July 6, 2005

  • UPDATE ON SIGNIN SECURITY

    It’s been a few weeks since we launched our new Signin Security, so thought we’d post an update.

    It’s definitely working – there’s been a dramatic reduction in
    account hackings.  We’re doing cartwheels over this news! 
    That said, all this added security has come at a price.  At this
    moment, there are a few dozen users locked out of Xanga. 
    Those accounts will be unlocked in the next 15-30 minutes, but it’s
    definitely annoying for these users.  We investigated the
    root cause of the lockouts, to see if there was any common pattern -
    and were surprised to discover most of them were caused by the same
    issue!

    It turns out that 99% of the time, a locked out Xangan has *just*
    changed their password in the last day or two.  In retrospect,
    this makes sense - I can’t count the number of times I’ve changed
    my password, and then the next time I went to sign in… I typed in the old password! 
    I guess it takes time for your fingers to “learn” the new
    password?  Anyway, with this new security system…  every
    time you try and signin with the old password more than 5x in a row,
    you’ll get locked out for another half-hour!    So please be careful.

    Basically, if this is happening to you… please make sure you’re
    using your latest and greatest password!  There’s a more official
    writeup of all this here.

    How is the new signin security working for you?  Please let us know below.  Thanks!

Comments (459)

Post a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *