We’re updating Daz Security Settings!

2

Comments

  • SimonJMSimonJM Posts: 5,999
    scorpio said:
    DAZ_Jacob said:

    As part of our ongoing commitment to keep your information secure, we’ve been implementing a number of security updates over the last few weeks.  Most of those updates have happened in the  background across all our programs including our website, DazCentral, DIM, DazConnect, and Studio.

    One change we’ve installed is that Daz now requires at least seven (7) characters for each user password, which better protects your individual account and helps keep your information secure.  Note, there are no other requirements for that password.

    While this large security update overhaul only affected certain users in a small capacity, it also marked the first time that some Daz users have ever changed their password! For good measure, we recommend you change your password at least once every five years or so :).

    We’re also offering you a special deal to thank you for participating in our increased password security: take 15% off up to 5 items* of your choosing using coupon code: SECURE-IT

    Thank you for being a Daz User, and for helping us keep your account secure!

     

    *Offer excludes New Releases.

    *Usable once per customer.

    *Limited time offer - coupon works until 12:00 midnight MDT, Friday 5/22.

    Thanks, but this information would have been nice when several of us were running around trying to figure out why we couldn't log into DIM several days ago

    Was just abou to mention this. Coming from a programming/Tech Support/System Software background I am fully in favour of better security, but if you are going to suddenly 'invalidate' peoples' passwords, you HAVE to warn them ahead of time, surely?

  • chatvenuechatvenue Posts: 21

    I already had a password over 7 characters length. And I saw the following when I went into my account page.

    * Due to recent security updates, passwords must be at least 7 characters. Be sure to update yours!

    Nevertheless I updated it again, with a 10 character length password. And I still see the same notice. After a while the notice becomes meaningless since it is sort of crying wolf, and people will get used to ignoring other security notices from you.

     

    You may want to look into this.

  • LeanaLeana Posts: 11,848
    chatvenue said:

    I already had a password over 7 characters length. And I saw the following when I went into my account page.

    * Due to recent security updates, passwords must be at least 7 characters. Be sure to update yours!

    Nevertheless I updated it again, with a 10 character length password. And I still see the same notice. After a while the notice becomes meaningless since it is sort of crying wolf, and people will get used to ignoring other security notices from you.

    The message is probably displayed on all accounts. It should have said something like "be sure to update yours if it's not compliant", that would have been clearer and would apply to everybody.

  • MelanieLMelanieL Posts: 7,496
    Leana said:
    chatvenue said:

    I already had a password over 7 characters length. And I saw the following when I went into my account page.

    * Due to recent security updates, passwords must be at least 7 characters. Be sure to update yours!

    Nevertheless I updated it again, with a 10 character length password. And I still see the same notice. After a while the notice becomes meaningless since it is sort of crying wolf, and people will get used to ignoring other security notices from you.

    The message is probably displayed on all accounts. It should have said something like "be sure to update yours if it's not compliant", that would have been clearer and would apply to everybody.

    I agree - I was surprised to see that message as mine is certainly longer, so I wondered what was going on.

  • nicsttnicstt Posts: 11,715
    DAZ_Jacob said:

    As part of our ongoing commitment to keep your information secure, we’ve been implementing a number of security updates over the last few weeks.  Most of those updates have happened in the  background across all our programs including our website, DazCentral, DIM, DazConnect, and Studio.

    One change we’ve installed is that Daz now requires at least seven (7) characters for each user password, which better protects your individual account and helps keep your information secure.  Note, there are no other requirements for that password.

    While this large security update overhaul only affected certain users in a small capacity, it also marked the first time that some Daz users have ever changed their password! For good measure, we recommend you change your password at least once every five years or so :).

    We’re also offering you a special deal to thank you for participating in our increased password security: take 15% off up to 5 items* of your choosing using coupon code: SECURE-IT

    Thank you for being a Daz User, and for helping us keep your account secure!

     

    *Offer excludes New Releases.

    *Usable once per customer.

    *Limited time offer - coupon works until 12:00 midnight MDT, Friday 5/22.

    7?

    I never go below 25 random characters on any password unless it is restricted to less.

  • Richard HaseltineRichard Haseltine Posts: 102,908
    Sevrin said:

    If you really want people to use safe passwords, make it a discount of 1% per character in our passwords. devil

    Daz doesn't know how long your password is, so they can't do this or selectively message those with short passwords to update them.

