View Single Post
Old 04-27-2006, 06:04 PM  
minusonebit
So Fucking Banned
 
Join Date: Feb 2006
Posts: 7,391
Quote:
Originally Posted by shaliza
Last week, ePassporte's LDAP server crashed and our backup was corrupted. The result: a number of account passwords were automatically reset. I know this issue was inconvenient for our account holders and we are extremely sorry for this. Most of you are able to login now and use your accounts again but if anyone is still having troubles, please feel free to contact me or Keyser and we will ensure your issue is handled immediately.

Were these accounts hacked??? NO! In fact, the database issue made it even harder for anyone to access any ePassporte account.

Some accounts were not effected by the crash however we were unable to differentiate between these accounts. Minusondebit, your account was one that was NOT effected but as I said we were unable to differentiate so we simply reset the password on accounts we thought would have an issue. We store the last three passwords with a one way encryption scheme. That means we can encrypt them, but we cannot decrypt them. We take the password that you enter and we encrypt it and compare it to the old encrypted password. If it matches, we don't let you use it again for security purposes.

I hope this answers your questions and everyone can put away their popcorn and milk duds.
This does answer my questions. I am not really sure I can trust anything ePassporte says due to the history of past indescretions. But this at least is a reasonable explanation, so in absence of anything else, I'll accept it as though it were truth.

The only thing I still wonder about is your statement that my account was not one that was affected. I know for a fact that I was not able to login to my account after trying several times. Did I fat-finger my password each time I tried to login? Perhaps. Is it likely? I dont think so. Oddly enough, when I did the reset, everything was fine and dandy. I dont really care about this as its like crying over spilled milk now.

But I closed out my debit card this morning anyway, just to be safe. An ounce of prevention is worth a dumptruck load full of cure.

With regard to my password, so if I understand your response correctly, if I change my password three more times to something different each time, the third time will kick the oldest password out of the DB and I'll be able to return to using 'my' password?
minusonebit is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote