Forum Settings
Forums
New
Pages (3) « 1 [2] 3 »
Sep 13, 2013 2:41 AM

Offline
Mar 2013
10
Login issue isn't fixed for me :'// I keep being logged out !!!!!!
+ Okk Password will be changed now :)
Sep 13, 2013 2:58 AM

Offline
Oct 2009
7146
koleare said:
Prequel said:
Now, I don't understand how forced log-outs can be related to IP block to a malicious person. It must be possible to block an IP without applying IP sensivity to whole site. Why exactly do we have to re-login when we change our IPs?
The IP block isn't for the malicious person. Well, blocking isn't really the best word either. Mostly and in simpler terms, your IP is used in the authentication process and session, so when your IP changes, the previous session isn't valid anymore and you have to authenticate/log in again. This pretty much prevents your session from being hijacked (http://en.wikipedia.org/wiki/Session_hijacking) like it happened two years ago.

Ah, and the forced log outs aren't related to the IPs. As I said, those were incompatibilities with the new security updates which fight DDoSes.


Ah, glad you explain the log out issue.
The most important things in life is the people that you care about
Sep 13, 2013 5:22 AM

Offline
Apr 2013
174
@koleare ,

Okay, how can someone "hijack session"s with only DDoS? I guess there were at least two malicious behaviours then. (I wasn't here 2 years ago.) So I'm assuming there are/were security flaws?

If those flaws are fixed, shouldn't you let us stay logged in when we change our IPs? If not, then isn't this a bigger issue that needs to be dealt with? And how can the site in such a situation be working almost flawlessly if such a mindlessly obsessed "hacker" is messing with MAL?

I'm sorry if "session hijacking" is something of an inevitability, but with so many sites letting people to use their sites flawlessly with or without IP changes, I can't help but think there is a better way.
RememberTheCantSep 13, 2013 5:27 AM
Open to chat about any storytelling related subject as long as it's clever and respectful.
Myanimelist
Sep 13, 2013 5:41 AM

Offline
Aug 2010
2344
Prequel said:
Okay, how can someone "hijack session"s with only DDoS? I guess there were at least two malicious behaviours then. (I wasn't here 2 years ago.) So I'm assuming there are/were security flaws?

If those flaws are fixed, shouldn't you let us stay logged in when we change our IPs? If not, then isn't this a bigger issue that needs to be dealt with? And how can the site be working flawlessly if such a mindlessly obsessed "hacker" is messing with MAL?

I'm sorry if "session hijacking" is something of an inevitability, but with so many sites letting people to use their sites flawlessly with or without IP changes, I can't help but thing there is a way.
I never linked the DDoS to hijacking and forced log outs to the IP sessions (like you did in your last post); it's only you who's doing that -_-'

These are separate matters. To patch up a clearer timeline (well, maybe I wasn't explaining it that well - but well, I am trying to say as much as I can without revealing too much :P):

- there were cases of session hijackings last year, so that 'IP to session' was implemented to prevent them from happening again
- the site has been DDoSed two weeks ago (if my memory isn't failing me), so a couple of security updates went live to counter them, but unfortunately, people started getting forced log outs, which were fixed yesterday

And yeah, everything should run smoothly without getting logged out every time your IP changes... - but then Xinil said in the opening post that he'd rather improve the improve the security over rolling back accounts, so maybe there's something planned for that.
koleareSep 13, 2013 5:44 AM
Sep 13, 2013 6:06 AM

Offline
Dec 2011
2016
Password changed and thanks for the hard work!
Keep us safe, please :3
Signature removed. Please follow the signature rules, as defined in the Site & Forum Guidelines.
Sep 13, 2013 7:30 AM

Offline
Jul 2012
25
Thanks for all your hard work!
Sep 13, 2013 7:44 AM

Offline
Oct 2011
8878
Thank you !!!!!!
Sep 13, 2013 8:01 AM

Offline
Sep 2009
32
Yay ! Thank you very much for your hard work , Xinil & the rest of MAL staff . You guys are the best :)
Sep 13, 2013 8:46 AM

Offline
Apr 2010
1909
The staying logged in issues seem to be fixed for me. Normally it'd happen every 5-10 minutes but I haven't been logged out since yesterday afternoon.

Thank you for your hard work.




