This is negligence on androidforums part; and, are the real people to blame. Can you imagine if large bank websites were also this insecure; and, asking all their online customers go change their passwords? Then.. customers just saying... oh well, these things just happen.
There's the argument that user passwords should be complex enough for the hash not to be brute forced hacked; but, really, it should never get to that point.
I've lost complete respect for the person/people responsible for maintaining this website. Hopefully, they know better than to list androidforums.com on their resumes.
There are bank sites out there that limit your password to only 8 characters and with letters and numbers only. Nothing else.
I can atest with personal knowledge that yes, there are bank sites configured that contain multiple potential attack vectors just waiting a good simple exoit.
I've had cell phone companies want to read my password to the first person who says they're me whoever I call. All they would need would be my name and my cell number. From that the CSR would volunteer them my account password which would allow them to log in as me, view my account and change anything.
I've worked on systems when our security has been extremely hampered by the need to interface to a mainframe. My heart crashes when I hear that we have to match a set of password parameters that the main frame.
All these things and more we had. We had two factor auththentication, multiple domains separating each tier and long passwords changed on a 42 day basis. Hell, it would take me a day to update all my passwords on all the systems when I had to change.
You can have it more and more besides. But unless you're willing to pony up the huge amount of dollars a ring fenced trip wired, glass breaking system, the bad guys are going to get in.
It's called life. You take a trip to work and use a car everyday because it makes fiscal sense to you. Sure you could go the whole hog and buy a swadding chieften tank and probably be even more secure but it would make any sense to do that.
Running a Web Site like AF requires a lot of decisions as to what should be utilized and where does its p&l stand. If the ROI on the tank is high enough then I guess you're gonna be having fun every day grinding over those other schmucks who kept their car... Same with these guys - at what point to they say the cost of security is greater than the advantages having it.
For what is essentially a fan Site with little to no PID I'd imagine the budget ain't gonna stretch for no tank...