πŸ”’ Security / Authentication Update

Over the last few months, the tape holding together our aging authentication system has started to fall and really show its age. You've probably been redirected to the login screen while trying to do anything, not been able to get the wardrobe or forums to load, and sometimes felt that it’s completely broken.

So instead of adding more tape to the system, we're introducing a centralized authentication site that'll handle logging you in across Subeta. Clicking on any login or logout button from this site or new Subeta should redirect you to https://auth.subeta.net, where you can log in.

I want to talk through a few of the benefits directly, and we'll be discussing this more in the coming days. As part of this change, we will be removing PIN protection but will be offering 2FA (getting a code sent to your email or phone) as soon as possible.

Benefits

#1 Central source of truth

[auth.subeta.net](notion://auth.subeta.net/) has one mission: account management. That's it! We're going to move registration there as soon as possible, with an avatar builder and pet creation, but its only job is account management.

You've probably noticed when clicking on a link to login with Google that you're taken to a non-google domain (sometimes youtube) where you log in, and it redirects you. That is the centralized account management service, doing the important work behind the scenes and then sending you to the website you're trying to use and saying "This user is all good, I've verified them!".

#2 2022 Encryption Method

The method used to encrypt Subeta passwords in our database is from PHP 5.7. We're now using PHP 8.1 on all of our servers. We have to include a special package in our PHP installation to have access to the 5.7 hashing methods.

We encrypt your cookie and decrypt it on the server, and the key is what tells the site that you're valid and not using some fake credentials.

This new management system uses modern hashing which are impossible (as much as anything is impossible) to crack. And they give us the benefit of...

#3 User-based Keys

Each cookie (what we set in your browser to say who you are) is salted with a special key that is unique to your account. We're going to be able to provide a button that allows you to reset that special key, which will log you out **on all devices**. It's also hashed with your account password, meaning if you change your password everyone will be logged out of your account immediately.

Finally, it's hashed with a top secret Subeta key, that we will rotate on a secret basis.

Password Update

As part of all of these changes, the encrypted password for your account on Subeta is woefully out of date. We've been able to implement this system in a way that it takes priority over the former system, which means we don't need to rotate every password on Subeta *immediately*. You can still log in with your current password, and we will alert you through the news before we require passwords to be rotated.

Login Update

You'll get a very annoying notice at the top of the page letting you know that you're logged in through the old method (with an old cookie), and that we'd appreciate it if you went over to auth.subeta.net and log in. It'll still read that old cookie, but we aren't going to be supporting this old system for long. This is different than needing to update your password, this is the temporary cookie that stores your account information in your browser. Very easy to fix by just logging in on auth.subeta.net. Remember to put in the email address for your account, not your username! You can check which email address you have set for Subeta at https://subeta.net/preferences.php?act=profile.

Thank you πŸ™

Thank you for your patience while the authentication system crumbles and you're constantly being asked to log in to an account you're logged in to. I'm hopeful that this is the last *major* change we need to make to accounts (🀞), since we've made the hard choice to build it up from the ground instead of adding more duct-tape.
User Avatar: 1

Posted by Keith

floyolson

Thanks for this information
0

HFEpro

hooray for updates <3 congratulations!
0

Dela

Hey, Keith it’s me, Dela.. you know the the person you hate so much that you removed Keith day a long time ago, very sorry about that but Amber banned me and she didn’t even know I didn’t have a alternative account on here!
0

Amalthia

I can't log in through the new log-in page. I just get constant errors even though I know my information is correct.
1

Sirensong

Why do I have to keep logging back into it the new way? Seems like every other day, and it's starting to get very annoying.
4

Kreeki

πŸ”’ You're logged in to Subeta using the old method, and we'd appreciate you switching to the new method. Check out the news post here for more details.

