Bitcoin Forum

Other => Meta => Topic started by: theymos on October 19, 2014, 03:49:15 AM



Title: Password reset log
Post by: theymos on October 19, 2014, 03:49:15 AM
Whenever a user changes his own password or resets his account (via email or secret question), this action is now publicly logged here for 30 days:
https://bitcointalk.org/seclog.php

Additionally, these same actions will be listed on the person's Trust page. A reset will be shown for 30 days, while a password change will be shown for 3 days.

This should make it easier to determine whether an account has been compromised.


Title: Re: Password reset log
Post by: marcotheminer on October 19, 2014, 07:18:08 AM
Thank you for taking this initiative, smart decision!


Title: Re: Password reset log
Post by: redsn0w on October 19, 2014, 09:12:26 AM
Whenever a user changes his own password or resets his account (via email or secret question), this action is now publicly logged here for 30 days:
https://bitcointalk.org/seclog.php

Additionally, these same actions will be listed on the person's Trust page. A reset will be shown for 30 days, while a password change will be shown for 3 days.

This should make it easier to determine whether an account has been compromised.
This is a great idea and  "tool" , thanks .


Title: Re: Password reset log
Post by: hilariousandco on October 19, 2014, 09:20:08 AM
Yeah, very useful. Though maybe you should change the colour of the warning This user's password was reset recently to red and make it a little larger. The yellow is hard to see, at least on my phone.


Title: Re: Password reset log
Post by: Shogen on October 19, 2014, 09:40:03 AM
Thanks for the new feature, theymos.

Yeah, very useful. Though maybe you should change the colour of the warning This user's password was reset recently to red and make it a little larger. The yellow is hard to see, at least on my phone.

The warning message is in orange for me. Did theymos change it after reading your feedback? :)


Title: Re: Password reset log
Post by: hilariousandco on October 19, 2014, 09:57:00 AM
It might have just been orange actually. It's still a bit hard to notice as the orange though.


Title: Re: Password reset log
Post by: shorena on October 19, 2014, 10:01:35 AM
https://i.imgur.com/QGOhTAz.png

Yep orange, way better than the yellow

https://i.imgur.com/XyfJPvF.png

but I also think that it should be little bigger.


Title: Re: Password reset log
Post by: PistolPete on October 19, 2014, 10:16:04 AM
Good feature.

What happens if the account is hacked but the password is deliberately not changed? There are a lot whose accounts are lying inactive so wouldn't check on it.


Title: Re: Password reset log
Post by: redsn0w on October 19, 2014, 10:20:06 AM
https://i.imgur.com/QGOhTAz.png

Yep orange, way better than the yellow

https://i.imgur.com/XyfJPvF.png

but I also think that it should be little bigger.

I think (as hilariousandco) that the write should be changed to :

This user's password was reset recently.


Title: Re: Password reset log
Post by: Muhammed Zakir on October 19, 2014, 10:41:12 AM
Thanks for this! It will be helpful! :)

https://i.imgur.com/QGOhTAz.png

Yep orange, way better than the yellow

https://i.imgur.com/XyfJPvF.png

but I also think that it should be little bigger.

I think (as hilariousandco) that the write should be changed to :

This user's password was reset recently.

Orange is okay but making the font a bit bigger would be good.

   ~~MZ~~


Title: Re: Password reset log
Post by: hilariousandco on October 19, 2014, 10:57:23 AM
Good feature.

What happens if the account is hacked but the password is deliberately not changed? There are a lot whose accounts are lying inactive so wouldn't check on it.

I don't think this is something we have to worry about. Someone isn't going to go to the trouble of hacking your account and then not change the password. If it's not changed then you still have control of the account until someone does change it. The original owner is going to notice something is amiss, and if it's an old inactive account then I don't see the big problem, but there's nothing that could be done about that anyway unless someone notices something fishy about the account.


Title: Re: Password reset log
Post by: 🏰 TradeFortress 🏰 on October 19, 2014, 11:01:10 AM
If you're investing development effort here for account security, how about implementing 2FA? I really don't understand the apparent aversion of 2FA.


Title: Re: Password reset log
Post by: Muhammed Zakir on October 19, 2014, 11:13:51 AM
If you're investing development effort here for account security, how about implementing 2FA? I really don't understand the apparent aversion of 2FA.

