DBraz Posted Wednesday at 07:42 PM Posted Wednesday at 07:42 PM Hey guys, I don’t post or visit this site much these days. Not for a lack of love. Life… Anyway, I hope you are all doing well. I play and record with my Hamer’s and Shishkov’s regularly. But I am not currently selling any of them. Someone seems to have taken advantage of my absence and posted that they are selling guitars. It looked like me, but it wasn’t me. My account has now been reset and this message is a polite point in case any of you were mislead. Dbraz 6 4 Quote
cornjulio Posted Wednesday at 08:08 PM Posted Wednesday at 08:08 PM Mad! Was that the brief FS thread for an Ultimate? Quote
Dave Scepter Posted Wednesday at 08:31 PM Posted Wednesday at 08:31 PM (edited) Wow, I almost bit on that Ultimate 😳 Was your PM hacked as well? Edited Wednesday at 08:32 PM by Dave Scepter Quote
cmatthes Posted Wednesday at 08:36 PM Posted Wednesday at 08:36 PM 3 minutes ago, Dave Scepter said: Wow, I almost bit on that Ultimate 😳 Was your PM hacked as well? It appears that DBraz' entire account was hacked by a Moroccan fraudster. That's been shut down and he should be all good now, but definitely a reminder to change your passwords here, there and everywhere at least as often as when you change the batteries in the home smoke detectors! 2 4 Quote
velorush Posted Wednesday at 08:52 PM Posted Wednesday at 08:52 PM 13 minutes ago, cmatthes said: a Moroccan fraudster. But seriously, sorry for your trouble and glad it got resolved. 5 Quote
DBraz Posted yesterday at 06:28 AM Author Posted yesterday at 06:28 AM Thanks guys. And, for the record, if I had an Ultimate I certainly wouldn’t sell it. I still adore my Shishkov’s. Super-C 1 is fast approaching 10 years old and is as amazing as it ever was. Both Super-C’s are incredible in their own way. 8 Quote
Spinaltap Posted yesterday at 09:54 AM Posted yesterday at 09:54 AM a Moroccan fraudster, it's almost funny, till it happens to you. Good to hear it wasn't a $$ fix 3 Quote
Saul Goodman Posted yesterday at 10:53 AM Posted yesterday at 10:53 AM I use really strong passwords like, qwerty123, password123, and bingo. I've never changed a password. Never been hacked. 1 3 Quote
kizanski Posted 21 hours ago Posted 21 hours ago 18 hours ago, cmatthes said: ...at least as often as when you change the batteries in the home smoke detectors! You're supposed to change those? 2 Quote
diablo175 Posted 20 hours ago Posted 20 hours ago (edited) 19 hours ago, cmatthes said: It appears that DBraz' entire account was hacked by a Moroccan fraudster. That's been shut down and he should be all good now, but definitely a reminder to change your passwords here, there and everywhere at least as often as when you change the batteries in the home smoke detectors! Oops. 😬 Ah well, at least I've now changed my password here: M0roc@nFr@ud$ter. They'll never guess it. Edited 20 hours ago by diablo175 4 Quote
velorush Posted 20 hours ago Posted 20 hours ago In all seriousness, if you've listened to the guys who came up with that 'one capital letter, one number, one lower case letter' paradigm, they've totally gone back on all that for more than five years. What they're recommending now are pass phrases (though I suppose the passkey will do away with all of this). There's a great pass phrase generator we use to great effect: Correct Horse Battery Staple | Generate Secure Memorable Passwords Give it a try. They're infinitely (well, almost) easier to remember and equally as difficult to hack. 1 1 Quote
mrjamiam Posted 17 hours ago Posted 17 hours ago 2 hours ago, diablo175 said: Oops. 😬 Ah well, at least I've now changed my password here: M0roc@nFr@ud$ter. They'll never guess it. 2 hours ago, velorush said: In all seriousness, if you've listened to the guys who came up with that 'one capital letter, one number, one lower case letter' paradigm, they've totally gone back on all that for more than five years. What they're recommending now are pass phrases (though I suppose the passkey will do away with all of this). There's a great pass phrase generator we use to great effect: Correct Horse Battery Staple | Generate Secure Memorable Passwords Give it a try. They're infinitely (well, almost) easier to remember and equally as difficult to hack. Not to be argumentative, but why can't it be both? A two-character password that only uses lower-case alphabetic characters (standard English keyboard, sampling with replacement) has 262 or 676 possibilities. If you allow upper-case also (that is, shift+letter), then you have 522 or 2704 possbilities. If you also allow numbers 0-9, then you have 622 or 3844 possibilities. Now allowing the shift+number characters too, you have 722 or 5184 possibilities. If you stretch the password to three characters, and following the same scheme, you have 263 or 17576, 523 or 140608, 623 or 238328, and 723 or 373248 possibilities. Using a passphrase, like "takesonetoknowone", increases the exponent: something to the 17th in this example. In fact, in this example, I used only lower-case letters, so it would be one of 2617 or 1,133,827,315,385,150,725,554,176 possibilities (unless I mis-entered something on my calculator). Obviously this is a much bigger number than you get from a two- or three-character password, but the same principle applies: Allowing more characters increases the number of guesses it takes to cover all possibilities. When I hear "they used to say that but now they are saying this" I wonder what they will be saying next. If it's a matter of just increasing the number of possibilities, adding other characters is a way to do that, if we live in a world where the password protected site allows thousands