Help support TMP


"Have often should you change your TMP password?" Topic


19 Posts

All members in good standing are free to post here. Opinions expressed here are solely those of the posters, and have not been cleared with nor are they endorsed by The Miniatures Page.

Please use the Complaint button (!) to report problems on the forums.

For more information, see the TMP FAQ.


Back to the Utter Drivel Message Board

Back to the TMP Talk Message Board


Areas of Interest

General

Featured Hobby News Article


Featured Link


Featured Ruleset


Featured Showcase Article


Featured Workbench Article

Printing Scenario Maps with Poster Software

You've got a scenario map, and you need to create some hills. Is there some way to just print out the map in very large scale, so you can trace the outline of the hills you need to build? The Editor finds out...


Featured Profile Article

The Simtac Tour

The Editor is invited to tour the factory of Simtac, a U.S. manufacturer of figures in nearly all periods, scales, and genres.


887 hits since 3 Jan 2020
©1994-2024 Bill Armintrout
Comments or corrections?


TMP logo

Membership

Please sign in to your membership account, or, if you are not yet a member, please sign up for your free membership account.
Silent Pool03 Jan 2020 6:14 a.m. PST

Do you still use the TMP password issued to you by Bill …and just for my records, what is it?

79thPA Supporting Member of TMP03 Jan 2020 6:20 a.m. PST

I thought I created my own when I joined.

Personal logo Editor in Chief Bill The Editor of TMP Fezian03 Jan 2020 6:25 a.m. PST

In the old days, you set your original password. This caused problems when people managed not to set a password on their account…

In more recent years, the system assigns you a password, which you can always change.

Stryderg03 Jan 2020 6:45 a.m. PST

I'm still using my original password.
It's "n0tYour1nf0", without the quotes. Please update your records.

I change passwords on sites where the potential damage can be high. If someone gets my password here, they can change my preferences and that's about it. Oh, wait, they could put me on the Napoleonic boards! <shudder>

Ed Mohrmann Supporting Member of TMP03 Jan 2020 8:15 a.m. PST

I've never changed mine since the initial sign-up.

Garryowen Supporting Member of TMP03 Jan 2020 10:15 a.m. PST

I haven't changed mine either. I can't see the potential damages as being at all significant if someone had it.

Tom

Frederick Supporting Member of TMP03 Jan 2020 11:26 a.m. PST

Have not changed it – No. 3 son, who is a tech wizard, tells me that frequent password changes, especially if mandated, actually degrades and not enhances security

14Bore03 Jan 2020 1:17 p.m. PST

Yes still the original, if its that hard to remember it for me who else is going to get it?

Stryderg03 Jan 2020 1:44 p.m. PST

Your No. 3 son is correct. Frequent changes means people will start writing them down, or use passwords that are easy to remember, like "password". Oh I have to change it, great, "password1" it is.

JimSelzer03 Jan 2020 3:31 p.m. PST

NEVER

Syrinx003 Jan 2020 7:39 p.m. PST

Never changed my original. Even Microsoft has finally admitted changing passwords frequently is meaningless. Using strong hard to guess passwords is better. That said, I don't use the same password for my gaming boards as my finances.

von Schwartz03 Jan 2020 8:54 p.m. PST

I haven't changed ANY passwords for at least 10 years unless I'm forced to, my previous employer required monthly changes with no repeats!!!
My original password was assigned by Hotmail and it was so random that I felt it was as secure as it's likely to get.

Dn Jackson Supporting Member of TMP03 Jan 2020 11:19 p.m. PST

TMP has a password?

ZULUPAUL Supporting Member of TMP04 Jan 2020 2:57 a.m. PST

Still use my original password, no plans to change it.

Mr Elmo04 Jan 2020 7:06 a.m. PST

I think a 12 character minimum that allows unicode is a good start. A dictionary of common passwords (top 1000) is also good to implement. Rotation isn't really necessary.

Also, store the passwords hashed (PBKDF2) with good salt and pepper.

And allow password managers, I cannot remember }ȹƧ♡⚕😽♺😀♈ı☺ìŅƩ«ǭ😕Ę+*¸Ə☒Ťš> or whatever.

That said, does it matter? TMP uses SHA1 and an invalid certificate.

Personal logo Legion 4 Supporting Member of TMP04 Jan 2020 8:16 a.m. PST

NO …

Andrew Walters04 Jan 2020 10:12 a.m. PST

Telling people how often your change your password is a bad idea. Anything people know about your password can help crack it, and cracking one can lead to cracking others. So it's probably not smart to even *ask* how often people change their passwords.

TMP is awesome, I'm here every day, but as an affectionate critique I have to say it is *extremely* insecure. It appears to me, an amateur, that when you log in your password is sent in clear text. As a result, it is essential that you change your password daily, or ideally every time you log in. If anyone asks that's what I do.

Dn Jackson Supporting Member of TMP05 Jan 2020 12:36 p.m. PST

"TMP is awesome, I'm here every day, but as an affectionate critique I have to say it is *extremely* insecure."

That's true. It keeps sending me emails asking if I really like it. :-)

DJCoaltrain25 Jan 2020 9:29 p.m. PST

My PW hasn't changed since I created it.

Sorry - only verified members can post on the forums.