Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Old Freeper Accounts Hijacked?
Original Content | 03/16/2025 | By Laz A. Mataz

Posted on 03/16/2025 6:09:41 AM PDT by Lazamataz

I've noticed, over the years, that very old Free Republic accounts, accounts that have been inactive for months or years, suddenly reactivate.... but their politics are suddenly suspect.

Be they Zeeper-oriented (that is, super-favorable to Ukraine) or, conversely, super-favorable to Russia, or even suddenly-liberal... these accounts reactivate with a flurry of posts that are contrary to conservatism.

Are these real Freepers who have had a change of heart about their politics? Are these real Freepers who feel the need to jump on the forum with propaganda and support for one side or the other per the Ukraine/Russia war?

Or are these hijacked accounts?

People will recall some time back, quite a few accounts of active Freepers were hijacked. It created a bit of a problem. When all was said and done, the accounts were returned to their rightful owners, and the site owner (and his moderator crew) pointed out that their passwords were very easy to guess. He instructed people to have stronger passwords.

I also have a friend on Facebook who no longer participates in the forum, but still reads it, who has seen a Freeper posting who he happens to know has been dead for more than a decade.

The problem is, we have far too insecure a login process, and enemies of the forum have been exploiting that.

At the login page, you can attempted unlimited login attempts. This will allow simple brute-force password cracking.

Also, the Forget Password option sends an email with your password in clear text. Emails can easily be sniffed with the right techniques. Passwords can easily be cracked that way.

My suggestions to mitigate these critical security concerns are:

  1. -- Limit login attempts to five, after which the account is suspended until unlocked. What unlocking consists of can be anything. One suggestion is that the account is auto-disabled for a day. That means a hacker will only get five brute-force attempts in any given 24 hour period.
  2. -- Install two-factor authentication, in which a text number is sent to a phone the user possesses.
  3. -- Emails for Forget Password should not send the actual password, but instead, a link to a page on FR that allows a reset of the password.

These relatively-simple security changes will stop account-hijacking.


TOPICS: Chit/Chat; Conspiracy; Weird Stuff
KEYWORDS: bitchassstalker; comingafterustalker; cowardlystalker; diekeywordstalker; doxthestalker; freerepublic; hereiskeywordstalker; iwillfindustalker; karensunite; keywordstalker; keywordstalkerbitch; keywordstalkerpunk; keywordstalkers; nobodyshacked; papersplease; peoplegettignold; punkstalker; seeyourpapers; showyourselfstalker; stalkeriscoward; stupidvanity; yournextstalker
Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-80 ... 341-357 next last
To: Robert DeLong

Two factor authentication can also be accomplished by sending to an email address, however, this is less secure. Still, better than nothing.


21 posted on 03/16/2025 6:26:55 AM PDT by Lazamataz (I'm so on fire that I feel the need to stop, drop, and roll!)
[ Post Reply | Private Reply | To 18 | View Replies]

To: Nextrush
Sleeper accounts to be used when needed I would guess.

While that is undoubtedly true, I am most concerned about the fact I can easily brute-force a password crack. There is no limit to the number of attempts.

22 posted on 03/16/2025 6:27:56 AM PDT by Lazamataz (I'm so on fire that I feel the need to stop, drop, and roll!)
[ Post Reply | Private Reply | To 20 | View Replies]

To: Lazamataz

People change over time. And, you can’t always judge the ‘politics’ of what an account used to seem like against some of the more controversial topics of today. One of them is the Ukraine and who falls down on what side of it.

The one big thing that would stand out for me is a former 2016-2020 Trump supporter being overly critical or unsupportive of Trump today.


23 posted on 03/16/2025 6:28:11 AM PDT by Gaffer
[ Post Reply | Private Reply | To 1 | View Replies]

To: 7thOF7th

Laz is pointing out a vulnerability of the site.

If you were in a foxhole and someone spotted an enemy would you react that way?


24 posted on 03/16/2025 6:28:45 AM PDT by MV=PY (The Magic Question: Who's paying for it?)
[ Post Reply | Private Reply | To 12 | View Replies]

To: Gaffer
People change over time. And, you can’t always judge the ‘politics’ of what an account used to seem like against some of the more controversial topics of today. One of them is the Ukraine and who falls down on what side of it.

Sure. But what still remains is unlimited login attempts. If I felt like retrieving a brute-force password cracker routine, I could get YOUR password. 😁

Of course I won't... but I could.

25 posted on 03/16/2025 6:30:01 AM PDT by Lazamataz (I'm so on fire that I feel the need to stop, drop, and roll!)
[ Post Reply | Private Reply | To 23 | View Replies]

To: Lazamataz

I love FR, but the whole platform is stuck in the 1990s. The tech is dated and it shows.