Sep 13, 2013 9:01 AM

Offline
Aug 2013
347
Glad I've changed my password today NO BODY CAN'T STOP ME! WOOOOOOHOOOOOO.
"There is nothing outside of yourself that can ever
enable you to get better, stronger, richer, quicker,
or smarter. Everything is within.
Everything is exists.
Seek nothing outside of yourself
" - Musashi
miyamoto
Sep 13, 2013 9:25 AM

Offline
Sep 2012
687
around 1 ~ 2 hour without logout....

Thanks, and the password has been changed ^.^
Sep 13, 2013 10:20 AM

Offline
Sep 2011
16158
I'm still having the log-in issue. What the hell?
TennoujiSep 13, 2013 10:24 AM


Sep 13, 2013 10:35 AM

Offline
Sep 2010
6759
Changed password just now thanks! Been logged in since 10 and its been almost 4 hours with no problems
"What has two arms, two legs, and is alive? Not your favorite character lol! xD"
Sep 13, 2013 11:10 AM

Offline
Oct 2012
9
koleare said:

- there were cases of session hijackings last year, so that 'IP to session' was implemented to prevent them from happening again

There are only two possible ways of session hijacking:
1. The attacker could read session keys from the database, in this case the site has to take actions to prevent database access, and not connect the session to the IP, after this actions are taken invalidate all active sessions once and the problem is solved.
2. The attacker hijacked sessions on user PCs. In this case it's only a problem of a small group of people who aren't capable of keeping their system safe. That can't be prevented and therefore shouldn't even be attempted. (If the attacker can hijack a session he can most likely as well hijack a password)

Either way, session hijacking is definitley not a reason to log out a user when he changes his IP. Since this happens to roughly 99% of the users every single night it's mainly annoying and not helpful.
Sep 13, 2013 11:11 AM

Offline
Dec 2009
603
I haven't changed my password since I joined.. Oh well, it was time for a new anyway. Now that that is resolved, a little, when do you think the bbcodes will be enabled again?

Sep 13, 2013 11:55 AM

Offline
Sep 2012
284
I seem to be staying logged on now.

THANK YOU! It was being really irritating...
Sep 13, 2013 12:59 PM

Offline
Apr 2012
56
"Starting on September 20, we will no longer be able to restore profiles for users who have not changed their password since August 22. It takes a lot of work to restore hacked profiles, and we would rather put that effort into security improvements that can benefit everyone."

Excuse me? So are you saying that I have to change my password for an account that's already been deleted? How the hell am I supposed to do that?

I get it that you prioritize security over rolling back people who lost their accounts. Actually no, I really don't get that. Because people have been waiting for WEEKS to have their accounts back. If anything I only want my god damn account back just to export my list and import it somewhere else.

What exactly am I supposed to do? If I don't change my password for a deleted account, I won't get my deleted account back? How long do we have to wait for our accounts to be rolled back? Seriously, you think the login thing is frustrating, it's frustrating not having your actual list, ratings, friends, etc. for weeks and weeks on end. This is frustrating as all hell.
Sep 13, 2013 1:06 PM

Offline
May 2011
9
Yay, hopefully all problems related to the hacking incident are now solved :)
I feel bad for those people who lost their accounts though...
~Otaku for 15 years~
Sep 13, 2013 1:28 PM
Offline
Jan 2012
16
Still having a problem keeping me logged in FYI. Ganbatte.
Sep 13, 2013 2:25 PM
Anime DB Admin
BACK FOR MORE?

Offline
Jan 2007
12683
If you still struggle with staying logged in I suggest you clear all myanimelist cookies and try again.


gettogaara said:
Rapha_Lamperouge said:
Just changed my pw, interestingly I got DC immediately after that.

Same here but it hasn't happened again since then.


That's normal. You get logged out when you change your password. I believe it even tells you exactly that on the page you see after changing your password, so eyes open.

staff.applications  
guidelines.faq 
 

report.abuse  

thx.skittles  
thx.kina 
 

[H+] ³  
Sep 13, 2013 2:31 PM

Offline
Mar 2009
512
Please explain to me why you think failing to keep your database secure should leak my password?

You aren't storing plain text or basic MD5 nowadays surely?
Sep 13, 2013 3:58 PM

Offline
Jul 2012
517
thanks!! what about BBcode?
Sep 13, 2013 4:01 PM

Offline
Jan 2013
420
how do i change my password on MAL?
Sep 13, 2013 4:34 PM

Offline
Nov 2012
165
welcome2NHK said:
thanks!! what about BBcode?

don't think most of them work yet. (at least for me)
Sep 13, 2013 5:19 PM
Offline
Mar 2006
7
MikeP said:
Please explain to me why you think failing to keep your database secure should leak my password?

