New Security Measures

Blog Discussion in 'BeerAdvocate Talk' started by Todd, Jul 17, 2020.

Thread Status:
Not open for further replies.
  1. MikefromDormont

    MikefromDormont Zealot (682) Dec 11, 2004 Pennsylvania
    BA4LYFE Society

    That happened to me so I logged out and had BeerAdvocate email me a password reset link when I tried to log back in.
     
  2. jts211

    jts211 Savant (1,109) Aug 5, 2018 Pennsylvania
    Trader

    luckily, I was able to reset my password through the existing email address After a password reset, seem to be fine now.

    Jeremy
     
    Todd likes this.
  3. CSO

    CSO Savant (1,134) Jan 31, 2014 Illinois
    Trader

    How did the system send a reset link to an email address that is no longer valid? Did you contact BA directly with your new email address?
     
  4. Todd

    Todd Founder (13,518) Aug 23, 1996 Finland
    STAFF Mod Team Society Pooh-Bah

    Drop me a DM. I can help right now.
     
    sulldaddy and BBThunderbolt like this.
  5. russpowell

    russpowell Grand High Pooh-Bah (8,292) May 24, 2005 Arkansas
    BA4LYFE Society Pooh-Bah Trader

    My only problem is I have God know how many passwords & the only real way I can keep up with them is to violate security on another device/level. At at least I no longer sweat the UCMJ piece. My mind was sharp enough to keep up with all that THEN
     
  6. MNAle

    MNAle Initiate (0) Sep 6, 2011 Minnesota

    There's an app for that! :wink:
     
    Palantir3 and officerbill like this.
  7. russpowell

    russpowell Grand High Pooh-Bah (8,292) May 24, 2005 Arkansas
    BA4LYFE Society Pooh-Bah Trader

    I'd find a way to F that up
     
  8. cid71

    cid71 Zealot (614) Mar 2, 2009 New Jersey
    Trader

    A followup to this question. So we can change our passwords elsewhere but someone has had our passwords for 8 years ? Just trying to understand thank you
     
    hopley, neenerzig and DEdesings57 like this.
  9. jvgoor3786

    jvgoor3786 Grand Pooh-Bah (4,222) May 28, 2015 Arkansas
    Society Pooh-Bah Trader

    I hear you. I keep all my non-work related passwords on LastPass.
     
  10. mactrail

    mactrail Grand High Pooh-Bah (8,999) Mar 24, 2009 Washington
    Mod Team BA4LYFE Society Pooh-Bah Trader

    You have to check the box that you have read the Privacy Policy and Terms of Service, but I did not see a link to either of them.
     
  11. Todd

    Todd Founder (13,518) Aug 23, 1996 Finland
    STAFF Mod Team Society Pooh-Bah

    The text to the right of the checkbox is linked.
     
  12. mactrail

    mactrail Grand High Pooh-Bah (8,999) Mar 24, 2009 Washington
    Mod Team BA4LYFE Society Pooh-Bah Trader

    Or, not knowing where that original page was, I see you can scroll down to the bottom of any page and there they are. Thanks for helping us deal with this stuff.
     
    Todd likes this.
  13. EmperorBatman

    EmperorBatman Zealot (741) Mar 16, 2018 Tennessee

    I made my account fairly well after the data breach in 2012-2013, and I joined I think either late 2017 or early 2018. Am I still at risk?
     
  14. ZPrime

    ZPrime Initiate (188) Jul 14, 2010 Ohio

    SMS (text message) 2FA is insecure as all hell. There are multiple ways to "steal" a phone number and then intercept the SMS. Amazon, Google, and many other places offer superior forms of 2FA (authenticator app). Sadly, many many financial institutions are really slow to get on this train, which is awful since they are the places I most want 2FA. (I really don't care about random forums, I just use long generated passwords that look like line noise...)

    LastPass, or even better, BitWarden, both have free options for password storage.
    For 2FA generators, Authy is fantastic (and you can use it from multiple devices, like your phone and your tablet and even a computer if you don't mind that small compromise in security).
     
  15. TheGent

    TheGent Grand Pooh-Bah (4,235) Jun 29, 2010 New Jersey
    Pooh-Bah Trader

    When you say that you “recently” became aware of the breach that began approximately 8 years ago how recent are you talking? When you became aware of the breach and when you disclosed it to users matters.

    Also, what’s the name of the third party cyber security firm you used to investigate the breach so we know they’re reputable?
     
    duceswild, hopley and TheDoctor like this.
  16. Snowcrash000

    Snowcrash000 Grand High Pooh-Bah (6,041) Oct 4, 2017 Germany
    Mod Team Society Pooh-Bah Trader

    In the Help Resources, under "How to Secure Your Account", there is a link to your account settings titled "Change Your Password (Logged In Users)". This option is bound to create confusion for anyone dealing with this forced reset as it requires putting in the current password, which does not exist anymore. To avoid confusion, I would suggest adding this note to the OP here, beween the second and third bullet point at the top:

    "It is not possible to change your password from your account settings unless you first reset your password using the above link."

    https://www.beeradvocate.com/community/threads/how-to-secure-your-account.643532/
    https://www.beeradvocate.com/community/account/security
     
  17. jmcdzzz

    jmcdzzz Initiate (0) Mar 15, 2010 Michigan

    Best practice for a breach of this stuff type is to force a password reset. Although it's nice to think that they only have the users in mind, they also also have to think of what may have been compromised beyond that. They have to protect themselves and the easiest way is to cut off access to everyone and force them to re-authenticate
     
    officerbill and jvgoor3786 like this.
  18. SILVER

    SILVER Zealot (668) Jan 3, 2007 Florida

    Done did it!
    I think.................
     
  19. bbtkd

    bbtkd Grand High Pooh-Bah (7,790) Sep 20, 2015 South Dakota
    BA4LYFE Society Pooh-Bah Trader

    2FA would be overkill, please don't. Some will find that too much of a hassle and leave if they have to sign-in much. Same thing for timing out passwords - the latest security best practices say not to time them out, or at least make it a couple of years. Timing out often increases the chances that folks will write them down or use the same password everywhere. Just force some basic complexity (8+characters, one special character, one number, one upper-case). We're not doing our banking here.
     
    PapaGoose03 likes this.
  20. Longhorn08

    Longhorn08 Savant (1,109) Feb 4, 2014 Texas
    Trader

    what if we no longer use the email address we used to create our account?
     
Thread Status:
Not open for further replies.