Would be a bummer to see this board go, but I can understand the reasoning.
If it's going to be spammed (or all the convo be held between like, the same 3 people forever) then it'd be better to lock it down.
captcha isn't going to fix the spam problem
AFAIK there are websites/services dedicated to cracking captcha and providing tools for anyone to easily bypass it (big economical incentive there). captcha may evolve as time goes but since it's always
being cracked, there's not much you can do. not to mention the growing AI capabilities.
But if you do decide to archive K64, please do start over on a new board, like back in 2012. It would be ideal if all threads here could be ported to there.
what would be the point of that? why switch websites if you're going to port everything over? might as well keep this one then.
remember: duplicates are redundant. you're supposed to avoid them
no amount of security will help if people use 'qwerty' or '123456' as a password
idea: lock those accounts ahead of time? if bad actors can find people with those passwords, so can you
btw does this board not have password requirements? as much as I hate them they're kind of a necessity at this point. I know some websites that outright reject passwords containing overused strings like the ones you mentioned
here's a fairly thorough standard:
-must be at least 8 characters long
-must contain at least one letter, one digit and one special character (e.g. & or @)
there's no requirements for uppercase/lowercase in this one (I haaate those)
new SM64DS hackers still use this board
they do? I recall seeing only like, two posts in the SM64DS forums with no reply. it was rather depressing
I feel like if there's an active SM64DS hacking community, it's not here. there may be a Discord for it or something.
In that case, maybe a better encryption of the new Kuribo64?
the encryption isn't the problem.
this is the problem:
a compromised password is typically a password that was reused across websites, one of them lacking critical security features (e.g. storing passwords in plaintext) and subsequently getting hacked, thus leaking the unprotected passwords. bad actors will then try to check if the passwords they stole work on other websites.
Now I have passwords so complex even I don't know them!
you don't need to do that. just get a password that's complex enough not to be cracked just by looking up a dictionary or whatever. that's all you really need.
machine-generated passwords like the ones browsers give you are a PITA to type and overall unnecessary.
plus, your chances of having someone actually trying to hack your account are determined by how enticing your account looks. a Kuribo64 account is not a bank account, and you are not an admin. there's barely anything they could use to their benefit, so your account isn't enticing.
also, there's little incentive to try cracking passwords that are
at all complex so I surmise the people who have been hacked had template passwords like the ones
Arisotura mentioned.
Personally I would love to see the board stick around even with the little activity it gets (shoutouts to Staryu and kikilxve basically carrying the discussions), but I understand if it gets archived because I don't know if maintaining this board is necessarily a priority in your life, especially if it costs money to host (unsure about this specifically).
I don't think archiving would reduce hosting costs, since it still has to be hosted either way if archiving means "make read-only". I doubt
Arisotura would hand over the hosting to some other party to save costs, for security reasons
If Kuribo64 gets revived as a new board, it needs a new name too. I have a genius one. Nokonoko64!
ye ain't the first one to think of this
I know I'm still sad about RVLution not really getting a proper archive.
saaaame
looking at old posts from when I was retarded would make me wanna bury myself but I still wanna see the board again
btw the whole reason we're not getting an archive is cuz
someone doesn't want their posts included in the archive and WMC said he would rather just not release it at all than release an altered version of it
we
are talking upwards of 2.6K posts, so it's not a trivial amount of threads that would be contextually broken
the Patreon donations I receive also largely cover the hosting costs, so there's no problem there.
wait, so you've got surplus money?
gimme.
realistically, I'd just need a way to deal with the spam attacks. it's one thing if they're just your typical spammer accounts, but if old accounts are getting hacked, that's concerning.
dyou have any info on who's being hacked? also is this still happening, or did it happen all at once?
would be good to know if it's only people with crapo passwords being hacked, because if not then you've got a real problem on your hands
I suggested IP bans regularly in PMs
IP bans aren't nearly as effective as they used to be. VPNs are commonplace, and some services can give you thousands of wildly different IPs. even banning IP ranges doesn't work in that case, so there's nothing you can do.
and uuh, whatever you said about geolocating the attacker: you can't. you only have access to the VPN's location
(that's the entire point). I'm pretty sure bots basically always use VPNs or similar. the ones we get daily on NSMBHD sure do...
P.S.: Could you also implement the changes to the register and edit profile pages with disallowing new passwords that:
• don't have at least 16 characters;
• don't have at least one non-alphanumerical symbol;
• don't have at least one uppercase letter, one lowercase letter and at least one number?
too much
we aren't a bank
typing your password shouldn't be an annoying minigame