Locking account for too many password attempts

RexBRexB Registered Users Posts: 13 Big grins
edited December 15, 2009 in SmugMug Support
In reviewing my statcounter report, someone spent almost an hour trying to hack into my smugmug account yesterday. There were 28 tries on my main password and 15 attempts on individual galleries. Does smugmug have the ability to lock someone out if there are too many attempts?

Comments

  • SteveMSteveM Registered Users Posts: 482 Major grins
    edited December 14, 2009
    RexB wrote:
    In reviewing my statcounter report, someone spent almost an hour trying to hack into my smugmug account yesterday. There were 28 tries on my main password and 15 attempts on individual galleries. Does smugmug have the ability to lock someone out if there are too many attempts?
    Hi Rex,

    We don't have the ability to lock out a certain individual from trying to login. This is one reason we highly suggest strong passwords. We have and continue to consider methods to thwart too many attempts.

    I'm sorry I don't have a better answer for you right now.
    Steve Mills
    BizDev Account Manager
    Image Specialist & Pro Concierge

    http://www.downriverphotography.com
  • RexBRexB Registered Users Posts: 13 Big grins
    edited December 14, 2009
    Thanks Steve. Its frustrating because I believe this is the same person who has contacted me twice before for a password which I have refused to give out. Not sure why they are after my site! I do have a good password, but if they ever did manage to hack in they could cause major problems.
  • rainforest1155rainforest1155 Registered Users Posts: 4,566 Major grins
    edited December 15, 2009
    RexB wrote:
    Thanks Steve. Its frustrating because I believe this is the same person who has contacted me twice before for a password which I have refused to give out. Not sure why they are after my site! I do have a good password, but if they ever did manage to hack in they could cause major problems.
    Thanks for sharing your concerns.

    Personally, I'm not sure such a thing would be very useful. After all, if they would be really after getting into your gallery and would know what they are doing, I'm sure they would know of ways to bypass such a "too many attempts" feature. They could simply dial out and back in to get a new IP or clear their browser cookies or use an anonymizer service to not reveal their own IP etc depending on what techniques the feature would use. There's no real good way to do this that I can think of if the protection is not bound to one account you try to login to, but a page that everyone can try to access.

    If you have a good password, you shouldn't have to worry about this.

    Sebastian
    Sebastian
    SmugMug Support Hero
Sign In or Register to comment.