Cigar Asylum Cigar Forum  

Go Back   Cigar Asylum Cigar Forum > Non Cigar Specialty Forums > Misc > General Discussion

Reply
 
Thread Tools Display Modes
Old 01-24-2012, 10:28 AM   #1
jledou
Have My Own Room
 
jledou's Avatar
14
 
Join Date: Oct 2008
First Name: Jay
Location: Kansas
Posts: 2,267
Trading: (27)
Punch
jledou has a spectacular aura aboutjledou has a spectacular aura aboutjledou has a spectacular aura about
Default Re: Great Way to Start the Morning....

First step is to log into his account (if he can and reset the PW) make it something hard and I mean hard. Something like jwidl&sj24kem (you get the point). He may not like it but try it and write the password down.

if he can't log in then get in touch with AT&T and they maybe be able to reset the pw and recover control of the account.

My hotmail was hijacked twice ... the third time the pw was similar to above and remains so today ... no problems for a while now.
jledou is offline   Reply With Quote
Old 01-24-2012, 11:29 AM   #2
markem
Bunion
 
markem's Avatar
16
 
Join Date: Oct 2008
First Name: Mark
Location: Second Star on the Right
Posts: 22,669
Trading: (47)
HUpmann
markem has disabled reputation
Default Re: Great Way to Start the Morning....

I agree that all that has happened is that a password was compromised. If he had any personal information in email archives in that account, etc, well, then he may be well and truly screwed.

I agree with the idea of making the password hard and that it is okay to write it down, especially if he pretty much only uses it from home - although sticking it in your wallet behind your drivers license (or similar) is fine as well.

Don't rely on the originating IP. IP injection and email injection are trivial to do. If I was doing something like this, I'd use a Nigerian IP address just to give a nod to those who figured it out.

The important thing to figure out is how the password was compromised. Was it just a brute force attack and he was using a weak password or perhaps his computer was infected with malware and his data was harvested from there or maybe he was foolish enough to use a public use computer that wasn't secure or ... You get the idea.

Oh well, back to prepping the course I am teaching next term. A grad CS course in secure programming...

quick edit: here is an acceptable set of hints for creating passwords. Don't give much credence to the first section "Tips" but the next two sections are really good. Mnemonic devices are your friend!
http://www.cs.umd.edu/faq/Passwords.shtml
__________________
I refuse to belong to any organization that would have me as a member.
~ Groucho Marx
markem is offline   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -6. The time now is 08:13 PM.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
All content is copyrighted jointly by Cigar Asylum and the content provider.