Quote:
Originally Posted by kippesp
I've not visited this forum in 6 years. But this mess brought me back for a short visit.
I know it is obvious, but people should be concerned that the harm from a successful username/password guess can do more harm than just spamming this forum or obtaining information from what this forum provides. Should that user still continue to use this same combination on other sites, say bankofamerica.com, then vbulletin forums can be a good testing ground for identifying valid combinations without triggering lockouts on other sites (without >1 factor improvements). Perhaps a design change to VB's log in such as reverting to a dreadded CAPTCHA after x-failed attempts. ...back to lurking.
|
That's not, in any way, shape or form, vB's responsibility. Preventing access to your bank account, or any other online accounts, is your job. How many times have we been told not to use the same password on multiple sites? How many times have we been told to use number/CAPS/Lowercase/Special Character combinations? How many times have we've been told not to give out our password to sites that don't have the same URL as the one they claim to be? We've been warned and warning people for nearly two decades now how to do this right, and if folks continue to think it won't happen to them, that's on them, not the developers of forum software who've already taken significant steps to preventing this in the first place.