Forum Settings
Forums
New
Jun 11, 2013 2:55 PM
#1
Overlord

Offline
Nov 2004
5752
Due to increasing attacks on MAL's servers and security, we've had no choice but to revert the removal of cookie IP restriction (last week we removed IP addresses attached to cookies.)

We're well aware that this causes many issues for users outside of the U.S. and please rest assured we're actively looking at newer and better techniques to combat growing and future security concerns.

I don't have an ETA yet on when we can be back to MAL without IP restriction, but we're diligently working on an alternative login system.

Sorry for the inconvenience everyone.
Pages (3) [1] 2 3 »
Jun 11, 2013 3:03 PM
#2
Lead Admin
Faerie Queen

Offline
Aug 2007
6269
For users from Singapore, this has proven to be a temporary solution:
mikhailn said:
1. in Google Chrome -> Settings -> Show Advanced Settings -> Change Proxy Settings
2. LAN Settings -> tick Use Proxy Server for your LAN
3. Address: proxy.singnet.com.sg
Port: 8080

Other users who cannot stay logged in for more than a few page loads are recommended to use a static proxy.

If you cannot login at all, try clearing your cookies. If this still doesn't work, try unchecking the "Keep me logged in" button. It seems (especially with Chrome) this is a problem.
KinetaJun 19, 2013 2:27 AM
Jun 11, 2013 4:25 PM
#3
Observer

Offline
Nov 2007
5283
For people having trouble to login, removing your cookies from your browser would be a good idea too.
bla bla bla
The endless debate between fans and haters. At one point, after spending a lot of time on MAL, you just realize it's totally pointless.
Niko-kun said:
On MAL, everyone who has used the lame rating system becomes a critic and an intellectual by default, haven't you heard?
Jun 11, 2013 5:02 PM
#4

Offline
Apr 2007
24
On Chrome it gave me some login issues after I closed the browser, but no problems on Firefox so far. (Holland, Europe)
Present day....Present Time....hahaha
www.Tribute2Trance.nl
Jun 11, 2013 6:25 PM
#5

Offline
Oct 2012
627
Lainfan said:
On Chrome it gave me some login issues after I closed the browser, but no problems on Firefox so far. (Holland, Europe)


This, i have problem too with chrome.
Jun 11, 2013 6:57 PM
#6

Offline
Sep 2009
504
Use https for more security? The overhead is increased a lot, but the information is protected. The whole session being https will protect cookies too, which is recommended since sensitive information is on cookies. OTP cookies and hashed cookies are other alternatives.

If those solutions don't work maybe use digital certificates with PKI?

Just throwing ideas out haha.


Jun 11, 2013 8:14 PM
#7

Offline
Aug 2011
1350
Don't have a problem with firefox.




**☾**
Jun 11, 2013 9:05 PM
#8

Offline
Mar 2008
347
Kind of annoying getting logged out all the time but I'll deal with it~
Jun 11, 2013 9:44 PM
#9

Offline
Feb 2009
83
What I want to know is why would someone even bother attacking MAL. Granted better security measures are always a good thing, but why would someone waste their time attacking this site?


Jun 11, 2013 9:47 PM

Offline
Jan 2013
327
ueda said:
Kind of annoying getting logged out all the time but I'll deal with it~


no shit buddy, dont think you have a choice. ( I apologize sounding rude. your comment just came off sounding very condescending to me.)

ANYWAYS, I thought this problem was just fixed? On this thread which was just locked http://myanimelist.net/forum/?topicid=529228&show=720, 2 days ago was posted it was fixed. Or is this something new?