LOL NO, WHY
I have logged into the new method so many times now! I never log out before I get this message, if this helps lol.
1

Faber

I get this message every day, sometimes multiple times a day. I log in the new way every time but it never stays. This page keeps taking longer and longer to load as well. Any advice or should I just resign myself to permanently playing with this stupid message on every page?
0

Julia

I appreciate better security but I AM logged in using the new method. I've done it twice now and I just got the message again. Can we get some clarification on why this is happening?
0

Serena922003

I am also continually getting a message that my username or password is invalid. I know after 25 times I'm entering them correctly. :(
1

lunarules

HOW MANY times are we going to have to keep logging in via the link above before it finally sticks? If we've done it once, do we have to keep doing it over and over and over and over...or can we just ignore the notification that we get? This will be the 4th or 5th time I'm doing this. I'm sure people would like to know via an announcement that if you've done it at least once, you don't have to keep doing it (if that is the case).
3

WolfieWU

Trying to use the new method, the site won't even let me log in.... so old method is the only way I seem to be able to access my account.
0

RoxyWolf

Given what happened with a certain other petsite recently, I appreciate Subeta's efforts to try and keep things moving forward before anything bad can happen.
1

Tammynoneed20

I'm gonna continue using the old method until I get told I can't or it gets fixed I'm tired of it changing to You're logged in to Subeta using the old method everytime I open the page back up
6

Reign

I have logged in using the new method as requested every time I have been on the site since the change, at least 5 times. It still says I am logged in the old way when I get on. I cleared the cookies. I don't know what the issue is but it is very annoying having to log in every time and still getting bad gateway messages every other thing I click on.
4

yellowdream

I used a strong password and it worked Thankyou so much XXXX
0

Tammynoneed20

Today all day the same banner here keeps popping up saying Your logged in to Subeta using the old method not sure how many times I need to do this cuz it seems to not help it still pops up
9

Kat77

Like some others on here, I've logged in with the new authorization several times on my phone and my computer. And every so often it tells me I'm logged in the old way and please do the new authorization.... Do I really need to keep doing it every time that notice shows up?
7

Shanty

I can’t get rid of the banner.
1

Penemuel

@Galaxia I finally managed to figure it out, thank goodness. At least I didn’t lose a long bathhouse streak :)
2

yellowdream

still cant log in will keep trying oh dear..
0

yellowdream

still cant log in will keep trying oh dear..
0

Freakshow

I log in via the new method, but it takes me to the site and I'm still logged out and have to sign in again, and I noticed since I use mobile if i leave the page for more than 15 minutes it logs me out :(
0

FCoD

I hit both logins every time I come on here. First is the old way and then it automatically takes me o the new way.
2

Diana

Same as @EvilRedDuckie
1

EvilRedDuckie

i'm getting a notice at the top of the page saying i'm logged in under the old system and need to sign in through the new system. i already did, a week ago. do i have to do it again?:pensive:
3

lunarules

@Saturnine This keeps happening to me also. I've logged on the "new" way at least 3 different times on desktop and mobile.
0

Galaxia

@Penemuel @yellowdream
Can you log back out and log back into the new version, making sure to choose the legacy site? Or is this still ongoing as a problem for you?
0

Saturnine

I logged in using the new auth method when it was first announced - now it's asking me to do it again because I'm not on the new method.

:?
3

Galaxia

@Itachi_Siller Past this point please put it in Problems and Bugs, although here's hoping it's been ironed out. There is also likely going to be a news post announcing when we're no longer supporting the old auth system.

Y'all have been champs dealing with the new process as Keith makes changes, and we appreciate it,!
1

Itachi_Siller

@Galaxia At this time it looks to be fixed.

If it happens again should i just contact you on here?
0

yellowdream

Im still trying to log in by new method ..changed email address, password and browser .I have made a ticket also but still left behind its making me very worried how much longer before I cant log into subeta at all ,
0

Penemuel

Sorry for spamming, but none of my comments ever showed up so I kept trying…
0

Penemuel

I’m on mobile & trapped in the new version, and can’t find the link to dailies or to the map. Help! Comments also don’t work.
1

Penemuel

I’m on mobile & trapped in the new version, and can’t find the link to dailies or to the map. Help! Comments also don’t work.
0

Penemuel

I’m on mobile & trapped in the new version, and can’t find the link to dailies or to the map. Help! Comments also don’t work.
0

Penemuel

I’m on mobile & trapped in the new version, and can’t find the link to dailies or to the map. Help! Comments also don’t work.
0

Penemuel

I’m on mobile & trapped in the new version, and can’t find the link to dailies or to the map. Help! Comments also don’t work.
0

Penemuel

I’m on mobile & trapped in the new version, and can’t find the link to dailies or to the map. Help !
0

Penemuel

I’m on mobile & trapped in the new version, and can’t find the link to dailies or to the map. Help !
0

GLaDOS

Seeing people still describing the process as very buggy, I'm reluctant to try the "new way" just yet. Occasionally I'll check back to see if people are still having trouble, but until it seems clear or is absolutely required, I'm not sure if I'm willing to rush into this new change.

