : 182
- Joined: 2005/02/19 22:55:11
- Location: Mobile, Alabama
- Status: offline
Re:Password security
2011/05/05 15:18:38
(permalink)
Kalle Rantaaho How many have the same, or almost the same password for Paypal and some forum? Not even close or in the same security universe. But I see your point. Cakewalk forums should anticipate foolish use of high security passwords in low security situations.
Keith SONAR X1d Producer Expanded (64 bit), Waves Platinum Home built PC Intel i7 2600K, ASUS P8P67 MoBo 16 Gb RAM, Windows 7 Ultimate (64 bit) TASCAM FW-1884 EEE-1394 Legacy driver PNY GeForce GTX 560Ti graphics card 2 ASUS V249H LED Monitors.
|
jamulbob
Max Output Level: -90 dBFS
- Total Posts : 3
- Joined: 2011/05/01 23:27:41
- Status: offline
Re:Password security
2011/05/05 16:28:55
(permalink)
Kalle Ranta-aho indeed understands the breadth of the risk. Below is a snip of email from celemony. I like their approach to security. Welcome to celemony_ forums Please keep this e-mail for your records. Your account information is as follows: ... snip ... Your password has been securely stored in our database and cannot be retrieved. In the event that it is forgotten, you will be able to reset it using the email address associated with your account. Thank you for registering.
|
daryl1968
Max Output Level: 0 dBFS
- Total Posts : 10984
- Joined: 2010/06/01 22:51:43
- Location: Englishman in deepest, darkest Wales
- Status: offline
Re:Password security
2011/05/05 17:19:18
(permalink)
PARANOIA - this isn't the Playstation Network, Jamulbob - relax, go and spend some time on X1 - be creative - don't sweat the small stuff Daryl
|
Re:Password security
2011/05/05 22:38:39
(permalink)
Your forum password is not stored in plain text in the database, this is only sent out when you create a new login or change your password. This is not unlike other forum software. Some companies have one login for their forums and store, we don't. The Cakewalk store has it's own set of user databases and everything is encrypted in addition to using https. The forum and Cakewalk store do not 'talk' to each other or share information. As a general guideline you should probably never use the same password for forums as anything that is even remotely close to your personal or financial information. Even if we disabled emailing the password there are thousands of sites that use the same forum software and even more that are using things like phpBB or vBulletin. If someone with ill intentions did manage to hack into a web server running any of the popular forum software all they would have to do is download a trial version to wrap their heads around the database schema. I do hear you loud and clear though just don't totally agree, after all its a forum not a financial institution. If the general consensus though is please don't do that we can disable the emailing of passwords, but I can't guarantee we'll keep it off if a flood of new users call or email about losing their forum password.
post edited by Willy Jones [Cakewalk] - 2011/05/06 11:06:46
|
chuckebaby
Max Output Level: 0 dBFS
- Total Posts : 13146
- Joined: 2011/01/04 14:55:28
- Status: offline
Re:Password security
2011/05/05 22:46:33
(permalink)
omg..what if someone starts posting stuff under my screen name?..smart stuff?.. dude this is the cake walk forum not bank of usa. welcome to the forum by the way.
Windows 8.1 X64 Sonar Platinum x64 Custom built: Asrock z97 1150 - Intel I7 4790k - 16GB corsair DDR3 1600 - PNY SSD 220GBFocusrite Saffire 18I8 - Mackie Control
|
Guitarhacker
Max Output Level: 0 dBFS
- Total Posts : 24398
- Joined: 2007/12/07 12:51:18
- Location: NC
- Status: offline
Re:Password security
2011/05/06 08:11:59
(permalink)
Hey Willy... where do you keep the launch codes for the ICBM's? I'm having a hard time finding them on this site. I thought ALL the websites I've had to sign up & in on did the same thing... cause I ALWAYS get an email with the log in and PW..... and me, being the security conscious person that I am..... I write them down on a piece of paper that I keep laying on my desk right beside the computer. I tend to delete or otherwise loose the emails and what in the world happens when the log in email address is no longer valid and I have forgotten the log in & PW and have to use "retrieve log in/PW?
My website & music: www.herbhartley.com MC4/5/6/X1e.c, on a Custom DAW Focusrite Firewire Saffire Interface BMI/NSAI "Just as the blade chooses the warrior, so too, the song chooses the writer "
|
craigb
Max Output Level: 0 dBFS
- Total Posts : 41704
- Joined: 2009/01/28 23:13:04
- Location: The Pacific Northwestshire
- Status: offline
Re:Password security
2011/05/06 14:03:54
(permalink)
This is why I usually use "chuakworcoaraanahwwrcrarrahanahcaoahoawokakahraanoowaoooaahoohuc" as my password.