26 posted on 03/16/2025 6:30:55 AM PDT by clee1 (We use 43 muscles to frown, 17 to smile, and 2 to pull a trigger. I'm lazy and don't wish to smile.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Lazamataz

Absolutely could!


27 posted on 03/16/2025 6:31:18 AM PDT by Sidebar Moderator
[ Post Reply | Private Reply | To 2 | View Replies]

To: clee1

I like the no-nonsenseness; but yeah, there could be some more ways to stop hijacking.


28 posted on 03/16/2025 6:32:31 AM PDT by 9YearLurker
[ Post Reply | Private Reply | To 26 | View Replies]

To: Lazamataz
Many conservatives post their more controversial takes here because the old-school security allows greater anonymity. Even I say things on FR I would never put on X - where I am a big consumer of content but post almost nothing.

A lot of FR veterans would not be willing to trust even this site with a phone number.

29 posted on 03/16/2025 6:33:15 AM PDT by Mr. Jeeves ([CTRL]-[GALT]-[DELETE])
[ Post Reply | Private Reply | To 1 | View Replies]

To: 7thOF7th; Lazamataz
dare I say your comments appear authoritarian and fanciest.

How dare you accuse Laz of fanciestism!

30 posted on 03/16/2025 6:34:15 AM PDT by Pilsner
[ Post Reply | Private Reply | To 12 | View Replies]

To: 9YearLurker

💯%


31 posted on 03/16/2025 6:34:15 AM PDT by clee1 (We use 43 muscles to frown, 17 to smile, and 2 to pull a trigger. I'm lazy and don't wish to smile.)
[ Post Reply | Private Reply | To 28 | View Replies]

To: Lazamataz

Americans must contend with three enemies...all within.

Democrat Party

RINOs

Judiciary

The judiciary is the left’s ace in the hole. Use of it failed when the attempts to jail DJT failed. Now they use it t thwart the will of the people.

At every turn there’s a judge appointed by one of our lousy presidents thereby becoming a landmine to stop the guy we elected to overhaul and drastically reduce the monstrous government.

No more Mr. Nice Guy! Confront those judges who willfully deny the people’s desire to drastically change the central socialist government.

Go on the offensive, Mr. President!


32 posted on 03/16/2025 6:35:06 AM PDT by ABStrauss (I miss Rush!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Lazamataz

33 posted on 03/16/2025 6:35:14 AM PDT by larrytown (A Cadet will not lie, cheat, steal, or tolerate those who do. Then they graduate...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: clee1; John Robinson
I love FR, but the whole platform is stuck in the 1990s. The tech is dated and it shows.

Some very simple programming could mitigate the security holes.

34 posted on 03/16/2025 6:35:17 AM PDT by Lazamataz (I'm so on fire that I feel the need to stop, drop, and roll!)
[ Post Reply | Private Reply | To 26 | View Replies]

To: AppyPappy

I submit that they were never Conservative in the first place.


35 posted on 03/16/2025 6:35:18 AM PDT by logi_cal869 (-cynicus the "concern troll" a/o 10/03/2018 /!i!! &@$%&*(@ -)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Lazamataz

Thanks, Laz!


36 posted on 03/16/2025 6:36:09 AM PDT by Cincinnatus.45-70 (What do DemocRats enjoy more than a truckload of dead babies? Unloading them with a pitchfork!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: 7thOF7th; Lazamataz

Cool it! Laz is a good egg.


37 posted on 03/16/2025 6:37:05 AM PDT by sauropod (Make sure Satan has to climb over a lot of Scripture to get to you. John MacArthur Ne supra crepidam)
[ Post Reply | Private Reply | To 12 | View Replies]

To: Pilsner; 7thOF7th
How dare you accuse Laz of fanciestism!

Of all the things I have been called, over the years, being called a fanciest was the most cutting of all.

I'm not sure I will recover from being called someone who embraces fanciestism.

I may need to enroll in therapy because of this.

38 posted on 03/16/2025 6:37:56 AM PDT by Lazamataz (I'm so on fire that I feel the need to stop, drop, and roll!)
[ Post Reply | Private Reply | To 30 | View Replies]

To: 7thOF7th; Lazamataz; Pilsner

Next you’ll be accusing him of consuming that fancy CATSUP!


39 posted on 03/16/2025 6:38:46 AM PDT by larrytown (A Cadet will not lie, cheat, steal, or tolerate those who do. Then they graduate...)
[ Post Reply | Private Reply | To 30 | View Replies]

To: Lazamataz

Two factor can use landline phones.

I find it hard to believe anyone would not want a phone especially when older.

Cant read the cellphone,how read emails? I call BS on such claims.


40 posted on 03/16/2025 6:38:53 AM PDT by hoosierham (Freedom isnt free)
[ Post Reply | Private Reply | To 21 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-80 ... 341-357 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson