We've finally finished a several month long project today by reworking the back end of Metafilter to bring site security practices up to date. The new login system
we were testing yesterday is now live for everyone. And you can even change your password now, after 8 years of everyone asking!
Here are the highlights:
* All logins via SSL here:
https://login.metafilter.com/
* More secure cookies set on login
* New password change form
* Forgotten password reset (for folks with verified emails on file)
You're also now required to give your password when changing sensitive data, like altering your email address or closing your account. And both of those happen over SSL as well, so your password is never sent in the clear.
You can change your password by clicking the "change password" link at the top of
your site preferences.
Behind the scenes, passwords are stored as unique hashes so your password is a secret between you and various hashing mechanisms. There are bound to be a few bugs with an major overhaul like this (yesterday's testing solved most of it), so please report any problems here or
via email.
Overall, login/cookie stuff is now way, way more secure. If anyone were to ever (worst-case scenario) snoop your transmissions over the wire or steal your cookie details, they'd never be able to change your password or email (so they can't "steal" your account) or close your account. That wasn't the case previously.
posted by dmd at 4:30 PM on November 29, 2007