Also, I kept getting 504 errors trying to access these comments, specifically for this news post. Not sure if that's related.
3

silverglow

oops...I logged in using my username instead of email (old habits die hard) is this going to cause a problem and if so how can I correct it? Thanks in advance.
0

Shanty

I keep logging in through the link but still got the barrier
1

Penemuel

I’m on mobile & logged in the new way, I think, but now all the links to daily things are gone, the sidebars are gone, and all the holiday stuff is stuck on Masquerade. I can’t use the site like this. I can’t even find where to go for the map or my pets.
0

Penemuel

I’m on mobile & logged in the new way, I think, but now all the links to daily things are gone, the sidebars are gone, and all the holiday stuff is stuck on Masquerade. I can’t use the site like this. I can’t even find where to go for the map or my pets.
0

Penemuel

I’m on mobile & logged in the new way, I think, but now all the links to daily things are gone, the sidebars are gone, and all the holiday stuff is stuck on Masquerade. I can’t use the site like this. I can’t even find where to go for the map or my pets.
0

Penemuel

I’m on mobile & logged in the new way, I think, but now all the links to daily things are gone, the sidebars are gone, and all the holiday stuff is stuck on Masquerade. I can’t use the site like this. I can’t even find where to go for the map or my pets.
0

Galaxia

@teacup132
It should be there now, the database hiccup was being addressed!

@Magic
Please try the 'forgot password' link. If you don't get the email or the one on https://subeta.net/preferences.php?act=profile isn't accurate for you, email support @ subeta.net!

@Itachi_Siller
Are you still getting this today?
1

teacup132

@Galaxia Since the banner is still lacking the link to log in directly, I am refusing to log in the "new" method.
0

Magic

Totally locked out of my account on mobile now. I absolutely am entering in my correct username/email and PW beyond any shadow of a doubt and it literally will not let me log in AT ALL. It keeps saying everything is wrong. And the link on that log in page to what I'm assuming is this news post doesn't even work because you need to be logged in to view it...which you can't.
0

Paula

I was able to log in, FINALLY! I found out what was wrong, in case it helps someone else out there:
I clicked 'forgot my password', had to wait a bit but the mail was sent (to spam), then I reset my password (it wasn't possible before because it said the password was weak, that's how I found out, and when the password said "strong", then I was able to click 'reset').
After I reset the password, it worked, I could log in just fine.

Just in case it helps someone that was having the same issue with invalid username/e-mail/password like me.
0

BoaConstrictor

...oops... obviously comment got through in spite of the 504
? weird...
0

BoaConstrictor

logging in with username doesn't work, either - "invalid" message

...getting 504's here on the comments repeatedly
0

BoaConstrictor

logging in with username doesn't work, either - "invalid" message
0

Itachi_Siller

Everyday i keep getting the "You're logged in to Subeta using the old method, and we'd appreciate you switching to the new method. Check out the news post here for more details." Do I have to sign into the Auth version everyday?
1

mmmh81

Finally got it to work.
0

SpectrumSurfer

Thank you for fixing it so quickly. I was able to use my username to log in and find out that the email I used to sign up was one I hadn't used in years.
0

Borxar

When I put my email and password to try log into the new system it says that my username cannot be found
0

Galaxia

@Hippolyta @Mort @jKat
Yes, sorry about that! We were trying to put in the option to log in with username instead of just email. The page should be working again, although username log-in will have to wait for another day. Thank you for letting us know!
4

jKat

I get a blank page when I go to do the new log in.
1

Mort

I also get a blank page when I want to log in, my workaround is to press the ESC key before it turns white lmao. :sob:
2

Hippolyta

https://auth.subeta.net/auth/login

Blank white page.

