2846
posted ago by Doggos [M] FL ago by Doggos +2846 / -0

These are the Win changes since the last update post:

  • fixed issue where posts and comments from prior to March 23rd would not appear in listings (such as hot and top) or profiles
  • clicking the header text with 'community styling' disabled now returns you to the homepage
  • fixed issue which prevented saving comments
  • fixed issue where save folders could be renamed to "" (nothing)

We've also made the decision that holding plaintext email addresses is not in the best interest of the community. Around 50,000 Win accounts had associated email addresses, which is an optional field during registration, and is only ever used to request password resets.

We have now hashed all email addresses that are associated with Win accounts and deleted the backups. This means that we do not have any way to know your email addresses, and nor would any attackers in the event of a breach.

As a result, if you ever need to request a password reset, you will now have to provide both your username and your email address. We don't know your email address, but we can verify whether the one that you provided when requesting a reset is the same one that's associated with your account. If it's a match, we'll send the password reset to the email address that you just provided. This works the same way as passwords.


Finally, we now have RSS feeds available for the hot, new, rising, and top listings:


Leave your feedback, bug reports, and suggestions in the comments. Upvote the suggestions that you agree with most.

Comments (223)
sorted by:
You're viewing a single comment thread. View all comments, or full comment thread.
8
Doggos [M] [S] 8 points ago +8 / -0 FL

Yep, I mean hashed. Bcrypt.

3
LikeAWombatScorned 3 points ago +3 / -0

Bcrypt is a great choice for a cryptographic hash. Thank you for making security a priority. Plenty of left-wing nut jobs would have a field day with those email addresses if the database were ever breached.