Edit: Nvm, I see the usage of the word "revert." Im guessing the change was reverted then?
dextronautJun 11, 2013 9:55 PM
Jun 11, 2013 9:59 PM

Offline
Mar 2010
969
It's not that much of a issue, I'm more than happy to deal with removing cookies before log-ins as long as MAL is safe~c:

Jun 12, 2013 12:16 AM
Offline
Jul 2018
564533
Ah, finally. I've been getting logged out every hour these past few weeks.
Jun 12, 2013 12:41 AM

Offline
Nov 2012
1755
Diablofan said:
What I want to know is why would someone even bother attacking MAL. Granted better security measures are always a good thing, but why would someone waste their time attacking this site?

maybe so MAL get MAssive lag (IFKWIM)
Jun 12, 2013 1:15 AM

Offline
Apr 2007
92
You guys say it's a problem for people outside of the US... but I think it's also a problem for within the US unless you guys think that Hawaii IP is outside the US... but it's driving me nuts! I've cleared out my cookies twice, and then I have to re-log into everything -_-... (Is this just a Chrome thing, or with other browsers too?)
Jun 12, 2013 3:03 AM

Offline
Sep 2007
1917
Until now I've actually had close to no problems. The only thing I noticed was that in my hometown I keep getting logged out, while in my current city at the other side of the country I stay logged in all the time. I don't know what that means, however I thought the information could come in handy for the people working on this problem. :)

(I live in the Netherlands btw.)
Jun 12, 2013 5:19 AM

Offline
Jun 2013
6
ο well this explains a lot but it seems ok for me now , thanks for your hard work :)
[/url]
Jun 12, 2013 5:20 AM

Offline
May 2013
304
oohhh thats why I always get logged out with chrome.... well wish to get it fixed as soon as possible. :)
Tch.
Jun 12, 2013 5:35 AM
Offline
Jun 2011
81
MAL user from Philippines here. I think it's good that I am not (I think) affected with this problem ._.
Jun 12, 2013 5:37 AM

Offline
Apr 2011
252
hmm the only problems i have is when i close Safari and relaunch it, it asked me to log back in...everytime. But i'm kinda use to it now because it's being doing this to me for more than 7months.

Besides that...no problems here (Perth, Australia)
Jun 12, 2013 6:05 AM

Offline
Sep 2008
152
I have to login once again whenever I closes my Firefox browser, even though I ticked the 'remember me'
NB: I am from Indonesia
Jun 12, 2013 6:27 AM
Offline
Nov 2011
1940
iharunatsu said:
MAL user from Philippines here. I think it's good that I am not (I think) affected with this problem ._.
Oh wow, I am from the same country yet mine's not fixed. But I guess it'll be fine sooner or later.
Jun 12, 2013 6:55 AM

Offline
Dec 2012
36
Nothing changed for me, I always used chrome and had to log in whenever I visited MAL and since it's still like this, I don't really see changes. (Germany, Europe)
So you say you're under a curse? So what? So's the whole damn world. - Jigo
Jun 12, 2013 8:58 AM

Offline
Aug 2011
1350
Eternia said:
I have to login once again whenever I closes my Firefox browser, even though I ticked the 'remember me'
NB: I am from Indonesia


Same country and province.
Same browser too.

Maybe it's just your connection? I used broadband and dial-up connections, and hardly getting logged out when i'm using dial-up




**☾**
Jun 12, 2013 9:40 AM

Offline
Oct 2012
229
hehe. No problems in China.(thank god)
Memories may fade, but that doesn't mean there isn't any point in making them.
Jun 12, 2013 10:03 AM

Offline
Jan 2012
67
I have the same problem with my laptop, using wireless connection, but I hope you fix it soon


PS. does this problem have anything to do with the Time (days) not updating? Mine hasn't been working for about a week now
Do you think this is a motherfucking game?
Jun 12, 2013 12:00 PM

Offline
Jul 2010
40
Nooooo!!! And it was so nice for like a week...

At least there is MALUpdater.
Jun 12, 2013 5:18 PM
Offline
Jul 2010
2493
I've been having this "we couldn't keep you logged in" problem for several weeks (months?) already, in France and maybe in Canada as well. Not such a big deal to me, but that seems to happen randomly (I'm using Opera)...
Jun 12, 2013 9:34 PM
Photojournalist

Offline
Apr 2007
660
Cloudflare. Nuff said.
Jun 13, 2013 4:41 AM

Offline
Sep 2008
152
Yoshiteru said:
Eternia said:
I have to login once again whenever I closes my Firefox browser, even though I ticked the 'Remember Me'
NB: I am from Indonesia


Same country and province.
Same browser too.

Maybe it's just your connection? I used broadband and dial-up connections, and hardly getting logged out when i'm using dial-up

Different province. :-)
I dunno.
Today I have tried Firefox, Chrome, Opera, Internet Explorer, and it's all the same. I was logged out automatically whenever I closed all MAL's page, as if MAL hates me or something. For provider, I have tried Speedy, Telkomsel, and Tri. I haven't tried XL yet.
Jun 13, 2013 11:55 AM

Offline
Jun 2007
183
It's annoying , but that's about it, no dealbreaker. Keep up the good work. :)
Jun 13, 2013 12:27 PM

Offline
Aug 2007
4530
My problem isn't the login issues, its random bans i've been receiving these past few days. It tends to be around 2 hours maximum in length and only in the evenings (PST).
MaoraJun 13, 2013 2:38 PM
Jun 13, 2013 1:42 PM

Offline
Dec 2008
1092
Poland, firefox. It was ok for a few days but now the problem returned :(
New profile design sucks.
Jun 13, 2013 2:31 PM

Offline
Jul 2012
2652
I'm in the US and this problem is occurring about once a day for me. Just pointing that out.
Jun 13, 2013 5:39 PM

Offline
Mar 2013
59
okkyblight said:
Lainfan said:
On Chrome it gave me some login issues after I closed the browser, but no problems on Firefox so far. (Holland, Europe)


This, i have problem too with chrome.


Same, and I'm in the States. Tried clearing everything, still having issues daily.
Jun 13, 2013 6:22 PM

Offline
Jan 2011
172
United States, Chrome.

Having to login daily.
"You watch too much."
"I don't watch enough."

Jun 14, 2013 2:25 AM
Offline
Jun 2012
2974
problem has been unsolved for 6 months :(
Jun 14, 2013 7:48 AM

Offline
Apr 2011
7024
MAL user from the PH here. So far, I've not encountered this problem on my IE browser, but the fact that MAL is under these kinds of cyber-attacks is still bothersome...
Jun 14, 2013 10:38 AM

Offline
Jul 2010
1027
Not that big of a problem. Chrome is helpful.
Jun 14, 2013 11:23 AM
Offline
Jul 2010
188
Diablofan said:
What I want to know is why would someone even bother attacking MAL. Granted better security measures are always a good thing, but why would someone waste their time attacking this site?

Plausibly because the security level is extremely low (so even people with low tech knowledge can attempt it) and the reward (the "lulz" of trolling anime/manga fans) is sufficient for the effort made.
Jun 14, 2013 1:43 PM

Offline
Apr 2013
174
THIS IS UNACCEPTABLE!!!

How on earth log-in cookies are related to stoppping attacks? Add a captcha confirmation or something... There are MILLIONS of solutions, other than this joke! I haven't seen a single website on earth that is attacked and they found solution in screwing up cookies... You're either bad programmers or very, very, VERY lazy.

YOU'RE NOT SORRY IF YOU'RE NOT USING THE SITE THE WAY WE USE IT!

EITHER USE IT THAT WAY FOR A WHILE AND THEN COMMENT ABOUT IT, OR FIX THIS!
Open to chat about any storytelling related subject as long as it's clever and respectful.
Myanimelist
Jun 14, 2013 6:35 PM

Offline
Sep 2009
504
Prequel said:
THIS IS UNACCEPTABLE!!!

How on earth log-in cookies are related to stoppping attacks? Add a captcha confirmation or something... There are MILLIONS of solutions, other than this joke! I haven't seen a single website on earth that is attacked and they found solution in screwing up cookies... You're either bad programmers or very, very, VERY lazy.

YOU'RE NOT SORRY IF YOU'RE NOT USING THE SITE THE WAY WE USE IT!

EITHER USE IT THAT WAY FOR A WHILE AND THEN COMMENT ABOUT IT, OR FIX THIS!


Clearly someone doesn't understand how cookies can be used to hack a website. I have done it before, it isn't hard.


Jun 15, 2013 3:19 AM

Offline
Apr 2013
174
xuezhi said:

Clearly someone doesn't understand how cookies can be used to hack a website. I have done it before, it isn't hard.


I repeat again, I haven't seen a SINGLE (non-retarded) website on earth that is attacked and they found solution in screwing up cookies and f***ing their members' life up.

Clearly someone doesn't know sites any more than 10.
Open to chat about any storytelling related subject as long as it's clever and respectful.
Myanimelist
Jun 15, 2013 3:22 AM

Offline
Jan 2009
92920
as others have pointed out why not use HTTPS or even CLOUDFLARE service
Jun 15, 2013 5:08 AM
Offline
Jul 2018
564533
Diablofan said:
What I want to know is why would someone even bother attacking MAL. Granted better security measures are always a good thing, but why would someone waste their time attacking this site?


Very true, so pathetic of whoever it is attacking an innocent anime listing site :(
Jun 15, 2013 6:43 AM
Offline
Mar 2010
2
Site is unusable because of the cookie issue. Oh well, I was in the process of migrating to AniDB anyway.
Jun 15, 2013 8:04 AM

Offline
Jul 2011
3921
j0x said:
as others have pointed out why not use HTTPS or even CLOUDFLARE service

Yup, why not? :/

"A half moon, it has a dark half and a bright half, just like me…", Yuno Gasai
Jun 15, 2013 12:03 PM

Offline
Sep 2009
504
Prequel said:

I repeat again, I haven't seen a SINGLE (non-retarded) website on earth that is attacked and they found solution in screwing up cookies and f***ing their members' life up.

Clearly someone doesn't know sites any more than 10.


Ok, buddy whatever you say. I am not gonna bother getting in a heated debate with you, especially someone who says a cookie problem messes up their life.


Jun 15, 2013 5:33 PM

Offline
Dec 2012
4876
Xinil said:
Due to increasing attacks on MAL's servers and security, we've had no choice but to revert the removal of cookie IP restriction (last week we removed IP addresses attached to cookies.)

We're well aware that this causes many issues for users outside of the U.S. and please rest assured we're actively looking at newer and better techniques to combat growing and future security concerns.

I don't have an ETA yet on when we can be back to MAL without IP restriction, but we're diligently working on an alternative login system.

Sorry for the inconvenience everyone.

Do not worry. I know all of the staff are working hard on it. I hope MAL will get better & become the best online social networking service for anime/manga/something similar fans.
I like anime.
Jun 16, 2013 1:49 AM

Offline
Dec 2009
64
I recommend to use captcha. Anyways, I have problem with ff from Europe.
Jun 16, 2013 9:03 AM

Offline
Apr 2012
66
xuezhi said:
Use https for more security? The overhead is increased a lot, but the information is protected. The whole session being https will protect cookies too, which is recommended since sensitive information is on cookies. OTP cookies and hashed cookies are other alternatives.

If those solutions don't work maybe use digital certificates with PKI?

Just throwing ideas out haha.


what kind of attack exactly the server experiencing?
I think https only works for attack within request packets. And I think hardly any packets within MAL contain sensitive information.

By the way, mine works just fine.
Conected from Indonesia and uses firefox. only got logged out once yesterday or two days ago (I forgot).
Pages (3) [1] 2 3 »

More topics from this board

» [Challenge] You Should Read This Manga 2024 ( 1 2 3 4 5 )

Kineta - Feb 23

231 by ParadiseSukai »»
May 6, 11:57 PM

» Try MAL's New Mobile Site! ( 1 2 3 4 5 ... Last Page )

Xinil - Feb 15, 2015

424 by nothing_ness »»
May 5, 8:51 PM

» Moderators Wanted! Accepting applications for all positions

Kineta - Apr 26

0 by Kineta »»
Apr 26, 6:46 PM

» Planned 5hr Maintenance, Thursday April 25 @ 1am-6am PT

Kineta - Apr 22

0 by Kineta »»
Apr 22, 8:10 PM

» New Site Update: Peak Anime 🗻 ( 1 2 3 4 5 )

Kineta - Mar 31

213 by Lancelot73 »»
Apr 21, 4:28 AM
It’s time to ditch the text file.
Keep track of your anime easily by creating your own list.
Sign Up Login