Windows 10, latest Opera browser.
1

Galaxia

@teacup132
The plan right now is to make it the default log-in page on Monday (with a username option, not just email address), and either a link to this newspost on it or a separate page with the information. I'm also trying to make sure we have the reminder/address to email support for assistance as well.
1

Bliss

It says I'm still on the old system when I did change to the new one on my laptop. Ah well lol
2

Pollux

I just wanna say I think the timing of subeta doing this update that will require updating our passwords while neopets has an active security breach is really funny to me
1

teacup132

@Galaxia It would be appreciated to have a direct link in the banner to the new authentication page as many of us have already read the text and don't want to search every single time to find the link.
0

Bathory

I'm having the issue where I log in via the new way on mobile, navigate to something else and come back and I get the banner again saying I need to log into the new way. Can we please get a button on the sidebar so I don't have to scroll to the bottom of the news post to relogin?
0

Ryuu

Everything worked just fine for me when I switched over the other day~ Big thanks to staff for keeping this place going & helping to keep the users safe & secure. β™₯️

Anyway, here's a list of what seems to be commonly asked questions, in one spot, with big, bolded bits, for your skipping-er viewing pleasure. ;)

How do I check / change which email I used?

Email Check And Change Info

How can I login the old way? (to check / change email, etc)

Old Login

I cannot remember my password / it says my password is incorrect?

Password Problems

I can't log in either way!

Please Remain Calm

Other assorted questions.

Do I need to change my password now?

No.
"You can still log in with your current password, and we will alert you through the news before we require passwords to be rotated."


Do I have to use Two-Factor Authentication?

No.
2FA is only you want to use it and it is not available yet. (but you really should consider using 2FA for any account you care about that offers it.)


Why are there so few users online?

Pretty sure users logged in the new way are not included in the online count.
For example, the "Last Seen" section of user profiles does not update for users logged in the new way. (I'm sure it will be fixed in the future.)
13

Taarna

Anyone that has logged in just to do the BH would've seen the former news post about how they were going to implement this change. I saw it and read that it would be for later, so I dismissed it. There's been an active forum thread about making sure your sign up email address was up to date since then, for a month now. Fortunately I still use mine as I've gotten used to using multiple emails for a variety of things.

This news post was too convoluted. Honestly, most of it could've/should've gone in a "tech post" in Site Updates. I don't know why everyone was trying to change their password at the time of this post b/c it specifically said -
Quote:
You can still log in with your current password, and we will alert you through the news before we require passwords to be rotated.

To check what the original email is, go to the dropdown menu of Personal and then select -> Dashboard-->Profile. There it is.
The original link in the news post works with your old email and and old password so if you want to get rid of the message, sign in that way (under a separate tab if you think you'll get locked out) and you should be fine. In the meantime, if your email is outdated then you should probably update it AFTER you use the new authentication https://auth.subeta.net With them switching the mail servers, I think that was part of the issue (that was many, many comments ago.)

To those that said it should've been a sticky, sidebar or whatever - MOST DEF agree. A step by step process, in most cases, that leaves out the how's and why's and just tells you what to do.

There is no need to update your password at this time so that's the first thing to pay attention to. The second is to login as normal, even w/ your outdated email (since you won't get an email asking you to verify it's you at this time), through the https://auth.subeta.net . Once logged in normally with your new cookie, you *shouldn't* have a problem changing your email address via the above route in Dashboard/Profile.
7

Suiicune

I can not log in the new way when I use my username and password it says email not correct I made this account forever ago I am not sure of the email I used ><
0

Sketchpad

@Galaxia okay thank you for the info! also apologies if it was mentioned in the news article and I managed to miss it somehow
0

ashen.glaze

@Nikole

I appreciate that they did, but I wasn't on Subeta at the time when they posted it. News posts get buried pretty quickly. If they could pin it up in some way (eg banners, on the sidebar in the front page such as below the staff forum post), that would make it less likely for users to miss such announcements.
4

ashen.glaze

@Galaxia

Keith's link doesn't work for me when I'm not logged in (which is the problem). As for the news post, that seems pretty dependent on people being around at the right time to see the post (which I did not get the chance to see). If possible, it would have been better to see it pinned as a banner or on the side bar of the front page.
0

teacup132

In the banner that asks people to log in using new method, please put a link to directly log in... instead we are redirected here, have to search through a bunch of text to find the link. I had already read the text... I don't want to have to search every single time to find the link.

Also, please keep in mind that many people use autofill for passwords so it's easier to forget when we don't constantly use it. I actually had to go retrieve it in my browser settings, use another password to let me see the passwords for sites, etc. It was complicated to say the least. I understand it's a necessity to change but for those that have emails, it might be good to have an auto email to remind the people what their password is or an option to send an email with a temporary password to allow people to reset passwords.
2

hannahharmin

I'm having trouble with the wardrobe! I'm getting the spinning wheel of death and had to log in to it separately from Subeta. When I do click on it from the drop down tab on the site it says I must be logged in to view the wardrobe.
1

mitsuie

i had a hard time trying to log into my account because my account didnt have a email set to it, luckily i found the old site link. please introduce a user log in link until the email link works correctly :)
2

mmmh81

It just keeps saying invalid email for me...
0

slippy

well I've tried everything and it still says my email is invalid. so sad
2

capper09

@Galaxia...
I will wait with everything until everything works without problems... we know that changes here have never run smoothly immediately... also i don't want to log out and then have to stand in front of the door...
2

Chef

@extremist

https://subeta.net/preferences.php?act=profile

I was just able to update my email address here. I just clicked on the "submit your profile" button on the bottom and it seems to have taken it without issue. Is there an autofill thing that keeps changing it back maybe?
2

Mort

Judging by the drop in the number of users online — I assume some of them can't log in anymore — what I would suggest is to put a disclaimer about the password reset on that new method login page, and a temporary link to the old method login page so people can log in as before and check their email address in the Prefs page... Or something like that, I'm no UI/UX designer lol!
At this moment, the password reset suggestion (which fixed it for me) is buried in the comments and the link to the news post on that auth.subeta.net main page seems incorrect.
6

Stiles

if you log in with your email through that link, are you fine then until the site tells us we have to update our passwords?
0

Stiles

if you log in with your email through that link, are you fine then until the site tells us we have to update our passwords?
0

extremist

Trying to change my email before I do the new log in.
I type my new email address into the profile section but it keeps showing up with the old one that has not been used in 10 years.
Am I doing something wrong?
1

CastlesInTheSky

Well OBVIO I was the Dumbe one then thinking we'd get at least a 24h notice/reminder of a post buried in the news from one month ago.
1

ToxicBaby

Made sure I was logged in the new way as soon as this went up. And now I'm getting the same pop up that I'm logged in the old way?
1

Shibuya

Got everything to work fine for me on the first try!

I work in chat/email based site support and opening the comments to this newspost sent me straight into nightmareland. Hope all goes smoothly! :skull:
1

Wizardpinky

@BoaConstrictor I saw the amount of users today and was shook ; 3 ; hope everyone was able to log back in
0

Thunderbird

Did anyone else notice that the image is Wheatley mixed with a turret from "Portal 2"?
0

Galaxia

@capper09
You'll be able to decide on the 2-factor authentication, you don't have to do it just yet. You also don't have to change your password just yet.

@jersey
Understandable, please just get to it when you can! We will be working on issues as well over time and will let people know before we stop supporting the old authorization system.
3

jersey

After reading all this not yet comfortable making the change with the issues.
Have a couple things going on that I'm involved in and would hate to get locked out and not be able to finish them.
6

capper09

@Galaxia... is it a must to do the 2 way authentication and change PW or can i decide that myself... ? .. i have the note on the side that i am still logged in the old way, but since the new one doesn't seem to work i will stay with it until it all runs stable....
1

slippy

Okay I ended up filing a ticket because it just doesn't work for me.
2

Galaxia

@Sketchpad
2-factor authorization is going to be voluntarily, you won't have to bother with a phone app or anything unless you want to.

@capper09
It should be back up, Keith was fixing something quickly! He wants to make sure this works, not just dump the code once.

@[ashen.glaze]
I did make a news post last month, and Keith's second comment on this post down at the bottom was showing someone where they could check the email for the account.

@Coyote
You will have to set your password again in the future, but if you change it from your old one to something new you can reconfirm the new one when we do the reset!

@PaintedPawz
Try requesting an email for a password reset? If that doesn't work, please file a ticket!
3

capper09

@frederick ... @Galaxia... aaaah, thank you both.... so it is understandable, even without translator... sometimes the simplest things are the best... :)

who hacks Neopets can also divide by zero...
2

capper09

@frederick ... @Galaxia... aaaah, thank you both.... so it is understandable, even without translator... sometimes the simplest things are the best... :)

who hacks Neopets can also divide by zero...
0

Coyote

If we change our password now on the new log in screen will we have to change it again when it switches over?
0

Tammynoneed20

All good thank you for keeping us updated :D
0

Baikou

If anyone is having trouble, change your old password and double check to see if your email is still working. I did both, as someone mentioned earlier in the thread and it worked.
5

capper09

after using right site the login i got this :

Server Error... Application Error ... This application failed to respond

good that this site is loyal to their faults... *sigh*
2

PaintedPawz

Can anyone help me here? I know my email address is correct, but it keeps telling me wrong email or password and I've been using it for the past year with no problems :/
2

Narshe

@Ashen.glaze
Staff did an announce last month regarding having your email up to date.
11

ashen.glaze

Really would have liked some sort of headsup before implementation so that I could actually check which email I'd used to sign up.......... over 10 years ago. That is an email I have not touched in years, have completely forgotten about in context re Subeta. And since I don't show my email in my profile, that's no help either. As it is, I'm lucky I was able to guess right, because otherwise I wouldn't have been able to log in at all.

