Twilight Forums

Idle chat for wannabe heroes
It is currently Sun May 19, 2013 3:45 pm

All times are UTC - 7 hours




Post new topic Reply to topic  [ 15 posts ] 
Author Message
 Post subject: What are the chances?
PostPosted: Tue Sep 25, 2007 10:32 am 
Offline
User avatar

Joined: Sun Apr 08, 2007 5:00 pm
Posts: 265
Location: Thessaloniki - Greece
My password for the TH forums is 8 digits long, containg numbers and letters, 'randomly' (as in through a proccess that helps me remeber it but has no logic for anyone else) selected.

There are 24 letters and 10 numbers, meaning that all combinations containing only letters and numbers, and are 8 digits long, are 1,785,793,904,896. My password, is one combination among all those. Note, that the chance of winning the UK national lottery JACKPOT is roughly 2 million times more probable than guessing my password.

Why all this analysis? Yesterday night, I saw a film, where a character receives a letter, and the receiving address had my password on it.

EDIT: Actually, I checked it again, and it has all the digits at the right order, excluding the 4th digit of my password that is missing on the letter.

_________________
Image


Top
 Profile  
 
 Post subject:
PostPosted: Tue Sep 25, 2007 3:17 pm 
Offline
User avatar

Joined: Thu Sep 06, 2007 10:56 pm
Posts: 1466
Location: Berkeley when at school, San Diego when at home
That's awesome.

It's like that guy who thinks Google is trying to make him miserable. It's a 5 billion $ case right now. :D


Top
 Profile  
 
 Post subject:
PostPosted: Tue Sep 25, 2007 8:42 pm 
Offline
User avatar

Joined: Sun Sep 09, 2007 12:41 am
Posts: 424
If and when you change your password, will you let us know the name of the film?


Top
 Profile  
 
 Post subject:
PostPosted: Tue Sep 25, 2007 8:50 pm 
Offline
User avatar

Joined: Sun Apr 08, 2007 5:00 pm
Posts: 265
Location: Thessaloniki - Greece
Quote:
That's awesome.

It's like that guy who thinks Google is trying to make him miserable. It's a 5 billion $ case right now.


I didn't know about this story until you intrigued me to esearch. Yikes! In its turn, this story reminded me of the guy who sued coca-cola because a can he opened did not *fizzle* resulting in "emotional pain" Oo

Jesus wrote:
If and when you change your password, will you let us know the name of the film?


I thought of that very seriously, considering that this fact brought me a sense of unsafety, but there comes a simple problem: I am extremely bad at memorizing, meaning that I do use only four passwords by memory, all of them distributed among everything I do. Considering that the one on the film is my *main* password, that one I use the most often, I am quite reluctant to just give it up.

_________________
Image


Last edited by Devant on Tue Sep 25, 2007 8:54 pm, edited 1 time in total.

Top
 Profile  
 
 Post subject:
PostPosted: Tue Sep 25, 2007 8:50 pm 
Offline
Site Admin
User avatar

Joined: Thu Apr 05, 2007 2:04 pm
Posts: 4192
Was the password "p@ssword"?


Top
 Profile  
 
 Post subject:
PostPosted: Tue Sep 25, 2007 8:53 pm 
Offline
User avatar

Joined: Sun Apr 08, 2007 5:00 pm
Posts: 265
Location: Thessaloniki - Greece
Ryme wrote:
Was the password "p@ssword"?


Nope :D I am not that simplistic...:P In case *you* really want to know it, I suppose you can check my IG password for Devant... it's the same... I suppose I can trust you ;).

_________________
Image


Top
 Profile  
 
 Post subject:
PostPosted: Tue Sep 25, 2007 8:58 pm 
Offline
Site Admin
User avatar

Joined: Thu Apr 05, 2007 2:04 pm
Posts: 4192
Not that simplistic? You could have fooled me! :P

All the password stuff for the game is stored encrypted, so I don't know what anybody's is. I figure it's safer that way. Or at least it's the honorable thing to do, right?


Top
 Profile  
 
 Post subject:
PostPosted: Tue Sep 25, 2007 9:03 pm 
Offline
User avatar

Joined: Sun Apr 08, 2007 5:00 pm
Posts: 265
Location: Thessaloniki - Greece
Ryme wrote:
Not that simplistic? You could have fooled me! :P


Gotcha! :P

Ryme wrote:
All the password stuff for the game is stored encrypted, so I don't know what anybody's is. I figure it's safer that way. Or at least it's the honorable thing to do, right?