  • TaozTaoz Posts: 9,979
    edited May 2020
    Sevrin said:

    If you really want people to use safe passwords, make it a discount of 1% per character in our passwords. devil

    Daz doesn't know how long your password is, so they can't do this or selectively message those with short passwords to update them.

    They can easily check the length when you log in (unless Magento prevents this in some way), they just can't calculate the length from the stored hash used to verify it.  You need to get the plain text password in a string from the input field before you can process it further, so it's just getting the length of that string.

    Post edited by Taoz on
  • lana_lasslana_lass Posts: 520
    DAZ_Jacob said:
    lana_lass said:
    Is there a time limit on the code we need to be aware of? :)

    Great Q, thanks for reminding me!  You should use this coupon before midnight, 12:00 MDT on Friday, the 22nd.

    Thanks Jacob! laughyes

  • Richard HaseltineRichard Haseltine Posts: 102,908
    Taoz said:
    Sevrin said:

    If you really want people to use safe passwords, make it a discount of 1% per character in our passwords. devil

    Daz doesn't know how long your password is, so they can't do this or selectively message those with short passwords to update them.

    They can easily check the length when you log in (unless Magento prevents this in some way), they just can't calculate the length from the stored hash used to verify it.  You need to get the plain text password in a string from the input field before you can process it further, so it's just getting the length of that string.

    I thought most of the suggestions were for general application, not a pop-up on entry.

  • TaozTaoz Posts: 9,979
    Taoz said:
    Sevrin said:

    If you really want people to use safe passwords, make it a discount of 1% per character in our passwords. devil

    Daz doesn't know how long your password is, so they can't do this or selectively message those with short passwords to update them.

    They can easily check the length when you log in (unless Magento prevents this in some way), they just can't calculate the length from the stored hash used to verify it.  You need to get the plain text password in a string from the input field before you can process it further, so it's just getting the length of that string.

    I thought most of the suggestions were for general application, not a pop-up on entry.

    Well my point was just that the data is accessible, at least theoretically - I don't know if Magento allows it. 

  • GallCommTVGallCommTV Posts: 239
    Taoz said:
    DAZ_Jacob said:

     

    One change we’ve installed is that Daz now requires at least seven (7) characters for each user password, which better protects your individual account and helps keep your information secure.  Note, there are no other requirements for that password.

    Great, then I can continue using "password".  cheeky

    Nah!! It' gotta be 'new' .... eg 'newpassword' devil

  • sapatsapat Posts: 1,735

    hmmm....I hadn't changed mine since May 2012 blush

  • Peter WadePeter Wade Posts: 1,642
    Dave230 said:

    How does Daz know how many characters my password has?  That sort of implies our passwords are stored in plain text.

    It would be fairly easy to implement a method of scrambling of the password that preserved the number of characters and was not easily reversible.

  • Peter WadePeter Wade Posts: 1,642

    I've always been skeptical of this idea you should change your password regularly. The idea that it makes it a moving target would only work if the site told a hacker how close they were to the answer and let them home in on it. If you have to change a password frequenty then people who could easily remember one password are more likely to write it down and possibly make it more vulnerable. Also if you have to keep thinking up new passwords a lot of people will eventually get annoyed and use something obvious. One place I worked had enforced password changes and wouldn't let you use any of the 20 last used passwords. I had a list of 21 passwords in my organiser (it was a paper one then)  with a note saying which number i was on.

  • ed3Ded3D Posts: 2,303
    edited May 2020

    _ and

    demotivation-Your-password-.png
    600 x 815 - 331K
    Post edited by ed3D on
  • ConnaticConnatic Posts: 282
    edited May 2020

    The red message at login is confusing.

    Post edited by Connatic on
  • Changed my password days ago while I was logged in. All was well for days. Today, I was logged in fine on my computer and phone both. Suddenly was unable to log in on my phone. Logged out on computer, then was unable to log back in there. I use a password manager, so I know for a fact it was the correct password. Had to use the password reset link to change my password again. Unexpected frustrations are unexpected.
  • ImagoImago Posts: 5,278
    Sevrin said:

    If you really want people to use safe passwords, make it a discount of 1% per character in our passwords. devil

    Daz doesn't know how long your password is, so they can't do this or selectively message those with short passwords to update them.

