Bitcoin Forum
July 01, 2024, 08:11:48 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Secret Question Help link disabled, Why?  (Read 281 times)
logfiles (OP)
Copper Member
Legendary
*
Offline Offline

Activity: 2030
Merit: 1719


Top Crypto Casino


View Profile WWW
April 23, 2020, 06:02:30 AM
Last edit: July 19, 2023, 09:10:38 PM by logfiles
 #1

I was looking at my Account Related Settings, and I was curious about the secret question part because i have seen people get their accounts locked up in the past because of inadequate information about the feature and yet there is guide on how to avoid getting your account locked on the page.

The why is this blank? Link which i thought would provide more information is disabled for some reason.



Why was it disabled?
Shouldn't users be able to access the help information about the Secret question feature since not much is known about how it works by most members?

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
mocacinno
Legendary
*
Offline Offline

Activity: 3444
Merit: 5039


https://merel.mobi => buy facemasks with BTC/LTC


View Profile WWW
April 23, 2020, 06:07:57 AM
 #2

It has been disabled for many, many years IIRC, it was because of a vulnerability in SMF that allowed hackers to obtain a database dump with the unencrypted security questions.. So if these questions were left as they were, the hackers could have used them to attack accounts, so Theymos disabled the feature.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
rhomelmabini
Hero Member
*****
Offline Offline

Activity: 2016
Merit: 578


View Profile
April 23, 2020, 06:44:49 AM
 #3

I think it was disabled because secret question isn't a recommended security measure for the account because most of those answers there can be easily brute forced. Besides, the Support for hacked/lost accounts is the new culture here. I think that feature "secret question" needs an update or permanently delete it(?).
TheBeardedBaby
Legendary
*
Offline Offline

Activity: 2240
Merit: 3150


₿uy / $ell ..oeleo ;(


View Profile
April 23, 2020, 07:17:23 AM
Merited by hosseinimr93 (1), mole0815 (1), DdmrDdmr (1), o_e_l_e_o (1), Rizzrack (1)
 #4

It has been disabled for many, many years IIRC, it was because of a vulnerability in SMF that allowed hackers to obtain a database dump with the unencrypted security questions.. So if these questions were left as they were, the hackers could have used them to attack accounts, so Theymos disabled the feature.

The Security Queston featute is still ON!
Only the help link is disabled.
I just tested with a fresh accound and got it locked when I tried to recover it!
See below >






mocacinno
Legendary
*
Offline Offline

Activity: 3444
Merit: 5039


https://merel.mobi => buy facemasks with BTC/LTC


View Profile WWW
April 23, 2020, 07:43:59 AM
 #5

@iasenko : Apparently, my memory looks like a swiss cheese, full of holes Wink

What i was thinking about was the server compromise in 2015 where Theymos explicitly asked everybody to disable their secret questions
https://bitcointalk.org/index.php?topic=1067985.msg11445725#msg11445725

--snip--
You should disable your secret question and assume that the attacker now knows your answer to your secret question.
--snip--

However, you are 100% correct, the secret question isn't technically disabled... But using it will lead to a locked account.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
logfiles (OP)
Copper Member
Legendary
*
Offline Offline

Activity: 2030
Merit: 1719


Top Crypto Casino


View Profile WWW
April 23, 2020, 09:23:35 AM
 #6

The secret question just works fine. But whatever was in this link(why is this blank?) next to the answer box was disabled. It's what i was inquiring about.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
DdmrDdmr
Legendary
*
Offline Offline

Activity: 2366
Merit: 10869


There are lies, damned lies and statistics. MTwain


View Profile WWW
April 23, 2020, 09:29:02 AM
 #7

I assume that, if someone has the secret question in place on their profile, deleting the question itself (leaving it blank) later on, deletes the feature altogether from the profile (question and answer) with no further consequences. Is that so?
TheBeardedBaby
Legendary
*
Offline Offline

Activity: 2240
Merit: 3150


₿uy / $ell ..oeleo ;(


View Profile
April 23, 2020, 09:33:57 AM
 #8

The secret question just works fine. But whatever was in this link(why is this blank?) next to the answer box was disabled. It's what i was inquiring about.

If you see the link that it leading to the action=helpadmin;
Code:
https://bitcointalk.org/index.php?action=helpadmin;help=secret_why_blank

If you ask me the whole helpadmin modul have been disabled, that's why you get a disabled on the link.
The regular help is accessed by action=help;

SFR10
Legendary
*
Offline Offline

Activity: 3052
Merit: 3472


Crypto Swap Exchange


View Profile WWW
April 25, 2020, 07:31:29 AM
Merited by DdmrDdmr (1)
 #9

The why is this blank? Link which i thought would provide more information is disabled for some reason.
The secret question just works fine. But whatever was in this link(why is this blank?) next to the answer box was disabled. It's what i was inquiring about.
I did some digging and could only find an archived version but it also doesn't provide that much information:

For your security, the answer to your question (as well as your password) is encrypted in such a way that SMF can only tell you if get it right, so it can never tell you (or anyone else, importantly!) what your answer or password is.

I assume that, if someone has the secret question in place on their profile, deleting the question itself (leaving it blank) later on, deletes the feature altogether from the profile (question and answer) with no further consequences. Is that so?
Almost correct:

You need to delete everything on both fields (Q&A) > Enter your "Current Password" > Click "Change profile" button.
On a side note: I accidentally clicked "delete" button instead of the # of post for getting the link. Is there any way to get it restored? Cheesy

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
DdmrDdmr
Legendary
*
Offline Offline

Activity: 2366
Merit: 10869


There are lies, damned lies and statistics. MTwain


View Profile WWW
April 25, 2020, 10:23:02 AM
Merited by SFR10 (1)
 #10

<…> You need to delete everything on both fields (Q&A) > Enter your "Current Password" > Click "Change profile" button <…>
I had this step (deleting my secret question) pending for ages, and it has not been until now that I’ve gone ahead with it. Just a minor observation: Since the Answer is displayed as blank, you can’t really delete the content of the field. I therefore deleted the question, assumed that the answer deletion would be deleted, and hoped for the best. Logging out and back in again works fine, so I figure that was all that was required (+ > Enter your "Current Password" > Click "Change profile" button <…> as you stated).
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!