Account security compromised

Questions and Answers : Preferences : Account security compromised
Message board moderation

To post messages, you must log in.

AuthorMessage
Bournecruncher

Send message
Joined: 30 May 99
Posts: 1
Credit: 1,770,548
RAC: 0
United Kingdom
Message 20992 - Posted: 1 Sep 2004, 16:24:14 UTC

It appears that boincstats.com not only has access to project data, but also to individual accounts. It publicly displays the BOINC Cross Platform Identifier (password), thus enabling any internet user to access and manipulate any BOINC/seti@home user account. How can this opening for possible abuse be plugged?
ID: 20992 · Report as offensive
Profile Keck_Komputers
Volunteer tester
Avatar

Send message
Joined: 4 Jul 99
Posts: 1575
Credit: 4,152,111
RAC: 1
United States
Message 21107 - Posted: 1 Sep 2004, 20:30:59 UTC

The cross project ID is not your password allthough they are in the same format so it is easy to get confused.

John Keck -- BOINCing since 2002/12/08 --
ID: 21107 · Report as offensive
Heffed
Volunteer tester

Send message
Joined: 19 Mar 02
Posts: 1856
Credit: 40,736
RAC: 0
United States
Message 21129 - Posted: 1 Sep 2004, 21:04:34 UTC

Yes, the CPID is benign...

ID: 21129 · Report as offensive
paul milton
Avatar

Send message
Joined: 24 Feb 03
Posts: 56
Credit: 73,265
RAC: 0
United States
Message 22999 - Posted: 6 Sep 2004, 17:07:55 UTC - in response to Message 21107.  

> The cross project ID is not your password allthough they are in the same
> format so it is easy to get confused.
>
John Keck -- BOINCing since 2002/12/08 -- <a> href="http://www.boinc.dk/index.php?page=user_statistics&project=sah&userid=138092">
>

what password? last time i checkd the boinc account dosent have a password, and if it dose i must have missd that step!
ID: 22999 · Report as offensive
Vorik
Volunteer tester

Send message
Joined: 29 May 02
Posts: 19
Credit: 53,983
RAC: 0
Austria
Message 23012 - Posted: 6 Sep 2004, 17:41:20 UTC
Last modified: 6 Sep 2004, 22:17:51 UTC

I think he means the account ID. That is what you need to change preferences. The cross project ID is something else.
ID: 23012 · Report as offensive

Questions and Answers : Preferences : Account security compromised


 
©2024 University of California
 
SETI@home and Astropulse are funded by grants from the National Science Foundation, NASA, and donations from SETI@home volunteers. AstroPulse is funded in part by the NSF through grant AST-0307956.