@ staff/Keith, next time you implement a security measure like this, please give us advance warning so we can prepare. Not everyone stays signed in, and not everyone remembers what email they signed up with.
1

Sketchpad

please tell me we aren't going to have to download and fight with one of those authenticator phone apps that generate one of those stupid codes you have to put in
1

loopa

finally worked for me!!! had to go into my profile and change my email address (forgot about the fact that everything i use now is connected to Google lol!!) and once I did it in the old system on my phone it worked!!!
1

Galaxia

@NekoHime
There's no midnight deadline or anything.

@Nebet @Maybird
You don't have to change it now, although if it's an older, re-used, or weaker password now might be a good time. We'll put out another notice when we are completely resetting passwords.

@Rosecel @BoaConstrictor @lissesul @slippy @yellowdream
If you're still having trouble when you try again, please file a ticket!

@yellowdream
You're not going to lose your account! This is about keeping your data safe and making log-in and authorization a more cohesive process.

@ColdDragon
Thank you for the details! I'm seeing a few other people mention issues as well across devices, and Keith is going to take another look today.
2

Rosecel

"Invalid email or password" Email is the one on my profile and my password is correct.
I tried on Safari, Firefox and Chrome.
2

Moonbeam

Given the massive data breach over on Neopets, this is not only welcome news, but a refreshing difference in how pet sites are managed. Thank you for being direct, up front, and letting everyone know EXACTLY what is going on, what will be changing, and why. This is the sort of staff response that all game/pet sites should have!
12

BoaConstrictor

Any new suggestions for us, who are not successful?
3

Shinko

Ahaha, very good timing for this in light of the neopets data breach.
5

daisuki

where's neugarten
4

lissesul

Update:
I tried it on Chrome as well. I also added https://auth.subeta.net to my whitelist as well. Still get *Invalid email or password*
0

lissesul

Invalid email or password*

I have triple checked my email address. Its still my same valid one & I have never changed my e-mail for Subeta.
I can log on with my username & old password.
I can't get logged on with the https://auth.subeta.net link at all.
I even reset my password and still no go.
I am using my old login & password, until this is resolved Ill keep on with the old way of logging in and playing.
I am using Firefox on my PC.
1

castyourshadow

Woo! It works. I was someone who initially didn't get the email to reset password, so if anyone was having that issue, it's working (for me) now. Maybe give it another shot?
2

StarShadow

Thank you for the update. I signed in last night with no problem. Just hope it keeps working correctly and there aren't any more problems. Appreciate the information.
1

slippy

I tried using it but it doesn't work for me. It says I don't exist!
0

ColdDragon

I cleared my cookies on both Chromebook and phone browser. Used the new login on both devices and the message at the top of the screen went away. When I came back on phone browser the new login message was back on top of the screen. I'm able to play the site so I'm not stressed but it is a worry since it's acting like I'm still on old cookie and login.

Using Chrome browser on Chromebook. Edge browser on Android phone.
2

Arcania

I am impressed - at least from my experience this is the most seamless rollout I have ever seen for account/authentication updates.
6

Synth

I waited until now to touch this since so many people were having problems and I was able to log in on my phone and desktop without issue (at least, none that I have detected so far). Just saying this for anyone else who may still be hesitant to try.

