Page 1 of 1 [ 15 posts ] 

KitLily
Veteran
Veteran

User avatar

Joined: 7 Jan 2021
Age: 55
Gender: Female
Posts: 5,074
Location: England

12 Dec 2023, 11:33 am

I am getting a lot of Error messages when I try to log in. Yesterday it was saying 'Try again in 59 hours'. Today it's 'you have 4 attempts left to log in.'

I'm used the same password and username I've always had!


_________________
That alien woman. On Earth to observe and wonder about homo sapiens.


blitzkrieg
Veteran
Veteran

User avatar

Joined: 8 Jun 2011
Age: 35
Gender: Male
Posts: 15,409
Location: United Kingdom

12 Dec 2023, 5:24 pm

This has happened several times to me, also.

It stops me from logging in, sometimes for hours at a time.

And the number of hours it mentions before trying again, seems random and has ranged from 25 hours to 65 hours.

Sometimes it'll say try again in say, 59 hours, and then if I try within another 10 minutes I can log in fine.



DeepHour
Veteran
Veteran

User avatar

Joined: 1 Jun 2014
Gender: Male
Posts: 78,257
Location: United Kingdom

12 Dec 2023, 9:01 pm

I always try to remain logged in. Occasionally the system logs me out for no apparent reason, but getting back in is usually straightforward.


_________________
On a mountain range
I'm Doctor Strange


KitLily
Veteran
Veteran

User avatar

Joined: 7 Jan 2021
Age: 55
Gender: Female
Posts: 5,074
Location: England

13 Dec 2023, 10:30 am

Well I changed my password as it advised and still couldn't get in today til now. I suppose I'll just have to see what happens each day :?


_________________
That alien woman. On Earth to observe and wonder about homo sapiens.


Mountain Goat
Veteran
Veteran

Joined: 13 May 2019
Gender: Male
Posts: 14,202
Location: .

14 Dec 2023, 8:05 pm

Yes. I am back after a 58 hour wait.


_________________
.


TwilightPrincess
Veteran
Veteran

User avatar

Joined: 28 Sep 2016
Age: 39
Gender: Female
Posts: 21,739
Location: Hell

14 Dec 2023, 8:07 pm

Welcome back! :lol:


_________________
Better to reign in Hell than serve in Heaven. – Satan and TwilightPrincess


Mountain Goat
Veteran
Veteran

Joined: 13 May 2019
Gender: Male
Posts: 14,202
Location: .

14 Dec 2023, 8:11 pm

Thanks.:D


_________________
.


Cornflake
Administrator
Administrator

User avatar

Joined: 30 Oct 2010
Gender: Male
Posts: 65,737
Location: Over there

15 Dec 2023, 8:20 am

DeepHour wrote:
I always try to remain logged in. Occasionally the system logs me out for no apparent reason, but getting back in is usually straightforward.
There's a session timeout, set to 7200 seconds (2 hours), which likely gets reset with your activity on WP - browsing, posting etc.
This is rather like online banking logging you out after a period of inactivity.

Once upon a time Firefox had a "Refresh page every X seconds" option but that seems to have gone away, so I use this add-on instead:
https://addons.mozilla.org/firefox/addo ... o-refresh/

To keep a track of my subscribed thread updates I use it to auto-refresh my "Subscriptions" page (My Account | Overview | Manage subscriptions) - which also keeps the session permanently active.
For me, this is much more useful and better focussed than endlessly checking for new posts.

Maybe the hit-and-miss emailed thread update alert issue has been fixed, so using the auto-refresh is either a coincidence or it's a fix in itself, because since starting it a few months ago I now regularly receive emailed thread update alerts.


I have no idea where the extreme enforced login delays are coming from.
One technique is to allow (say) 3 failed logons, then each subsequent failed logon doubles a delay before you can try logging on again - so if you fail 1 more time that's 1 minute, again is 2 minutes, again is 4 minutes and so on.

But WP doesn't implement this - or at least, it's not visible at the administrator level.
There are failed logon timeouts but they're quite modest and nowhere near the tens of hours reported here.
It's conceivable something "stronger" is implemented at the CloudFlare level, which I can't see, but even so the tens of hours delay is unnecessarily extreme.