You aren't storing plain text or basic MD5 nowadays surely?


More than this, even salted the current requirements are 4-18 alphanumerics, which is fairly trivial to break via bruteforce.
Sep 13, 2013 6:35 PM

Offline
May 2012
3820
Changed my password yesterday. Not forced log-out, which is actually good for me. <3


Thanks for your hard work, mods! *thumbs up*
Badges: C.C.O / T.C.O / TFCC admin ID | Previously known as kazumi-san95
Sep 13, 2013 6:40 PM

Offline
Sep 2011
489
Thx, bro.
Sep 13, 2013 6:42 PM

Offline
Mar 2012
18961
I'm still getting logged out even after changing my password.
Kickstarter for Rokujouma is fully funded. Good work everyone. Lets wait for the result of our hard work together.
Sep 13, 2013 7:24 PM

Offline
Oct 2011
136
Xinil said:
We believe we've fixed the majority of login issues. Terribly sorry it took so long to get this under control, but hopefully we can move forward from here. If your IP is changing frequently though, you'll still get logged out on each subsequent change.

Also, we've received information that the attacker who has hit MAL before may have compromised other anime sites as well. If you've reused usernames, e-mail addresses, and passwords on these sites, it is likely that the attacker has them, and can log in as you if he or she wants. We highly recommend that you change your password as soon as possible, to ensure that your profile and data aren't compromised.

Starting on September 20, we will no longer be able to restore profiles for users who have not changed their password since August 22. It takes a lot of work to restore hacked profiles, and we would rather put that effort into security improvements that can benefit everyone.

Thanks everyone!


i just changed my password now.

Anime-Planet.com - anime | manga | reviews
Sep 13, 2013 7:59 PM

Offline
Apr 2012
56
Akichii said:
"Starting on September 20, we will no longer be able to restore profiles for users who have not changed their password since August 22. It takes a lot of work to restore hacked profiles, and we would rather put that effort into security improvements that can benefit everyone."

Excuse me? So are you saying that I have to change my password for an account that's already been deleted? How the hell am I supposed to do that?

I get it that you prioritize security over rolling back people who lost their accounts. Actually no, I really don't get that. Because people have been waiting for WEEKS to have their accounts back. If anything I only want my god damn account back just to export my list and import it somewhere else.

What exactly am I supposed to do? If I don't change my password for a deleted account, I won't get my deleted account back? How long do we have to wait for our accounts to be rolled back? Seriously, you think the login thing is frustrating, it's frustrating not having your actual list, ratings, friends, etc. for weeks and weeks on end. This is frustrating as all hell.
Considering that I really don't want to lose all my ratings, anime, friends, etc. because of a crappy reason like this, I'd really, REALLY appreciate if a mod replied to me and got back with me on this?
Sep 13, 2013 8:00 PM

Offline
Oct 2012
765
getting tired of log in... -_-



Sep 13, 2013 8:01 PM

Online
Jan 2009
92389
Akichii said:
Akichii said:
"Starting on September 20, we will no longer be able to restore profiles for users who have not changed their password since August 22. It takes a lot of work to restore hacked profiles, and we would rather put that effort into security improvements that can benefit everyone."

Excuse me? So are you saying that I have to change my password for an account that's already been deleted? How the hell am I supposed to do that?

I get it that you prioritize security over rolling back people who lost their accounts. Actually no, I really don't get that. Because people have been waiting for WEEKS to have their accounts back. If anything I only want my god damn account back just to export my list and import it somewhere else.

What exactly am I supposed to do? If I don't change my password for a deleted account, I won't get my deleted account back? How long do we have to wait for our accounts to be rolled back? Seriously, you think the login thing is frustrating, it's frustrating not having your actual list, ratings, friends, etc. for weeks and weeks on end. This is frustrating as all hell.
Considering that I really don't want to lose all my ratings, anime, friends, etc. because of a crappy reason like this, I'd really, REALLY appreciate if a mod replied to me and got back with me on this?


try PMing Kineta since she is the database administrator
Sep 13, 2013 8:40 PM

Offline
Nov 2012
65
I'm still getting randomly logged out at times but it's happening much less often now.
Sep 13, 2013 9:40 PM

Offline
Aug 2009
983
Sep 13, 2013 10:50 PM
Offline
Aug 2013
2
Thanks for fixing the problem.
Sep 14, 2013 1:51 AM

Offline
May 2012
59
so I can login with my phone again

~SUGOI

Sep 14, 2013 8:20 AM

Offline
Aug 2012
16
I'm still having the random login issue.
Sep 14, 2013 8:38 AM

Offline
Dec 2011
276
I've not been getting logged out!!

Thanks for all the hard work ~
Sep 14, 2013 11:01 AM

Offline
Jan 2013
49
Changing my password now. Thank you
Sep 14, 2013 1:01 PM

Offline
May 2010
3518
tsubasalover said:
Thank you for your extremely hard work.
"Wait for the signal, and I'll meet you after dark"
Sep 14, 2013 1:10 PM

Offline
Feb 2012
1
Changed my password here and also on Hummingbird to be safe, does anyone know of any other sites that might have been effected?
Sep 14, 2013 1:12 PM
Manga Moderator
🖤🖤🖤

Offline
Sep 2012
988
I haven't been logged out for a few hours now, so I think it's safe to say that it won't happen anymore. Thanks for fixing this! :)


thanks to my lovely Secret Elf Santa
for the forum set~
(*’∀’人)♥
Sep 14, 2013 1:31 PM

Offline
Feb 2008
257
Hmm, it still logs me out though after an hour of logging on.
Sep 14, 2013 1:56 PM

Offline
Oct 2010
84
changed my password. thanks for the updates and everyone's hard work. :3 to be honest, i have a pretty big list and i use this list to clear off some of my "memory" in my brain, haha. but anyway...

now, if we could only find out why this happened.
blog.::.patreon.::.

Sep 14, 2013 8:43 PM

Offline
Sep 2009
146
PrOxAnto said:
I can log-in, even though I get randomly logged out at times

ryshin said:
getting tired of log in... -_-

me too..

Xinil said:
We highly recommend that you change your password as soon as possible, to ensure that your profile and data aren't compromised.
Starting on September 20, we will no longer be able to restore profiles for users who have not changed their password since August 22. It takes a lot of work to restore hacked profiles, and we would rather put that effort into security improvements that can benefit everyone.


ok, I'll change my password..
Thanks..
Sep 14, 2013 10:05 PM

Offline
Jul 2013
2894
I still keep getting logged out but it's slower now. Changed my password. Thanks for trying to keep our profiles safe.
Sep 14, 2013 11:19 PM

Offline
Nov 2009
15
I keep logging out every ten minutes, I clear the cookies but nothing changes.

location:. Istanbul / Turkey
Browser: Chrome
Sep 14, 2013 11:30 PM

Offline
Jul 2009
3344
finally i was able to login after 2 weeks of waiting.

change my password, will back up my list ASAP!

thanks for the updates, though i suggest you should have put this announcements as part of news since i can't see them if i'm not logged in.
Sep 15, 2013 12:29 AM

Offline
Aug 2013
516
thanks it worked for me too :-p
Sep 15, 2013 2:15 AM

Offline
Jan 2011
2839
I would love it if MAL supported SSL, even a self-signed certificate would be fine. Of course it would be optional to prevent everyone's browser from crying, but one could just add an exception.
A lot of IRC servers do the same with self-signed SSL certificates.

Is that an option at all or are we going to send password unencrypted for eternity?
I almost never read discussions after I made my post, if you want to reply PM me or post on my profile page.
Pages (3) « 1 [2] 3 »

More topics from this board

» [Challenge] You Should Read This Manga 2024 ( 1 2 3 4 5 )

Kineta - Feb 23

206 by Aerixo »»
2 minutes ago

» Try MAL's New Mobile Site! ( 1 2 3 4 5 ... Last Page )

Xinil - Feb 15, 2015

422 by Hayukoo »»
Today, 8:30 AM

» Planned 5hr Maintenance, Thursday April 25 @ 1am-6am PT

Kineta - Yesterday

0 by Kineta »»
Yesterday, 8:10 PM

» New Site Update: Peak Anime 🗻 ( 1 2 3 4 5 )

Kineta - Mar 31

213 by Lancelot73 »»
Apr 21, 4:28 AM

» Heavenly Easter Delusion: Devil and Dolce ( 1 2 3 4 5 ... Last Page )

Kineta - Mar 27

3332 by Terra_strong »»
Apr 17, 8:26 PM
It’s time to ditch the text file.
Keep track of your anime easily by creating your own list.
Sign Up Login