Changing Sky Password

0 views
Skip to first unread message

Gundenia Ransbottom

unread,
Aug 4, 2024, 10:29:25 PM8/4/24
to nikrisice
IfI ever change the password of my account I was expecting the need to update it everywhere I use it. If, by any change, somebody uses a Desktop/Mobile client and I change my password, this person would be able to keep on using it without problems.

Did this post not resolve your issue? If so please give us some more information so we can try and help - please remember we cannot see over your shoulder so be as descriptive as possible!


Its not a security flaw - clients that are connected only use the password for the first time they connect, after that they use a token that they receive on that first authentication. Same goes for all third party apps.


I see the point, but I don't agree. Specially since I don't have any option to disable it. The first thing you do when a device is stollen, a security breach happens, is changing your passwords. If the person has your connected device it will not change a thing.


If someone steals your password, no devices are affected anyway as you do not have to enter your account password to use any of them - mobile devices allow you to set a separate PIN, but your account password is never required.


I should have the option to revoke all access to my account as soon as I change the password. I'm pretty sure that it's not hard and you could keep using it the way it is and I would change to my way. Everybody would be happy.


Indeed I could change my password daily, which would be a bummer, but since I use a password manager (let's say it is the only way to use secure password updated frequently for several different services) to type again a password for a specific client is not even close to be problematic.


so for example: if a thief stole my dropbox password, and before I even notice that, he/she might already install the sync app in his/her pc. now after I change my drobpox password, so the thief can still see the sync the files from his/her pc?


Richard P, if yo still don't think that is a security issue, then I will be shocked. are you in fact dropbox employee? or you just a super dropbox user like us? no offense, but I need email dorpbox support team for the security concern if you are not employee.


It looks to me that the concern one of the users is having is that there is no security option when changing the password so that it will have to be re-entered when using a device. But if I am understanding correctly, that security exists if you unlink the other device(s); a new password will have to be entered for the device to be registered again.


My question is if you unlink the device and then enter the new password from the unlinked device, will it have to re-sync all files? Will files be duplicated? Or will Dropbox recognize all the old files on the device and sync only the newer or updated ones?


The site is secure.

The ensures that you are connecting to the official website and that any information you provide is encrypted and transmitted securely.


In The Security of Modern Password Expiration: An Algorithmic Framework and Empirical Analysis, researchers at the University of North Carolina at Chapel Hill present the results of a 2009-2010 study of password histories from defunct accounts at their university.


Organizations should weigh the costs and benefits of mandatory password expiration and consider making other changes to their password policies rather than forcing all users to keep changing their passwords.


An accurate and up-to-date email address, and/or phone number ensure you never lose access to your X account. There are a few ways to change your password, and keeping this information up to date simplifies resetting your account or password.


Note: Resetting your password will log you out of all your active X sessions. Additionally, password reset via text message isn't available to accounts that are enrolled in login verification. You can only reset your password through email.


If you frequently receive password reset messages that you did not request, it may be a good idea to turn on the Password reset protection in your account settings and set up two-factor authentication.




Hi - I have a dropbox account which I share with a few people. In effect a single dropbox login and a few people know the password. Some of these access it via the dropbox App. I have changed the password on the main dropbox account, thinking this will stop them accessing it, but a number still seem to have access to it? Bit concerned as I though once the password was changed they would lose their access.


Thank you for your help. That's really poor security though isn't it? Normally if you give someone access to your account by sharing the password, if you then change it they should not be able to get back into the account? Come on Dropbox that's a massive security hole?


Normally you wouldn't give somebody access to your account though - its basic security. Would you give them access to your email? No. By giving them your password they could do ANYTHING at all to your account and you'd have no come back at all - permanently delete files, remove your access, change the password/emails, anything. And as you've given them your security you have basically made them co-owner and allowed them to do it.


While I'm at it, an option to automatically unlink systems idle for a user settable time would be good - I just checked and I had 4 old cell phones and 6 old computers still linked but inactive - I should have an automatic method of cleaning this up.


To expand a bit more, the standard action if a security breakin is suspected is to change a password, but on dropbox, as currently configured that's useless - once a "bad guy" is in to your account, i.e. linked, changing a password does no good - you have to take the extra unlink step, which I would wager most users have never heard of.


But that leaves the data on your devices. If you unlink via the website then you can ask Dropbox to wipe any data on it. You cannot do that if its unlinked. Nor could you track lost / stolen devices.


Personally I disagree. Most modern syncing tools/similar set up programs work on secure tokens. Changing a password on 99% of iOS device applications does not cause the linked accounts to re-request it for example.


Most systems (e.g. windows) at least require a password entry on reboot - dropbox doesn't even do that - the old credentials are still valid across a reboot, at least on windows, and I suspect other platforms as well.


As far as other platforms not invalidating tokens when passwords change, that doesn't make it right - in fact, the right (i.e. secure) way to do this is to ask on password reset if the current tokens, links, etc. be invalidated. Just because other people jump off a cliff doesn't mean it's a good idea. The basic rule of security is to err on the side of too much authentication, not too little!


You are right about my auto unlink suggestion, but that's easily remedied - just add the option on the auto unlink to erase the data, and make it the default. In my case, it's irrelevant - all of these devices are known to be dead or upgraded to new identities.


Phone number not linked to account

If you haven't added a phone number to your account, you'll need to reset your password by email. After signing in, you can add a phone number at any time by going to your Account page and selecting Add phone number. If the phone number on your account is no longer valid, go to your Account page and select Change phone number.


If you pay for Netflix through a third party, or your subscription is included in a package, search our Help Center for the name of the third party to find the right article. Then see the "I'm having trouble signing in to Netflix" section for instructions.


You can use your mobile or desktop device to reset your NCID password or unlock your NCID account at any time. Please note, however, that all NCID accounts that are locked automatically unlock after 30 minutes.


Note: Employees of the University Police Department and other employees (including student employees) who use workstations that accept credit card payments have different password requirements than other faculty, staff, and students at Western. View the password requirements for UPD and PCI workstations users.


If you are working off-campus on a university-owned Windows computer, you will also need to sync the new password to your computer using the steps in this article: My computer accepts only my previous password


If you encounter the error where the page seems to 'reload' and kick you back to the start, open the page below in an Incognito, InPrivate or Private browsing window and continue from there by right-clicking the button and selecting "Open link in a new Incognito/InPrivate/Private browsing window". This is a known bug in the interaction between modern browser caching and that page.


Outside of the reasons discussed in Password Aging: Why We Change Our Passwords Regularly, the frequency at which we require users to change their passwords is determined by the state. Per University Policy U3000.07, we adhere to the Washington State Office of the Chief Information Officer (OCIO) Standard 141.10, Securing Information Technology Assets. In section 6.3.2 Internal Authentication, this standard requires that the password expiration period does not exceed 120 days.

3a8082e126
Reply all
Reply to author
Forward
0 new messages