by Bossy Zunu » Thu Feb 02, 2023 3:46 pm
I don't know if any of you caught that (thanks boinsie) but some spammer apparently hijacked one of our already existing accounts (that is, a member in good standing who hasn't posted in a few years). I can't recall that happening before. Usually we just get people signing up who have figured out our annoying signup protocol, and they are never seen by the forum in general because they don't get past the vetting phase. So it's a little troublesome that someone breached the walls, so to speak. At this point I don't know if they used a hack to read our entire password list (in which case we'll start to see a crapton of this) or if hopefully they just obtained that specific name/password combo from off some other list out in the wild. But anyway, if you think your password might be guessable you might want to update it just to be on the safe side. (And if you use the same username/password combo elsewhere, you might consider changing it there too.)
FWIW as site admin I don't have any way that I'm aware of to read anyone's password; unless I'm mistaken the password list is hashed and not in plaintext format. Thus when people forget their password, I can only reset or change it, not read it back to them.