• Member Since 23rd Nov, 2024
  • offline last seen Last Tuesday

xeqciel


xeqciel

More Blog Posts1

  • 17 weeks
    About Online Security

    Hello,

    My FimFiction account was very recently accessed without my knowledge and promptly deleted. Fortunately, I did not have any important data on there, so no real harm was done. What surprised me, however, is that the password I picked was 14 characters long, and included special symbols.

    Read More

    3 comments · 31 views
Nov
24th
2024

About Online Security · 12:24am Nov 24th, 2024

Hello,

My FimFiction account was very recently accessed without my knowledge and promptly deleted. Fortunately, I did not have any important data on there, so no real harm was done. What surprised me, however, is that the password I picked was 14 characters long, and included special symbols.

Nevertheless, I consider myself lucky. This breach of security could have affected a more important account, and caused a lot of problems. This is in part why I'm writing this blog post : to anypony reading, it would be wise to take a day and secure important accounts using an encrypted database, with TOTP (timed one-time password) support. Revise your old, probably weak, passwords.

You'll thank yourself later.

~xeqciel

Report xeqciel · 31 views ·
Comments ( 3 )

Or perhaps pick and choose what you subscribe to. I have a username and password on maybe ten sites and only critical sites get unique usernames and passwords. None of my accounts have been hacked although Discord has had frequent attempts. I can't use Discord anyway so I don't care. It's just a chat interface, it's not worth all the security hoops Discord devs demand. TOTP is one rabbit hole I wouldn't want to bury all my passwords in.

5817720
While I don't consider sites like Fimfiction critical, it's nonetheless a hassle to have to remake an account and losing all your libraries, mails, and such. Limiting what services I make an account on is beside the point.

What I like about TOTP is that it's entirely local from the moment you set it up, as they're based on a universal clock. Of course, since the likelihood of guessing one TOTP at any moment never changes, its unsafe to rely solely on it to login; as the name suggests, it is the second factor in authentication.

For low-priority subscriptions, I always have a common "pattern" for all my passwords, combined with some hash of the site name itself (from a random function I made), hashed with the current year. Plus TOTP.

While all those precautions appeal to my suspicious nature, I have yet to have an account hacked or to get phished in a compelling way. Yes, starting a new account from scratch would be annoying, but until that happens, I prefer to keep track of my credentials using less script-dependent techniques. ^_^ (That said, I really ought to do another backup copy of my files.)

Login or register to comment