forum

Password Change Request [important]

posted
Total Posts
60
Topic Starter
peppy
Hi again (it seems like only yesterday that I last posted an announcement!). This is a request to everyone to please change your password. Any accounts that don't have their password changed within a couple of weeks will be temporarily deactivated (requiring email reactivation). You can do this easily here. I suggest you make it at least 8 characters if possible. Read on for the reasoning behind this.

Recently there was a brute-force attack on many users' accounts, which was in turn used to negatively affect the rating of a beatmap. This was corrected quickly afterwards, but it remains true that many of your accounts are currently vulnerable due to a someone farming account passwords. If your password was quite secure (not a common dictionary word) then it is likely you are safe.

I have taken measures to ensure this doesn't happen again, so once you change your password you can relax. I realise this should have probably been in place from the beginning, but unfortunately was overlooked (sorry).

Thanks for your time!

peppy out

tldr version: CHANGE YOUR PASSWORD HERE PLEASE (especially if it was 'password' or 'abc123' etc.)

edit: if you want to keep your current password and you believe it is secure enough, change it to something else then back again, please.
anonymous_old
I'm eager for someone from #osu to log in as me.
[Sean]
I've been meaning to change my password...
jericho2442
kk ive changed mine and will pass the word onto ppl i kno over this too ;)
Aoitenshi
Good one peppy, Now I have no clue my next password. But yeah, this is for the best.

Time to help a bit.

Use something like '153ELaIsMolSm' as password, if you can remember, use several capital letters. Signature number is great too, like my 053 in Ain053, It's certainly not because Ain052 won't work. Just pick your favorite number (Preferably 3 Digit like 423), EXCEPT, 13 and 666 as they are known as Devil's number and IS quite popular. Don't put your username or something familiar or related as password, they are just easier to guess.
Galkan
I have already changed my password yesterday (and it's hard to guess), must I change it again to avoid deactivation? Just want to know.
Derekku

Galkan92 wrote:

I have already changed my password yesterday (and it's hard to guess), must I change it again to avoid deactivation? Just want to know.

peppy wrote:

if you want to keep your current password and you believe it is secure enough, change it to something else then back again, please.
Galkan
Whoops, I didn't notice the edit.
vivere
Changing password O.O

Edit: Uppercase, lowercase and numbers! Buahahahaha
arien666
Noticed on Korean forum anyway :3

Also, changed pw :3
Waryas
Sigh.
Changed.
qlum
no need to change for me 14 random letters and numbers is secure enough for me
anonymous_old

Ain053 wrote:

Good one peppy, Now I have no clue my next password. But yeah, this is for the best.

Time to help a bit.

Use something like '153ELaIsMolSm' as password, if you can remember, use several capital letters. Signature number is great too, like my 053 in Ain053, It's certainly not because Ain052 won't work. Just pick your favorite number (Preferably 3 Digit like 423), EXCEPT, 13 and 666 as they are known as Devil's number and IS quite popular. Don't put your username or something familiar or related as password, they are just easier to guess.
A better suggestion:

Make your password a piece of text. It could be some quote from literature, lyrics from a song, or dialog from a movie. As long as it's not "never gonna give you up" or something else which is easily guessable (though Rick Rolling hackers does sound like fun).

The only problems with using passphrases are that some sites limit the number of characters in your password and sometimes the chosen text is in a dictionary or is easy to brute force.

If you're really paranoid, throw in some numbers and punctuation or use  .

(As if this information matters.)
Vanmonky

qlum wrote:

no need to change for me 14 random letters and numbers is secure enough for me

peppy wrote:

if you want to keep your current password and you believe it is secure enough, change it to something else then back again, please.
Vanmonky

strager wrote:

Ain053 wrote:

Good one peppy, Now I have no clue my next password. But yeah, this is for the best.

Time to help a bit.

Use something like '153ELaIsMolSm' as password, if you can remember, use several capital letters. Signature number is great too, like my 053 in Ain053, It's certainly not because Ain052 won't work. Just pick your favorite number (Preferably 3 Digit like 423), EXCEPT, 13 and 666 as they are known as Devil's number and IS quite popular. Don't put your username or something familiar or related as password, they are just easier to guess.
A better suggestion:

Make your password a piece of text. It could be some quote from literature, lyrics from a song, or dialog from a movie. As long as it's not "never gonna give you up" or something else which is easily guessable (though Rick Rolling hackers does sound like fun).

The only problems with using passphrases are that some sites limit the number of characters in your password and sometimes the chosen text is in a dictionary or is easy to brute force.

If you're really paranoid, throw in some numbers and punctuation or use  .

(As if this information matters.)
Just a side note. If you want the strongest password you ever had, use definitely [b]12 characters[/] of lowercase, uppercase, and numbers. I once read an article about this. Password which consist of 12 characters is hard to be hacked by some of hacker's application.
nonoh_old

VanMoNky wrote:

I once read an article about this. Password which consist of 12 characters is hard to be hacked by some of hacker's application.
Good to know, my password just happens to be 12 characters :9

well it was before I changed it for this.
wmfchris
Everyone should change the password since this is good for this game ._<

BTW here is a strong password generator for those who're lazy to think of your new password~
http://strongpasswordgenerator.com/


For myself I think 30-digit prime with half of them being random stuffs inside it would be secure enough orz
Shael_old
My password was safe but I'll change it anyway ^^
Orkel
changed.
Sakura
I was thinking of changing my password sometime soon anyways, thanks for warning us peppy, i changed my password
Verdisphena
Changed ~~
FurukawaPan
pass changed.