and millions and kajillions of consecutive guesses until the right one is finally entered. Sites can do everyone a favor and implement a lockout or at least a cooling-off period when a number of incorrect entries are tried. Starting with a passphrase and then applying some creative misspelling (to counter the use of dictionaries in the guessing game) and alternative characters makes the number of possibilities skyrocket. I think it used to be that the worry was that if you wrote the password down, someone would access it and be able to log in. You'd have to judge your exposure to that, but in my case it's just my wife and me here at home, and in fact I'm at the age where I have an estate plan and part of that is to have passwords available to my wife or whoever survives me or us, so they have to be written down. I can make them as wacky as I want, and reference them when I need them. This is especially useful if the site that requires a hard-to-crack password also requires me to change it yearly, quarterly, or whatever. Passphrases might be easier to remember, but is what I remember the current one, or that cool one I used a couple of years ago? Of course I don't leave the passwords right at the keyboard. And if there is a key-logger malware on my computer, it doesn't make any difference how cute I get with the passwords, so I use anti-malware software. Ultimately your security is your responsibility, and good security is inconvenient. 1 1 Quote
scottcald Posted 17 hours ago Posted 17 hours ago 22 hours ago, cmatthes said: It appears that DBraz' entire account was hacked by a Moroccan fraudster. That's been shut down and he should be all good now, but definitely a reminder to change your passwords here, there and everywhere at least as often as when you change the batteries in the home smoke detectors! I knew this guy was no good: 2 Quote
velorush Posted 17 hours ago Posted 17 hours ago (edited) 39 minutes ago, mrjamiam said: Not to be argumentative, but why can't it be both? Not argumentative at all. The business of one special character, one capital letter, etc. was proposed by a dude named Bill Burr back in the '80's working for the National Institute of Standards and Technology. I happened on an interview of him from some time in the past twenty years wherein he said he regretted what his simple white paper had become, especially the part about changing passwords every 90 days. The whole theory behind the practice was to prevent machines guessing the passwords. He said 1. the standard was only a discussion and not based on any hacker data, and 2. implementation had resulted in lower overall security because the difficulty in remembering passwords thus configured along with the 90-day expiration all but forced users to write them down and keep them where they were easily found by others. Additionally, the practice put users in the habit of using easily guessed passwords with simple modifications such as capitalizing the first letter and adding an exclamation point on the end. Pass phrases are now recommended (at least by the NIST) because they are more or less random (see the Battery Horse Staple example), more easily remembered and can be significantly longer (as your probabilities post points out). If anyone is interested in completely nerding out on this, the most recent NIST publication (26 August 2025) can be found here: NIST Special Publication 800-63B. I will say I administer a network of around thirty users and those who have implemented pass phrases seem to be far more satisfied with the experience. Mostly because, given the complexity available, they aren't required to change them every 90 days. ETA: the implementation of Passkeys (where a linked device provides biometric confirmation of identity) seems to be the way of the at least short-run future. I have around a dozen sites (my iPhone says I have 15) sites administered this way and it is extremely convenient - so long as I have my iPhone with me. ETAA: quantum computing, of course, will render all of this moot. 🙃 Edited 17 hours ago by velorush 3 Quote
mrjamiam Posted 15 hours ago Posted 15 hours ago It's certainly a spy-vs-spy situtation, if you remember the Mad magazine cartoon. If you don't, it's alternating advances in offense and defense. I like analogies, and since security has multiple applications, here are a couple: When hiking in bear country, make sure you can outrun at least one of the folks you're with - you can't outrun the bear, but if you outrun someone else, the bear might not pass them up and come for you. And I've had a couple of experiences with the local cops addressing a community group about Neighborhood Watch, and both times it came down to this, very roughly paraphrased: Criminals gonna crime. What you wanna do is make your neighborhood so obviously nosy that the criminals say "forget this place, I'mma go on down the road". The general idea is to be a harder target than some or many, and you'll be less likely to be the victim. But there will always be victims. 1 Quote
Saul Goodman Posted 14 hours ago Posted 14 hours ago 51 minutes ago, mrjamiam said: The general idea is to be a harder I'm always harder than the next guy. Just ask Rufus. Quote
Biz Prof Posted 10 hours ago Posted 10 hours ago This is probably a good time to divulge that I am actually an exiled Nigerian prince. Great political unrest put my family in danger and forced me to leave my homeland. If you would be so kind as to assist me, I would like to transfer $1.5 million U.S. to your account so that I might bring my family safely to... ....aw, Hell. Just kidding. I hate grifters. 1 Quote
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.