    Mine is 16 character long, can I assume I'm fine? Or it's something more deep than that?

  • Richard HaseltineRichard Haseltine Posts: 102,908
    Imago said:
    Sevrin said:

    If you really want people to use safe passwords, make it a discount of 1% per character in our passwords. devil

    Daz doesn't know how long your password is, so they can't do this or selectively message those with short passwords to update them.

    Mine is 16 character long, can I assume I'm fine? Or it's something more deep than that?

    That should be fine.

  • Khai-J-BachKhai-J-Bach Posts: 163

    be nice if they fixed the "stay logged in" function that *does not work*

    I've just taken to logging in everytime. 

     

     

    (ok if it works fine for you. I am NOT you. it does not work for me. yet Amazon, Netflix, Steam. all places I can and do spend more money with have this working function. remember, I am not you. I don't care if it works for you.)

  • xyer0xyer0 Posts: 6,064

    Fortunately, I had a 12 character password; so, I dodged a bullet. BUT I want to say THANK-YOU!!! for the 15% off coupon. I combined it with the extra 20% off a gift card and got 32% off a gift card. Dees ees vewy goot!

  • edited May 2020
    Imago said:
    Sevrin said:

    If you really want people to use safe passwords, make it a discount of 1% per character in our passwords. devil

    Daz doesn't know how long your password is, so they can't do this or selectively message those with short passwords to update them.

    Mine is 16 character long, can I assume I'm fine? Or it's something more deep than that?

    That should be fine.

    So my password is still working fine on my laptop (Chrome & Firefox browsers) but won't work on my Kindle Fire tablet. AND the forgot your password the instructions sends me too doesn't work; I do not get a reset code. Yes I am using my correct email, yes I have checked spam, yes I checked both my regular inbox and promotions inbox sice Daz3d emails go to one or the other almost randomly. Yes I have tried from both my laptop & tablet

     

    EDIT: Tablet seems to have sorted out its login issue, whatever it was.

     

    Post edited by miladyderyni_173d399f47 on
  • SpottedKittySpottedKitty Posts: 7,232

    Oh, that's evil. Eeeeevil. EEEEEEEEEEEEEEEEEEEVIL!!!1!!one!!!!  

  • Aussie ArtistAussie Artist Posts: 84
    edited May 2020

    I am not able to login using Daz Central / Daz Studio nor Daz Install Manager..... since this change..  sadsadsadsadsad

     

    I have recently changed my password.

     

    I have checked my password length also it is 12 Characters long, so it should be accepted by the these programs...  sadsadsadsadsadsad

     

     

    Post edited by Chohole on
  • 3Diva3Diva Posts: 11,749
    edited May 2020

    I am not able to login using Daz Central / Daz Studio nor Daz Install Manager..... since this change..  sadsadsadsadsad

     

    I have recently changed my password.

     

    I have checked my password length also it is 12 Characters long, so it should be accepted by the these programs...  sadsadsadsadsadsad

     

     

    You'll probably need to put in a ticket with customer service then if you're still not able to log in to Install Manger or Daz Studio. 

    Post edited by Chohole on
  • Aussie ArtistAussie Artist Posts: 84
    edited May 2020

    Divamakeu.. I have already sent in a ticket... yet to get a reply back... I just hope there are people working on support as i don't if Co-vid restrictions have stopped this or reduced the number of people working on support for daz..

     

    Thanks for suggestion though..

     

     

     

     

    Post edited by Chohole on
  • 3WC3WC Posts: 1,114

    Any chance the forum will stop logging people out so often? 

    Nope, if anything it is more often for me.

  • ed3Ded3D Posts: 2,303
    Connatic said:

    The red message at login is confusing.

    _ yeah ,  partly _

  • WonderlandWonderland Posts: 7,057

    Since I changed my password DIM and DS are still saving my old password and I have to manually put in the new one each time although "remember me" is checked. (LOL autocorrect had somehow replaced "put in" with "Putin"! )

  • fixmypcmikefixmypcmike Posts: 19,613

    Since I changed my password DIM and DS are still saving my old password and I have to manually put in the new one each time although "remember me" is checked. (LOL autocorrect had somehow replaced "put in" with "Putin"! )

    Try unchecking "remember me", closing the application, then restart and check it.

Sign In or Register to comment.