Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar Mark Forums Read
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 01-13-2005, 05:56 PM   #1
mrthumbs
salad tossing sig guy
 
mrthumbs's Avatar
 
Join Date: Apr 2002
Location: mrthumbs*gmail.com
Posts: 11,702
allinternal and likes privacy breach?

https://secure.perfectgonzo.com/cgi/...t_password.cgi

This system for account retrieval, ive seen other paysites use it, would stop me from joining a site if i knew about it.
mrthumbs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-13-2005, 05:58 PM   #2
media
Confirmed Moneymaker
 
media's Avatar
 
Industry Role:
Join Date: Apr 2002
Location: Eugene, OR It's Like Jail, Only with Trees!
Posts: 9,852
Why would it be a privacy breach???

If someone has your name then they need your email address account info as well...
__________________
I'm here for the violence!
media is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-13-2005, 05:59 PM   #3
mrthumbs
salad tossing sig guy
 
mrthumbs's Avatar
 
Join Date: Apr 2002
Location: mrthumbs*gmail.com
Posts: 11,702
With the zillions of pornsites around what would be the odds of your victim being a member.. but a last name + email address is too public imo..

Why not last 4 cc digits or the good old "..enter your email address and IF its present in our database..." etc..


Media: exaclty my point email address and lastname .. thats public info.
And those two not only tell me if im a member or not but also displays
my account data and subscriptions.

Last edited by mrthumbs; 01-13-2005 at 06:01 PM..
mrthumbs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-13-2005, 06:01 PM   #4
media
Confirmed Moneymaker
 
media's Avatar
 
Industry Role:
Join Date: Apr 2002
Location: Eugene, OR It's Like Jail, Only with Trees!
Posts: 9,852
Quote:
Originally Posted by mrthumbs
True, with the zillions of pornsites around what would be the odds of your victim being a member.. but a last name + email address is too public imo..

Why not last 4 cc digits or the good old "..enter your email address and IF its present in our database..." etc..
We already have that information anyways on a member.. so why is it considered a privacy breach? I still don't get it... Are you referring to someone just saying lets check if joe blow has an account here? or if my husband is surfing this site? If thats the case, half the ladies will know their husbands account info..

edit: by acount info, I mean cc info
__________________
I'm here for the violence!
media is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-13-2005, 06:04 PM   #5
mrthumbs
salad tossing sig guy
 
mrthumbs's Avatar
 
Join Date: Apr 2002
Location: mrthumbs*gmail.com
Posts: 11,702
Quote:
Originally Posted by media
Are you referring to someone just saying lets check if joe blow has an account here? or if my husband is surfing this site? If thats the case, half the ladies will know their husbands account info..


If i join a site i dont want anyone except the program owner to know i joined.. i dont want my neighbours checking up on me and see if joined
gaymania.com AND use my account data to leech free porn!!

And my neighours have my lastname + email.. nothing confidential.
mrthumbs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-13-2005, 06:05 PM   #6
media
Confirmed Moneymaker
 
media's Avatar
 
Industry Role:
Join Date: Apr 2002
Location: Eugene, OR It's Like Jail, Only with Trees!
Posts: 9,852
Quote:
Originally Posted by mrthumbs
If i join a site i dont want anyone except the program owner to know i joined.. i dont want my neighbours checking up on me and see if joined
gaymania.com AND use my account data to leech free porn!!
You're not getting the fact that they need to have your email account dude.. the password and login info will be dispatched to an email address which if the person does not know any pass info to this email address to begin with, then they will not be able to get any details on login info..

It will not just say ok heres the details for the random name you entered.. lol
__________________
I'm here for the violence!
media is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-13-2005, 06:07 PM   #7
mrthumbs
salad tossing sig guy
 
mrthumbs's Avatar
 
Join Date: Apr 2002
Location: mrthumbs*gmail.com
Posts: 11,702
Quote:
Originally Posted by media
You're not getting the fact that they need to have your email account dude.. the password and login info will be dispatched to an email address which if the person does not know any pass info to this email address to begin with, then they will not be able to get any details on login info..

It will not just say ok heres the details for the random name you entered.. lol

Thats my point! Once i fill in lastname + email it displays the username / password data on the webpage.. no email sent.
mrthumbs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-13-2005, 06:09 PM   #8
mrthumbs
salad tossing sig guy
 
mrthumbs's Avatar
 
Join Date: Apr 2002
Location: mrthumbs*gmail.com
Posts: 11,702
So basicly to chew it a bit more for my beloved gfy members:

If my neighbours name is John Doe and his emaila ddress is [email protected]
(i got his business card)

i simply enter
DOE and [email protected]

To access his account details.
mrthumbs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-13-2005, 06:09 PM   #9
media
Confirmed Moneymaker
 
media's Avatar
 
Industry Role:
Join Date: Apr 2002
Location: Eugene, OR It's Like Jail, Only with Trees!
Posts: 9,852
Quote:
Originally Posted by mrthumbs
Thats my point! Once i fill in lastname + email it displays the username / password data on the webpage.. no email sent.
So this one will display it right on the page??? Thats insanely stupid.. usually it would send an email to the account holder so they can have the email in their secure password protected account..

if all they require is a name and email to get the pass, then yes this is an insecure form of password lookup..
__________________
I'm here for the violence!
media is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-13-2005, 06:10 PM   #10
mrthumbs
salad tossing sig guy
 
mrthumbs's Avatar
 
Join Date: Apr 2002
Location: mrthumbs*gmail.com
Posts: 11,702
why use a passowrd system in the first place? just tell your members to login with your lastname + email address!
mrthumbs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-13-2005, 06:11 PM   #11
mrthumbs
salad tossing sig guy
 
mrthumbs's Avatar
 
Join Date: Apr 2002
Location: mrthumbs*gmail.com
Posts: 11,702
ARS used to do PW recovery like this a few years back.. they changed it after a few complaints.
mrthumbs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-13-2005, 06:25 PM   #12
s9ann0
Confirmed User
 
Join Date: Sep 2001
Location: Boston
Posts: 4,873
yea i just broke into a mates account there I am in the members area now :o)

thats shady I like the image verification shit for members access though might have to steal that for my sites
s9ann0 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-13-2005, 06:26 PM   #13
s9ann0
Confirmed User
 
Join Date: Sep 2001
Location: Boston
Posts: 4,873
urrr they squirting milk up her asshole this site is sick
s9ann0 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks
Thread Tools



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.