He said, it will be implemented in the New Forum. :)

   ~~MZ~~


Title: Re: Password reset log
Post by: 🏰 TradeFortress 🏰 on October 19, 2014, 11:22:02 AM
He said, it will be implemented in the New Forum. :)

   ~~MZ~~

Implementing TOTP 2FA is significantly more effective than implementing a password reset log.


Title: Re: Password reset log
Post by: hilariousandco on October 19, 2014, 11:44:31 AM
He said, it will be implemented in the New Forum. :)

   ~~MZ~~

Implementing TOTP 2FA is significantly more effective than implementing a password reset log.

And I imagine setting up 2F is significantly more work than implementing a simple password reset log. Shouldn't be too long for the new forum now anyway.


Title: Re: Password reset log
Post by: anujjain on October 19, 2014, 01:03:22 PM
This feature will help so much atleast for who try to hack and using for scam.


Title: Re: Password reset log
Post by: Muhammed Zakir on October 19, 2014, 04:38:20 PM
He said, it will be implemented in the New Forum. :)

   ~~MZ~~

Implementing TOTP 2FA is significantly more effective than implementing a password reset log.

And I imagine setting up 2F is significantly more work than implementing a simple password reset log. Shouldn't be too long for the new forum now anyway.

I would like to have bitcoin 2FA too though an option to choose Google Authenticator and BTC 2FA would be good. Suggestions are welcome! :)

we should use bitcoin related 2FA

https://github.com/nanotube/supybot-bitcoin-marketmonitor/blob/master/GPG/local/bitcoinsig.py

easy to implement and only requires storing public bitcoin addresses.

   ~~MZ~~


Title: Re: Password reset log
Post by: santaClause on October 19, 2014, 05:10:40 PM
Whenever a user changes his own password or resets his account (via email or secret question), this action is now publicly logged here for 30 days:
https://bitcointalk.org/seclog.php

Additionally, these same actions will be listed on the person's Trust page. A reset will be shown for 30 days, while a password change will be shown for 3 days.

This should make it easier to determine whether an account has been compromised.
Would it be possible to not disclose how a password is reset (email verses secret question). If this is disclosed then the fact that someone has a secret question which would make their account more vulnerable to getting hacked. Removing the disclosure of what method was used to to reset a password would remove this vulnerability.


Title: Re: Password reset log
Post by: BombaUcigasa on October 19, 2014, 06:51:39 PM
Whenever a user changes his own password or resets his account (via email or secret question), this action is now publicly logged here for 30 days:
https://bitcointalk.org/seclog.php

Additionally, these same actions will be listed on the person's Trust page. A reset will be shown for 30 days, while a password change will be shown for 3 days.

This should make it easier to determine whether an account has been compromised.
OMG, thanks theymos, we can finally change our ava..... oh...

Good implementation idea...


Title: Re: Password reset log
Post by: greatwolf_ on October 19, 2014, 07:14:41 PM

And I imagine setting up 2F is significantly more work than implementing a simple password reset log. Shouldn't be too long for the new forum now anyway.

You mean the new forum that's supposedly in the works since jan 2013? Frankly, I don't understand why there's a need to design a completely new forum software from scratch when there are many off-the-shelve open-source choices available. It would save so much time going with one of them that closely fits the requirements and just customize and mod it to fit our purposes.

PS. I'm still waiting for a reply to my PM on my hacked account btw.


Title: Re: Password reset log
Post by: Raize on October 20, 2014, 03:07:26 PM
Implementing TOTP 2FA is significantly more effective than implementing a password reset log.

It's also significantly more difficult. SMF's password-handling and use is, to put it simply, horrible. It's better to just have the new forum designed from the ground up to use 2FA than to even attempt to hack it into SMF. I can't speak for theymos, but I'd be terrified to try to hack up a 2FA for SMF given the little I already know of its code and especially the anti-XSS part of it.

I just recently changed my password and I think I agree with the others, it should be a bigger font and maybe even RED and bolded. It might help cut down significantly on the "oh, I got hacked!" scams. Of course, it's going to have to require that a lot of folks actively refuse to do business with people who have changed their password or reset their account recently.


Title: Re: Password reset log
Post by: Salmon1989 on October 21, 2014, 06:30:28 AM

And I imagine setting up 2F is significantly more work than implementing a simple password reset log. Shouldn't be too long for the new forum now anyway.

You mean the new forum that's supposedly in the works since jan 2013? Frankly, I don't understand why there's a need to design a completely new forum software from scratch when there are many off-the-shelve open-source choices available. It would save so much time going with one of them that closely fits the requirements and just customize and mod it to fit our purposes.

The following is what theymos said 8 months ago about the new forum software.

Quote
Why do you think we needed to spend so much for software when there are free or much cheaper option available?

The most popular forum software is:
- Old.
- Written in PHP, which sucks.
- Written insecurely and messily.
- Difficult to modify, especially safely.
- Not much more featureful than SMF, if at all.

There are a handful of newer forum software packages which solve some of those problems, but all of them are very sparse in features.

The goal of this software project is to create new, open source forum software which will compete with SMF, phpBB, etc.

Quote
What special features will the forum have?

This isn't completely defined yet. It'll have almost all features that we have now. A main goal will be improving filtering and data presentation so that users can more easily manage the flood of posts both board-wide and within threads, while simultaneously reducing the need for centralized moderation.


Title: Re: Password reset log
Post by: theymos on October 25, 2014, 11:46:36 PM
I added color-coding to the usernames in this log. That'll make it easier to pick out more valuable accounts from the list. The colors are the same as the colors on Who's Online (https://bitcointalk.org/index.php?action=who):
- Admins = red
- Global mods = dark blue
- Donators = green
- VIPs = violet
- Staff = pink
- Regular users are various shades of grey, getting darker with seniority.
- Legendary = lightish blue

Also, I made the "reset recently" text darker and larger.


Title: Re: Password reset log
Post by: Muhammed Zakir on October 26, 2014, 04:26:34 AM
I added color-coding to the usernames in this log. That'll make it easier to pick out more valuable accounts from the list. The colors are the same as the colors on Who's Online (https://bitcointalk.org/index.php?action=who):
- Admins = red
- Global mods = dark blue
- Donators = green
- VIPs = violet
- Staff = pink
- Regular users are various shades of grey, getting darker with seniority.
- Legendary = lightish blue

Also, I made the "reset recently" text darker and larger.

Thanks! Now it is better.

Off-topic: It would be good if you make a total no. of logged in users and total no. of guests in a small box or something like that in Who's Online (https://bitcointalk.org/index.php?action=who).

   ~~MZ~~


Title: Re: Password reset log
Post by: --Encrypted-- on June 18, 2015, 11:03:03 PM
sorry for bumping an old topic, but I have just noticed something a little strange while I was wandering around.

KWH's trust page (https://bitcointalk.org/index.php?action=trust;u=70535) shows the "This user's password was reset recently." notice, but according to seclog (https://bitcointalk.org/seclog.php), his password hasn't been changed since May 25th. and I compared him with some other members that had changed their password on that day, but I don't see anything like this.

which one is correct?

for additional info, I noticed that before this appeared on the seclog. "10:36:25 PM - DooMAD - password changed"


Title: Re: Password reset log
Post by: Muhammed Zakir on June 19, 2015, 05:26:01 AM
sorry for bumping an old topic, but I have just noticed something a little strange while I was wandering around.

KWH's trust page (https://bitcointalk.org/index.php?action=trust;u=70535) shows the "This user's password was reset recently." notice, but according to seclog (https://bitcointalk.org/seclog.php), his password hasn't been changed since May 25th. and I compared him with some other members that had changed their password on that day, but I don't see anything like this.

which one is correct?

for additional info, I noticed that before this appeared on the seclog. "10:36:25 PM - DooMAD - password changed"

KWH resetted his password via email. It will be shown till June 25.

-snip-
Additionally, these same actions will be listed on the person's Trust page. A reset will be shown for 30 days, while a password change will be shown for 3 days.
 -snip


Title: Re: Password reset log
Post by: yogg on December 10, 2017, 12:07:07 AM
Sorry for bumping an old thread...

Is there any way to check the seclog archives for between 2015 and 2017 ? Yeah, I know it's 24 months and it keeps only the last 30 days...  ;D

I tried webarchive but it didn't keep track of everything. :-\