Time for all of you to head over to Beyond My DAW!
|
Starise
Max Output Level: -0.3 dBFS
- Total Posts : 7563
- Joined: 2007/04/07 17:23:02
- Status: offline
Re:Password security
2011/05/06 14:13:09
(permalink)
If you want to minimize risk change your password right away...FYI also remove photo tags if you don't want them known. I did report one incident. I'm not loosing any sleep over it but it caused me to go on alert............At least they didn't get to those launch codes. Some of you use open servers. for pics.....a person can go on there and look around.....not that I have mind you.
Intel 5820K O.C. 4.4ghz, ASRock Extreme 4 LGA 2011-v3, 16 gig DDR4, , 3 x Samsung SATA III 500gb SSD, 2X 1 Samsung 1tb 7200rpm outboard, Win 10 64bit, Laptop HP Omen i7 16gb 2/sdd with Focusrite interface. CbB, Studio One 4 Pro, Mixcraft 8, Ableton Live 10 www.soundcloud.com/starise Twitter @Rodein
|
Russell.Whaley
Max Output Level: -47.5 dBFS
- Total Posts : 2755
- Joined: 2006/03/01 11:53:45
- Location: Baja Manitoba
- Status: offline
Re:Password security
2011/05/06 14:13:50
(permalink)
Guitarhacker Hey Willy... where do you keep the launch codes for the ICBM's? I'm having a hard time finding them on this site. "ICBM" - Instant Cakewalk Beat Maker? Just wonderin'...
|
geoffemm
Max Output Level: -90 dBFS
- Total Posts : 1
- Joined: 2011/08/25 08:53:23
- Location: Weymouth, UK
- Status: offline
Re:Password security
2011/08/25 09:31:59
(permalink)
I’m not sure I understand what the problem is, if there is one at all? Registration takes only a few mins. It takes even less time, once you press enter, for your details to be logged on the system and an E-mail confirming your details to be sent to you. Once you have validated your account it’s a simple matter to go in and CHANGE YOUR PASSWORD! The whole process, including registration, can be done in about three mins. However, assuming that someone is able to hack your account, what’s the worst they can do – get your E-mail address? WOW!
|
bapu
Max Output Level: 0 dBFS
- Total Posts : 86000
- Joined: 2006/11/25 21:23:28
- Location: Thousand Oaks, CA
- Status: offline
Re:Password security
2011/08/25 12:45:50
(permalink)
Great idea geoffemm, Give me your password and I'll change it for you.
|
UbiquitousBubba
Max Output Level: 0 dBFS
- Total Posts : 8912
- Joined: 2008/07/09 16:55:12
- Location: Everywhere Else
- Status: offline
Re:Password security
2011/08/25 12:51:12
(permalink)
I can't get hackers to use my passwords. They don't want to be associated with me. They also said I didn't have anything they wanted. Anymore.
|
bapu
Max Output Level: 0 dBFS
- Total Posts : 86000
- Joined: 2006/11/25 21:23:28
- Location: Thousand Oaks, CA
- Status: offline
Re:Password security
2011/08/25 12:53:23
(permalink)
So long and thanks for all the fish.
|
craigb
Max Output Level: 0 dBFS
- Total Posts : 41704
- Joined: 2009/01/28 23:13:04
- Location: The Pacific Northwestshire
- Status: offline
Re:Password security
2011/08/25 13:27:17
(permalink)
Just to be safe, I've changed all my passwords to "********" - it's just better that way.
Time for all of you to head over to Beyond My DAW!
|
Meffy
Max Output Level: -78 dBFS
- Total Posts : 629
- Joined: 2003/11/22 16:41:23
- Status: offline
Re:Password security
2011/08/25 13:35:51
(permalink)
Despite his nick being very like my name reversed, geoffemm is not someone who has hacked into my account to seize my user name (passwords are sooo passé). Just sayin'.
|
craigb
Max Output Level: 0 dBFS
- Total Posts : 41704
- Joined: 2009/01/28 23:13:04
- Location: The Pacific Northwestshire
- Status: offline
Re:Password security
2011/08/25 13:57:32
(permalink)
Meffy Despite his nick being very like my name reversed, geoffemm is not someone who has hacked into my account to seize my user name (passwords are sooo passé). Just sayin'. So nice to meet you Mmeffoeg.
Time for all of you to head over to Beyond My DAW!
|
Meffy
Max Output Level: -78 dBFS
- Total Posts : 629
- Joined: 2003/11/22 16:41:23
- Status: offline
Re:Password security
2011/08/25 14:33:48
(permalink)
Very like, not identical. :-}
|