PistonHeads Forum not secure - change your passwords!

PistonHeads Forum not secure - change your passwords!

TOPIC CLOSED
TOPIC CLOSED
Author
Discussion

AndrewEH1

Original Poster:

4,917 posts

154 months

Wednesday 25th January 2017
quotequote all
Here's hoping I don't get an instant ban...I'd ask for Mod from our Community to leave this thread in the Lounge so it doesn't get ignored by the majority of the Community. I guess PH/Haymarket employees might feel differently.

For those who use Google Chrome to browse the internet and these forums you might notice in the coming week or so a pop-up appearing as shown in this thread:

http://www.pistonheads.com/gassing/topic.asp?h=0&a...

This will highlight an issue that PH/Haymarket have been aware of for well over a year and have made no progress on fixing it as highlighted in this thread:

http://www.pistonheads.com/gassing/topic.asp?h=0&a...

The short version is that these forums are not secure, especially if you ever login to this site via a public WiFi connection and login using an email address

I beg all users to please change their PH password to a unique one that you don't use for any other online accounts, especially online banking.

I know we are often told to use separate passwords for every online account but most people (myself included) ignore this advice from time to time. The problem is that PH is so unsecure in comparison to most other website you might login to that you can be vulnerable to man-in-the-middle and eavesdropping attacks, which can let attackers gain access to your PH account and in-turn your email and other online accounts if you use the same or similar passwords.

Please make sure your PH password is unique to PH so your chances of being hacked are reduced

NiceCupOfTea

25,298 posts

252 months

Wednesday 25th January 2017
quotequote all
Thanks for that - I had read that thread before but not got around to it. It is pretty poor and doesn't reflect well on Haymarket's opinion of the forum users.

GreigM

6,733 posts

250 months

Wednesday 25th January 2017
quotequote all
Agreed - people need to treat their PH account as a throw-away. Use a unique email address as well so as not to link it to any other accounts.

AndrewEH1

Original Poster:

4,917 posts

154 months

Wednesday 25th January 2017
quotequote all
GreigM said:
Agreed - people need to treat their PH account as a throw-away. Use a unique email address as well so as not to link it to any other accounts.
Not a bad idea using a throwaway email address!

PH/Haymarket has left the average user completely in the dark regarding the severity of this issue.

pincher

8,630 posts

218 months

Wednesday 25th January 2017
quotequote all
Can't see why you'd get a ban for that or for the thread to be deleted - all you have done is highlight a glaring vulnerability to a wider audience than would probably be normal if it was contained to Website Feedback.

In truth, it's something that PH should thanking you for in the absence of it being highlighted to their user base via an email update.

Will be interesting to see what happens to you and this thread.....

Edited by pincher on Wednesday 25th January 13:22

Europa1

10,923 posts

189 months

Wednesday 25th January 2017
quotequote all
Is this why the forums are occasionally littered with threads about cheap kitchens (usually in some sthole of a town)?

Ace-T

7,719 posts

256 months

Wednesday 25th January 2017
quotequote all
Anyone know how to change their email addy? It is greyed out on my account details and won't let me change it.

AndrewEH1

Original Poster:

4,917 posts

154 months

Wednesday 25th January 2017
quotequote all
pincher said:
In truth, it's something that PH should be highlighting to their user base themselves by a mass email update.

Will be interesting to see what happens......
They'd probably end up CCing everyone instead of BCCing...

AndrewEH1

Original Poster:

4,917 posts

154 months

Wednesday 25th January 2017
quotequote all
Ace-T said:
Anyone know how to change their email addy? It is greyed out on my account details and won't let me change it.
You'll need to contact PH directly to do that.

feef

5,206 posts

184 months

Wednesday 25th January 2017
quotequote all
pincher said:
Can't see why you'd get a ban for that or for the thread to be deleted - all you have done is highlight a glaring vulnerability to a wider audience than would probably be normal if it was contained to Website Feedback.

In truth, it's something that PH should be highlighting to their user base themselves by a mass email update.

Will be interesting to see what happens......
In the other thread, posts were deleted which demonstrated how easy it was to obtain password information. The information and methods they described are not some 0-Day exploit but common tools that many use, from security professionals and auditors right through to black-hat hackers.

That they are already willing to delete posts demonstrating the vulnerability suggests it wouldn't take a great leap to delete posts highlighting it too

pincher

8,630 posts

218 months

Wednesday 25th January 2017
quotequote all
AndrewEH1 said:
They'd probably end up CCing everyone instead of BCCing...
Surely not?!? wink

Tonsko

6,299 posts

216 months

Wednesday 25th January 2017
quotequote all
Thing is, if you changed your passwords, they would still be in the clear.. .you'd have to use a new password every time you connected to the forum!

thebraketester

14,290 posts

139 months

Wednesday 25th January 2017
quotequote all
Tonsko said:
Thing is, if you changed your passwords, they would still be in the clear.. .you'd have to use a new password every time you connected to the forum!
Correct... but if you use the same password on PH as you do for all your other online activity this becomes a problem.... hence the suggestion to use a separate PH password.

PoleDriver

28,657 posts

195 months

Wednesday 25th January 2017
quotequote all
scratchchin
So, to keep things safe we should use a unique password for PH?
And we should also use a unique email address for PH and must request PH admin to change?
idea Somebody is going to get really busy in 3...2...1...

AndrewEH1

Original Poster:

4,917 posts

154 months

Wednesday 25th January 2017
quotequote all
PoleDriver said:
scratchchin
So, to keep things safe we should use a unique password for PH?
And we should also use a unique email address for PH and must request PH admin to change?
idea Somebody is going to get really busy in 3...2...1...
That would be inconvenient...

King Herald

23,501 posts

217 months

Wednesday 25th January 2017
quotequote all
PoleDriver said:
scratchchin
So, to keep things safe we should use a unique password for PH?
And we can't change the password ourselves and must request PH admin to change?
idea Somebody is going to get really busy in 3...2...1...
I can change mine, no grey areas.

Do you want me to do yours too? biggrinbiggrin

AndrewEH1

Original Poster:

4,917 posts

154 months

Wednesday 25th January 2017
quotequote all
I'd like to make it clear that even though I only mentioned Google Chrome in the OP this security flaw will effect all users no matter what operating system, web browser or device used.

motco

16,003 posts

247 months

Wednesday 25th January 2017
quotequote all
Ace-T said:
Anyone know how to change their email addy? It is greyed out on my account details and won't let me change it.
I cannot change mine either

Funk

26,338 posts

210 months

Wednesday 25th January 2017
quotequote all
AndrewEH1 said:
Ace-T said:
Anyone know how to change their email addy? It is greyed out on my account details and won't let me change it.
You'll need to contact PH directly to do that.
I've done exactly this, changed to a masked email which isn't used anywhere else.

As a longer-term user I don't have to pay for an advert if I list something - do those that do have to pay get taken to a secure payment page or is that done through unsecured pages as well?

jeremyc

23,702 posts

285 months

Wednesday 25th January 2017
quotequote all
motco said:
Ace-T said:
Anyone know how to change their email addy? It is greyed out on my account details and won't let me change it.
I cannot change mine either
Read these instructions. readit

TOPIC CLOSED
TOPIC CLOSED