Header Wallpaper

Passwords & Forums [Fixing the issues]

AvatarHigh Priest Zevios Metathronos2 min to read

Dec 12 2022 Update:

We are working to resolve the e-mail mechanism problem especially in regards to Protonmail. It might take a while.

The recommendations from the Zevists who noted this feature was no longer necessary after the breach of the years old files have been followed; therefore the mandatory password reset has been removed, nobody will have to change password again.

Passwords from now on will require a little more length and complexity, to make sure things are safe.

It is still advised to change your password every so often.

Anyone who cannot login, please send an e-mail at [ email redacted ] and we will do a manual password retrial process.

Sorry for the inconvenience.

____________________

Dec 6 2022 Update:

Apparently, Protonmail has blocked the password retrieval e-mails. At the same time, they have blocked the function to receive new e-mails as posts, likely triggering false alarms in their spam filter.

Until that is resolved [it might not be] then receiving e-mails from the forum will be blocked on this provider.

We have tried this on other e-mail providers and everything was received properly.

______________________

Greetings everyone,

So every sometime now [40 days or a month] one might be asked to change their password. That's for security measures and in case anything gets attacked by the enemy.

I know this might be a little non convenient, but it's kind of needed. So try to use a password you remember, and then change it at the given interval.

Recently it appears also the pass retrieve mechanism is not working on those who registered with Protonmail. We are not sure why, maybe it is triggering a spam filter. We are looking into this and will implement a solution.

If anyone has account access problems, please do email at [email protected] so we can restore access or manually send the retrieval e-mail.

Thank you and sorry for this inconvenience.

-High Priest Zevios Metathronos

#1

Can the password be a complex variant of the same word used previously? I ask because I suck at remembering passwords and several times on this forum I had to change accounts because I didn't remember my login details when I changed my mobile phone and therefore I no longer had the passwords memorized...

#2

Glad I am not as dumb as I thought :lol: . For a second there I thought something was wrong with me for forgetting passwords...

Anyway, what alternatives can be used ? Instead of protonmail I mean.

#3

No problem

#4

Password changing is a minor inconvenience compared to being hacked by the enemy. We can do this! :)

#5
Shadowcatsaid:

It's all good, I saw and changed mine this morning. Gotta do what we gotta do to keep everything safe :)

I agree, but I know things will get better with the time.

Going Into Depth With The High Priest Zevios Metathronos

#6
SeguaceDiSatanasaid:

Can the password be a complex variant of the same word used previously? I ask because I suck at remembering passwords and several times on this forum I had to change accounts because I didn't remember my login details when I changed my mobile phone and therefore I no longer had the passwords memorized...

Technically yes, but you would have to make considerable changes, like turning all e:s into 3:s and so on, and after a while the password becomes obsolete anyway requiring you to make so many changes it becomes practically a new password.

Check this software out: https://keepassxc.org/

To supercharge your magickal experience: Hera's Guidance

For beginners: A Beginner's Guide

#7

Sadly I lost my previous account (Carvier) due to that little inconvenience. I even had a thanks from Lydia, I'm sad.

#8

I believe a password change every month is a little overkill. It was a good precaution after a known database leak happened, but if people use strong passwords, changing them every month gives very little benefit.

There are two types of password leaks to consider:

1. Password Hashes. The hacker would access the database and get password hashes. These cannot be cracked if a strong password was used. (That's what they were designed for!) Changing it in a month would only help if a weak password was used, which might be cracked after a month of CPU time, but it's still risky since you never know how long a weak password will withstand.

2. Password Plaintext. The hacker would get passwords in plaintext, probably by injecting code to capture passwords as people log in. The hacker would get a person's password immediately after they use it, and he can use it immediately to hack the account, so it will not help to change it in a month.

---------

A monthly password change will help people who use weak passwords, but it's an unnecessary inconvenience for everyone who uses strong passwords.

#9
HP. Zevios Metathronossaid:

Greetings everyone,

So every sometime now [40 days or a month] one might be asked to change their password. That's for security measures and in case anything gets attacked by the enemy.

I know this might be a little non convenient, but it's kind of needed. So try to use a password you remember, and then change it at the given interval.

HPZM bro i have forgotton all mine im on my 8th acc as you can prob see.

Thanks for this might need if happens again. Wish I still had my original.

Ave Satanas

#10
Soaring Eagle 666 [JGsaid:

" post_id=403556 time=1670127681 user_id=346]
I believe a password change every month is a little overkill. It was a good precaution after a known database leak happened, but if people use strong passwords, changing them every month gives very little benefit.

There are two types of password leaks to consider:

1. Password Hashes. The hacker would access the database and get password hashes. These cannot be cracked if a strong password was used. (That's what they were designed for!) Changing it in a month would only help if a weak password was used, which might be cracked after a month of CPU time, but it's still risky since you never know how long a weak password will withstand.

To add to this, simply instructing members how to make a strong password without the nonsensical requirements that lots of other sites have for their passwords, like special characters, numbers, upper/lower case letters, ect would be more helpful.

A strong password that's hard to crack by a CPU is as simple as a string of words together that can't be guessed in random order.

Easy example being

PurpleMonkeyDishwasher

A CPU will never guess the above in any practical or meaningful time.

"When the twines that hold him start to yield before his might
The day will come when Skoll and Hati devours all our light"

#11

This was only temporary, we will eventually go to 60 days and 100 days interval.

Yet this change now must be used so everyone makes a strong memorable password. Statistically a lot of people might have a weak password, so that would help. For this time.

It is all very good if this is what must be done.

Admittedly, I myself hate to have to do all of this. We will up the limit to trice per year.

Soaring Eagle 666 [JGsaid:

" post_id=403556 time=1670127681 user_id=346]
I believe a password change every month is a little overkill. It was a good precaution after a known database leak happened, but if people use strong passwords, changing them every month gives very little benefit.

There are two types of password leaks to consider:

1. Password Hashes. The hacker would access the database and get password hashes. These cannot be cracked if a strong password was used. (That's what they were designed for!) Changing it in a month would only help if a weak password was used, which might be cracked after a month of CPU time, but it's still risky since you never know how long a weak password will withstand.

#12

Like Henu said, KeePass is a fully encrypted and secure place to create and store passwords. For Satanic Documents, VeraCrypt can be a good place to store your files in an encrypted Hidden partitions that only you can access.

BrightSpace666 wrote: ↑
Mon Oct 10, 2022 5:28 pm
VeraCrypt

If you want additional encryption for your files under your already encrypted Linux system, you can use VeraCrypt. In it you can encrypt partitions or even files. You can choose multiple encryption types for a file, and you can perform two Encryptions within a virtual storage. The essence in a nutshell - you create an encrypted virtual space for yourself and encrypt it with a password, then PIM and log in. You store files there, but in this encrypted space there is also a hidden encrypted space where you store more important files.

When you unlock the first encrypted space, the second one doesn't show up, you have to unlock it manually, then once unlocked, you enter the password and PIM if you chose that too, and log in. This is your file encrypted in several ways, if you chose this at the beginning it is also hidden, plus you have to enter two passwords (I recommend you choose the PIM too, it's like a PIN, it's made up of numbers).

You can also generate a "key file" yourself, this is an even bigger security detail, because without these you cannot enter your files. You can store anything here, be it Project works, or passwords, or text documents, anything, and it's your own encrypted part under an encrypted Linux system.

The Tutorial video - https://incogtube.com/watch?v=4SBWc_cQm-Y

https://veracrypt.fr/en/Home.html

The leader of the Kundalini-Project -> https://kundalini-project.neocities.org

Contact:

Disroot Mail -> [ email redacted ]

I2P Mail -> [ email redacted ]

#14
HP. Zevios Metathronossaid:

This was only temporary, we will eventually go to 60 days and 100 days interval.

Yet this change now must be used so everyone makes a strong memorable password. Statistically a lot of people might have a weak password, so that would help. For this time.

It is all very good if this is what must be done.

It sounds like a better option would be for the forums to be strict about the password strength and not the frequency of change. Doesn't sound like it is currently possible to do that, but that would be more ideal.

#15

Hp please can you manually send me the verification email on the Weassel account?
I forgot my password and despite having a gmail on that account I didn't received the verification email and I also sent you an email from saturday where i ask for help and... you still didn't respond.
Can you help me please?

#16
BigWeasselsaid:

Hp please can you manually send me the verification email on the Weassel account?
I forgot my password and despite having a gmail on that account I didn't received the verification email and I also sent you an email from saturday where i ask for help and... you still didn't respond.
Can you help me please?

I do not know about the e-mail you sent to Cobra, but I think you should check your spam filter.

Perhaps the mail woth verification or password reset link ended up in there

Happens to me a lot with other emails from news sites and others.

Gmail and other email providers perhaps have a "hard time" in putting our emails correctly in place, especially when it comes to the ToZ.

#17
HP. Zevios Metathronossaid:

Dec 6 2022 Update:

Apparently, Protonmail has blocked the password retrieval e-mails. At the same time, they have blocked the function to receive new e-mails as posts, likely triggering false alarms in their spam filter.

Until that is resolved [it might not be] then receiving e-mails from the forum will be blocked on this provider.

Protonmail offers other domains for their emails, such as pm.me and proton.me. Have these been tested as well?

To supercharge your magickal experience: Hera's Guidance

For beginners: A Beginner's Guide

#18
BlueLake666said:
BigWeasselsaid:

Hp please can you manually send me the verification email on the Weassel account?
I forgot my password and despite having a gmail on that account I didn't received the verification email and I also sent you an email from saturday where i ask for help and... you still didn't respond.
Can you help me please?

I do not know about the e-mail you sent to Cobra, but I think you should check your spam filter.

Perhaps the mail woth verification or password reset link ended up in there

Yes, yes i checked there, I only have like 5 stupid mails there and nothing from ToZ.

#19
BigWeasselsaid:
BlueLake666said:
BigWeasselsaid:

Hp please can you manually send me the verification email on the Weassel account?
I forgot my password and despite having a gmail on that account I didn't received the verification email and I also sent you an email from saturday where i ask for help and... you still didn't respond.
Can you help me please?

I do not know about the e-mail you sent to Cobra, but I think you should check your spam filter.

Perhaps the mail woth verification or password reset link ended up in there

Yes, yes i checked there, I only have like 5 stupid mails there and nothing from ToZ.

Hmm.. okay... understood.

Then it really needs to be clarified with HP. Cobra then

#20

Thanks for the update.
Keep a record of your passwords so you can make it easy for yourself.