Thanks for working to keep us secure, Subeta!
7

LothlorienRain

Once I found where I can find my email I used to sign up (located in Preferences) I was able to sign in with now problems so far.
2

Julie

Disregard, I think I'm at the Legacy Site.
0

Julie

It doesn't recognize my email address at the new authentication site.
0

ChatLunatique

Interestingly I initially got the "invalid password" error, but being the stubborn old bat that I am, I called the system a few choice names and smashed the enter/next/whatever button anyway. It let me in without any further problems. :)
4

Banana

Everything has worked for me so far. I relogged in on my work computer and on my home laptop, both Mac's and both using Chrome. My desktop at work said invalid the first time but worked the second time, I waited like no time in-between attempts. I don't know if this information helps at all but I figured I'd share incase it did lol
1

Shannon

@Galaxia Hi :) Everything has worked fine for me so far, but I was wondering if we were being encouraged to go ahead and change our passwords or if we should wait until you guys tell us it's time?
0

BoaConstrictor

Judging by the measly number of users online, a lot of people have successfully locked themselves out of Subeta :-(
9

BoaConstrictor

*Invalid email or password*
Fortunately
1) I tried on my fairly useless, tiny, slow, garden/vacation meant notebook.
2) I still had another Subeta window open, a random link of which opened up the old login page - which let me in
3) old login still possible & works

I have never in all those years changed my e-mail for Subeta.
Obviously the password I tried numerous times, is correct.
I did add https://auth.subeta.net to my very few allowed cookies.
3

corvoo

so weird how we get this news on the same day as neopets' data breach. yet another reason why subeta is superior 😝
7

BleedingOrange

I've logged in 2 times with new method but when I go to another page the message is still on top saying I'm using the old one
0

the_beast

cant see the games tab?
0

yellowdream

it's saying my password or email is invalid, been trying but still getting messageat the top, will I loose my account so worried ..
1

Ciannwn

Managed to log in with the new system yesterday and the banner disappeared. Came on this morning to see the banner again telling me I'm logged in under the old system.
0

Luck

@CastlesInTheSky Notice that we needed up-to-date email addresses for this process was posted a month ago : News post
27

NekoHime

Is it important to long in that way before midnight?because if so then I already failed
0

CastlesInTheSky

Just out of curiosity..
Ever hear about giving people fair warning? or SOME KIND OF FN' notice?
I never stay logged in & I aint got a clue what my email is that I use on this site. I had to search around for anything that looks remotely familiar. 40min later here I am. But not from the new login. I signed in using the old page using my username/passwrd. I
ll go look what my email is later.
Do my head in
2

Luck

I'm not sure if I just typed my pw wrong the first time (unlikely, I'm slow and careful) but I also had the invalid email/pw error the first time. I refreshed the page and typed my pw again and it worked that time. Not sure if refreshing/trying more than once will help anyone having trouble.
0

Coma

Logged in to the new system, changed my password because it was due for a refresh anyways — worked like a charm across all my devices. Thanks! We love a good security/transparency update.
2

Kinky

Looks like I missed all the fun because I was able to reset my password, and it worked perfectly.
5

CassieFenix

@Galaxia

Thanks for putting the link to the profile page here! I was trying to log in with my new email address which I changed a while back but couldn't, so when I checked my profile, I realized I had my old email address there! Updated it and fixed it so I could log in using the new method.
0

Bliss

I logged myself into the new system on my laptop, but I see it didn't change me to the new login on all my devices as I still have the message on mobile
@Galaxia
0

oilbird

@Galaxia Great, thank you!
0

Bren

So far so good- I logged into Subeta via the Authenticator site on my iPad first- then updated my PW and logged on using my phone. I’ll set it up on the laptop tomorrow! πŸ‘πŸ»
1

Tammynoneed20

Well I kept getting logged out on chrome this time I couldnt log back in so I'm back on firefox and no troubles yet and the forums are working for me on firefox
0

Faizh

this change comes in a very interesting day. thanks for this update.
0

Chef

One issue that I do have with the changing of the password system as it is currently is that it doesn't send a link or anything to your email to click on. It just allows you change the password. I also didn't receive any email stating that the password on my account was changed.
2

sundaykid

Yeah, same as a lot of other people, it's saying my password or email is invalid, and won't send a reset email, and the email is definitely correct.
1

raw

thank you for working so hard with Subeta ;-; I love this website, am so happy and thankful for the people who keep it running <3
8