Is there any way to check if my account was accessed by someone other than myself during the vulnerable time? a login history view or something that shows IP?
Esupanitix
Brb changing password; but besides when I get unbanned, who would want to log in as me and wh- okay now I see.

Not using StrongPasswordGenerator.com, because the password is too damn long for me to remember. Especially if it's eighteen characters. >_<
Powerdrone
Weegee you so silly.

I always have my browser remember my osu! password. =P
crystalsuicune

Powerdrone wrote:

Weegee you so silly.

I always have my browser remember my osu! password. =P
What about public computers?You can't use cookies with those.

BTW,changed my password yesterday.
Powerdrone

crystalsuicune wrote:

Powerdrone wrote:

Weegee you so silly.

I always have my browser remember my osu! password. =P
What about public computers?You can't use cookies with those.

BTW,changed my password yesterday.
I remember my password, duh. I just have it saved on my browser so I don't have to type it in all the time.
Pokebis
And you can take a USB key with you or sync something, but that's kind of unsafe.
On that note, though, who would log onto the osu! forums on a public computer? I sure wouldn't.
ekopret8ks
The sequence of events before the osu! website crashes.

Just kidding, Good job peppy
K2J

Pokebis wrote:

On that note, though, who would log onto the osu! forums on a public computer? I sure wouldn't.
Why not? Afraid of copyright disputes? The sheer pinkness in public? Sure, you don't have a client, but that doesn't mean you can't check up on maps you're following / making.
Jarby

K2J wrote:

Pokebis wrote:

On that note, though, who would log onto the osu! forums on a public computer? I sure wouldn't.
Why not? Afraid of copyright disputes? The sheer pinkness in public? Sure, you don't have a client, but that doesn't mean you can't check up on maps you're following / making.
I'd personally find it a nuisance to have to change my password when I get home which seems like a reasonable thing to do after logging on to the forum on a public computer.
Azure_Kite
Or you could, you know. Make sure it doesn't save your password by not checking the save box, and log out when you leave.
Jarby

Azure_Kyte wrote:

Or you could, you know. Make sure it doesn't save your password by not checking the save box, and log out when you leave.
I don't trust those filthy computers and their monstrous spyware! I guess.
Aoitenshi

Jarby wrote:

Azure_Kyte wrote:

Or you could, you know. Make sure it doesn't save your password by not checking the save box, and log out when you leave.
I don't trust those filthy computers and their monstrous spyware! I guess.
I rather use 2nd ID to log in.

SPOILER
YEAH LIKE IT'S ALLOWED TO CREATE 2ND ID IN OSU
K2J
Ah, I see. As a university student, my perception of "public" means "log in using your student ID", so there's an extra layer of security that makes me not too worried.
awp

peppy wrote:

edit: if you want to keep your current password and you believe it is secure enough, change it to something else then back again, please.
This is just general curiosity, but: what does the above accomplish?
Gabi
Avoiding getting your account deactivated probably
Topic Starter
peppy

Gabi wrote:

Avoiding getting your account deactivated probably
Nice deduction work!
Azure_Kite
I giggled.
Hamuko

vivere wrote:

Changing password O.O

Edit: Uppercase, lowercase and numbers! Buahahahaha
mine is numbers, Upper and lower and upper and numbers and lower and upper and lower and numbers.
Numbbi
I guess changing password is a must now. :c

Don't want to get deactivated.
Hyguys
My password is reeaaaaallly secure :3
eru
question over here

peppy wrote:

Any accounts that don't have their password changed within a couple of weeks will be temporarily deactivated (requiring email reactivation)
if they still don't change their password within months, will they get permanently deactivated?
Ephemeral
the only accounts that ever get permanently deactivated are the ones that are used for cheating in some fashion or another

i don't think there's ever been an inactivity purge and i doubt there ever will be
Zetta
Pass is all changed and I'm glad peppy added the password protection to the forums too.

So if you type your password on any post it comes up as *'s

*******

See, :D
FurukawaPan

Zetta wrote:

Pass is all changed and I'm glad peppy added the password protection to the forums too.

So if you type your password on any post it comes up as *'s

*******

See, :D
Somehow I'm not feeling the temptation to test that out.
Mara

Zetta wrote:

Pass is all changed and I'm glad peppy added the password protection to the forums too.

So if you type your password on any post it comes up as *'s

*******

See, :D
That password is kinda weak, you know...
KcLKcL
Okay, just changed by password :)
bagnz0r
I'm not changing mine, it's strong enough for brute-force to take 5 centuries.
And I don't feel like remembering another one complicated password.
James2250

bagnz0r wrote:

I'm not changing mine, it's strong enough for brute-force to take 5 centuries.
And I don't feel like remembering another one complicated password.
Then don't forget about

peppy wrote:

edit: if you want to keep your current password and you believe it is secure enough, change it to something else then back again, please.
:D
Galkan

James2250 wrote:

Then don't forget about

peppy wrote:

edit: if you want to keep your current password and you believe it is secure enough, change it to something else then back again, please.
:D
He meant he's not changing to OTHER psw and he stays with this one he's got by now.
show more
Please sign in to reply.

New reply