Very wise of you ;). I was wondering if you use actual encryption or hashing... You know, the former puts ideas in people's minds...

Indeed, considering that you could just call it "my site, my rules" and get away with that little concience thingy, it's trully honorable ;).

EDIT: How the heck is "consience" or whatever written? Oo

_________________
Image


Top
 Profile  
 
 Post subject:
PostPosted: Tue Sep 25, 2007 9:40 pm 
Offline
User avatar

Joined: Sun Apr 08, 2007 1:01 am
Posts: 4228
Location: the Conservatory with the lead pipe
Stored in a hash but able to be edited by an admin, I would assume? Or are you totally unable to touch them?

Or should I stop prying on this sort of thing :wink:

_________________
Image
The churches are empty / The priest has gone home / And we are left standing / Together alone
--October Project: "Dark Time"


Top
 Profile  
 
 Post subject:
PostPosted: Tue Sep 25, 2007 9:43 pm 
Offline
Site Admin
User avatar

Joined: Thu Apr 05, 2007 2:04 pm
Posts: 4192
Conscience.

I'm just hashing the passwords, but that seemed to obscure the data enough for the purposes of a game site. Besides, why bother stealing the passwords outright when the keylogger that Twilight installs will get me credit cards and bank accounts, too? :lol:

Someday, I'm probably going to regret saying that. Someone's going to take it seriously and tell their parents I'm stealing things from their computers, and I'll end up in jail. Sheesh.


Top
 Profile  
 
 Post subject:
PostPosted: Tue Sep 25, 2007 9:46 pm 
Offline
Site Admin
User avatar

Joined: Thu Apr 05, 2007 2:04 pm
Posts: 4192
Cristiona wrote:
Stored in a hash but able to be edited by an admin, I would assume? Or are you totally unable to touch them?


As it's in a database, I can of course edit the password, in that I can delete them entirely or put anything else I want into that field. I don't know of any way to convert/extract the current one from the hashed result, but on a couple of occasions when people lost their password I did insert a temporary one for them until they could log in and change it back. For the most part, though, I discourage the losing of passwords because it's a total pain for me, and if I don't know you well enough to trust you I might not feel confident in resetting it.


Top
 Profile  
 
 Post subject:
PostPosted: Tue Sep 25, 2007 9:51 pm 
Offline
User avatar

Joined: Sun Apr 08, 2007 1:01 am
Posts: 4228
Location: the Conservatory with the lead pipe
That's kinda what I figured. For what it's worth, I think there are some tools that can extract a password from a hash, but they're pretty limited (I believe they need to be 'trained', and of course, you need access to the hashes), and I think they don't work over a certain length (as hashes tend to be of a set length, even when the pw is longer than the hash).


Anyway, what you might consider for lost passwords is having an automated system that creates a new password (ie: 4 random numbers and a random letter) to the associated e-mail.

_________________
Image
The churches are empty / The priest has gone home / And we are left standing / Together alone
--October Project: "Dark Time"


Top
 Profile  
 
 Post subject:
PostPosted: Tue Sep 25, 2007 10:00 pm 
Offline
Site Admin
User avatar

Joined: Thu Apr 05, 2007 2:04 pm
Posts: 4192
Cristiona wrote:
Anyway, what you might consider for lost passwords is having an automated system that creates a new password (ie: 4 random numbers and a random letter) to the associated e-mail.


Yeah, I know. I've been mostly neglecting administrative stuff like that. I'm sure about two weeks of beta will make me clean it up, what with all the rapscallionish newbies.


Top
 Profile  
 
 Post subject:
PostPosted: Mon Oct 01, 2007 1:07 am 
Offline

Joined: Sun Apr 22, 2007 6:29 am
Posts: 10
Ryme wrote:
For the most part, though, I discourage the losing of passwords because it's a total pain for me, and if I don't know you well enough to trust you I might not feel confident in resetting it.

Hey, I lost my password, could you reset it and send it to me? Account name is 'Ryme'... :lol:


Top
 Profile  
 
 Post subject:
PostPosted: Mon Oct 01, 2007 6:21 am 
Offline
Site Admin
User avatar

Joined: Thu Apr 05, 2007 2:04 pm
Posts: 4192
Ryme? Oh, yeah, I totally know you. But then again, I also know where you keep your password. So why don't I just retrieve it and hand it over to you personally?


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 15 posts ] 

All times are UTC - 7 hours


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group