It's possible that refreshing the browser logon window will clear or reset these delays and allow a logon, but if that doesn't work immediately there's no point in repeating it.


_________________
Giraffe: a ruminant with a view.


Cornflake
Administrator
Administrator

User avatar

Joined: 30 Oct 2010
Gender: Male
Posts: 65,737
Location: Over there

19 Dec 2023, 7:21 am

It's been pointed out that these failed logins and delays could be the result of bots attempting to brute-force guess a password, where many password combinations are automatically tried over a short period of time in an attempt at guessing it.

That would generate many failed login attempts and apparently, through some non-visible mechanism, the extended delays before being allowed to try again.

I don't think there's any immediate worry - this is something any site could be subjected to, but reviewing your password and increasing its length/complexity would decrease the chances of it being guessed.

Unfortunately these are bad actors external to WP and their activity is not something I'm able to control.


_________________
Giraffe: a ruminant with a view.


blitzkrieg
Veteran
Veteran

User avatar

Joined: 8 Jun 2011
Age: 35
Gender: Male
Posts: 15,409
Location: United Kingdom

19 Dec 2023, 8:27 am

How do you know it is bots and not a human or humans doing the password guessing?

It seems like a lot of effort for a person to employ bots to guess the passwords of an obscure internet forum.



Cornflake
Administrator
Administrator

User avatar

Joined: 30 Oct 2010
Gender: Male
Posts: 65,737
Location: Over there

19 Dec 2023, 8:46 am

I don't know - it's just that having an actual person sitting there spending hours entering password guesses isn't how it's normally done. Bots are free, fast, can work 24/7 without tiring, and they can be fed different word/phrase combinations to try with little to no effort.

While WP itself is a little obscure, if it can be cracked covertly and set up as a bot farm it becomes quite valuable to spammers.


_________________
Giraffe: a ruminant with a view.


blitzkrieg
Veteran
Veteran

User avatar

Joined: 8 Jun 2011
Age: 35
Gender: Male
Posts: 15,409
Location: United Kingdom

19 Dec 2023, 8:49 am

Cornflake wrote:
I don't know - it's just that having an actual person sitting there spending hours entering password guesses isn't how it's normally done. Bots are free, fast, can work 24/7 without tiring, and they can be fed different word/phrase combinations to try with little to no effort.

While WP itself is a little obscure, if it can be cracked covertly and set up as a bot farm it becomes quite valuable to spammers.


Ah, sorry, what I meant with the question was to ask how do we know it isn't a human controlling the bots, but I realise now that is what you meant anyhow with your initial post.

I just had an idea of a mindless army of bots descending upon the website. I am not sure how these things work as you can determine. :lol:



Cornflake
Administrator
Administrator

User avatar

Joined: 30 Oct 2010
Gender: Male
Posts: 65,737
Location: Over there

19 Dec 2023, 8:54 am

It could be one or many - I can't see the activity, unfortunately.

One benefit (from a security viewpoint, at least) is that if failed logins are causing increasing delays before being allowed to try again, that would affect the bots too and thus slow their activity.


_________________
Giraffe: a ruminant with a view.


belijojo
Veteran
Veteran

User avatar

Joined: 4 Dec 2023
Age: 20
Gender: Male
Posts: 910

19 Dec 2023, 9:25 am

Ddos always troubles small websites


_________________
For I so loved the world, that I gave My theory and method, that whosoever believeth in Me should not be oppressed, but have a liberated life.


superboyian
Veteran
Veteran

User avatar

Joined: 9 Sep 2009
Age: 32
Gender: Male
Posts: 14,704
Location: London

25 Dec 2023, 10:21 am

I couldn't even log in, tried resetting my password, that didn't work but then for whatever reason I don't know, my old password works again.


_________________
BACK in London…. For now.
Follow my adventures on twitter: @superboyian
Please feel free to help my aspie friend become a pilot: https://gofund.me/a9ae45b4