Silk Road forums
Discussion => Security => Topic started by: MySecretAccount on February 01, 2013, 05:36 am
-
Did I space on this, or is there a new login screen with a "Forgot Passcode" or whatever choice under the register option. I don't know how you'd use it, and I didn't click it, but - was this planned? Maybe a midnight deployment?
-
It wasn't there when I signed on this morning, but I just signed out and back in a few minutes ago and noticed the same thing. Definitely new ... hopefully planned!
-
I saw this and thought it was kinda off.. Hopefully its no BS.. SR has been down off and on all day maybe their changing a thing or 2. I dont know how we could retrieve our password though when we never put any secret questions in if it was lost or forgotten.. Far as i know our PIN is the only other thing..
RIGHT?
-
I tested it with a throw away account. After entering username and pin it says:
Your password has been changed to <password>
Please log in immediately and change it via account->settings
After logging in, everything seems normal. I think it's a new feature to recover lost passwords.
-
Probably easier for SR staff than having to address lost password problems individually / manually.
-
so is it safe??? or maybe phising?? or should i not be worried/??
-
I saw it as well and thought it was really odd, so i double checked i wasn't on a phising link ,But everyone else seems to be seeing the screen as well so i think it might be ok, If an admin addressed this it would put my mind at ease.
-
I tried that 'forgot password' function with a throw away account and it seemed legit. It just asks for your username and PIN and then generates a new password for you. You then log in using the new password and change the password immediately. I obviously wouldn't try it with an account that had funds on it, but as I said, it seemed legit.
-
I tried that 'forgot password' function with a throw away account and it seemed legit. It just asks for your username and PIN and then generates a new password for you. You then log in using the new password and change the password immediately. I obviously wouldn't try it with an account that had funds on it, but as I said, it seemed legit.
MM - or anyone here - Where is it please?
Tanks
-
I tried that 'forgot password' function with a throw away account and it seemed legit. It just asks for your username and PIN and then generates a new password for you. You then log in using the new password and change the password immediately. I obviously wouldn't try it with an account that had funds on it, but as I said, it seemed legit.
MM - or anyone here - Where is it please?
Tanks
Hey, I haven't tried it, but when you get to the Login screen, you will see underneath where it says click to join, it says 'forgotten my password' or something along those lines :)
-
It would be nice if such innovations would be made public by DPR or at least the mods.
-
An official post on this would be much appreciated. First time I tried logging in it apparently timed out, think I had a small heart attack "knowing" I'd just given up my password. Alas second attempt no issues.
-
It would be nice if such innovations would be made public by DPR or at least the mods.
Moderators aren't given any kind of heads up about SR matters - too much of a security concern. However, I did ask DPR immediately after noticing this last night and he has read it but not yet replied.