Beefy Boxes and Bandwidth Generously Provided by pair Networks
Welcome to the Monastery
 
PerlMonks  

Re: Making assessments

by mje (Curate)
on Oct 08, 2009 at 12:55 UTC ( [id://799951]=note: print w/replies, xml ) Need Help??


in reply to Making assessments

I'd like to know our gut feelings

I've noticed no real differences I can put my finger on but of course that is not to say there aren't any. I was caught out a long time ago using the same password at multiple places and learned my lesson then so my perl monks password was not used elsewhere. As a result, the worst thing that could have happened (had my password been outed as it appears it was for some) is that someone could have logged into perl monks and pretended to be me . I have difficulty in imagining that could have caused any real long term harm that could not have been put right (as a mere Pilgrim I didn't have much to lose anyway).

The fact that the password is still 8 characters and may or may not be disguised/hashed whatever in the database still to this day does not overly concern me other than what the world outside might think about it.

The "Users, please read the following important update: Status of Recent User Information Leak" message seems to have been on the monastery gates for a long time now and I wonder if that might put some people off joining. As far as I can see it serves little purpose for any anonymous visitors and in any case a) how many signed up members start at the monastery gates b) often you cannot see the message because a front paged article is formatted such it is off the right of the screen.

"did the exploit change the behavior of monks in any way?"

I'd guess most changed their password to something they do not use elsewhere ;-)

Replies are listed 'Best First'.
Re^2: Making assessments
by markuhs (Scribe) on Oct 08, 2009 at 16:51 UTC
    I'm quite new here, so my password was not made public...
    The "Users, please read the following important update: Status of Recent User Information Leak" message seems to have been on the monastery gates for a long time now and I wonder if that might put some people off joining. As far as I can see it serves little purpose for any anonymous visitors
    I would agree with mje, that it is a bit confusing for new users. It was for me.

    But, it is fair! I read it and decided to join. Everybody makes mistakes, but the way things are communicated makes me confident, that this error has been taken care of seriously. And God willing it will not happen again...

    So leave it or take it away, I assume both will attract some and repel others.

    Lukas

Log In?
Username:
Password:

What's my password?
Create A New User
Domain Nodelet?
Node Status?
node history
Node Type: note [id://799951]
help
Chatterbox?
and the web crawler heard nothing...

How do I use this?Last hourOther CB clients
Other Users?
Others musing on the Monastery: (3)
As of 2024-04-19 06:07 GMT
Sections?
Information?
Find Nodes?
Leftovers?
    Voting Booth?

    No recent polls found