Dracona

could not change my password. logged in ok, but wanted to change password and the submit button is greyed out despite having all the rules followed and passwords matching. :(
@Wizardpinky go to Dashboard then click Profile on the top tabs to find email.
2

micheleey

@Galaxia
Will do, thank you for your help!! :)
1

Galaxia

@micheleey
Please file a ticket, then! If it's something that needs patching or there are more troubleshooting steps we can do, the ticket is going to be the best way to have the info handy and follow up.
1

micheleey

@Galaxia
Yes, it is the same Email
0

Galaxia

@micheleey
Hmm, a little trickier then...is it the same one that you have listed on your https://subeta.net/preferences.php?act=profile?
1

micheleey

@Galaxia
Yes, I am putting my email.
0

Galaxia

As a reminder for people, unique passwords are going to be the best way to protect your account! If your current password is the same as another site, now would be an excellent time to change it to something you don't use anywhere else. Or, if you are taking the opportunity to make a new one, don't re-use it on other pet sites.
9

Galaxia

@micheleey
Make sure you're putting in the email address, not just your username.
2

Galaxia

@oilbird @Valiska
2FA will be voluntary, just like PINs were!
6

micheleey

It's not working for me on Ipad or Windows computer. Both are saying invalid Email or password.
0

PeachGoblin

finished, went smoothly for me :3

appreciate the work being put in ^_^
2

Valiska

I hope 2FA remains voluntary. I already have to have my phone with me to get any paid work done, I'd like to be able to put it down to play :)
3

EvilRedDuckie

thank you for all the hard work you've all put in to address this issue. i'll keep my fingers crossed that this solution will stop all the insanity. :joy:
3

Daydream

Thanks for all your hard work!!! I really appreciate how Subeta cares for its users safety - especially as That Other Site had yet another data breach TODAY! I hope it all works out smoothly.
6

oilbird

Will it be required to opt into 2FA?
1

Shannon

So wait, should we go ahead and change our passwords? Or should we wait until you guys tell us to?
4

Luce

Would love to say it worked. I logged in the new way. And went back to my page five minutes and had to log in again.
0

Tammynoneed20

Even tho I cant get into the forums I'm happy to be back on chrome
0

Avel

I couldn't login in on my mobile but my computer worked on my first try.
1

Austria

You guys are fighting the good fight. Good luck wrangling everyone, explaining everything, and doing the boss battle with the code.
8

Nebet

I've been able to log in fine so far, but should I update my password now or wait???
1

Galaxia

@Xuanmeng
Make sure you're putting in your email address, not just your username, and that it matches the one you have listed at https://subeta.net/preferences.php?act=profile.

@MarchOnOff
Select old/legacy Subeta on that screen!
7

theraphos

Thank you for your hard work! I'm always a fan of 2FA, looking forward to it.
1

Reekoh

I haven't been asked to log in, but I am getting robot checked very often. It hasn't happened for a couple of days, so knock on wood.

https://subeta.net/forums.php/read/926879/Anyone-else-constantly-getting-Are-you-a-robot-checked/1/#66224952
1

Tammynoneed20

I'm on chrome and was able to log in but the forums are not wanting to load I get this at the bottom of the loading If forums are loading infinitely, please make sure you are logged in on New Subeta.

Trying to read a staff post? Check our Admin Posts page if you are unable to load the forums.
0

MarchOnOff

So where do I log in, to old subeta or new subeta? and if I log in one, is the other working? I so don't get it...or like it...
3

Xuanmeng

What do we do if auth.subeta.net doesn't recognize the email address connected with our account?
1

-HyperBlossom-

@Nikole thanks honey, but for some odd reason it wanted me to type in my email. Don't know why. Everything was spell the same and correct. Thanks again honey :heart:
1

Hound

I'm all about cyber security lately!
Thank you, Subeta!
3

Narshe

@-HyperBlossom-
If you're having trouble logging in on mobile with the correct information, double tap the login and it should work.
2

Solas

I personally think its great that Subeta is moving forward to better site protection 😍 I just wish I understood the technical aspects of it all πŸ€” I have Asperger syndrome and sadly its not easy for my brain to understand things that I've never learned before.
7

Delirium

Thank you!
Worked for me. Happy to see better security for logging in!
1

-HyperBlossom-

That's strange. The login works on the desktop, but if I try to login with on my phone it doesn't take my email address.
0

Galaxia

@capper09
Older passwords may not be safe anymore: Neopets just today, for instance, had a major security incident with their entire database exposed. We just want to make sure we're keeping everyone's accounts safe.
Go to https://auth.subeta.net and follow the directions to reset your password, make sure it's got a mix of capital letters and symbols and numbers to make it harder for other people to guess it! Choose 'legacy' when it gives you that option. The rest of it, the technical stuff, you don't need to worry about it. We just have the details there for people who are curious.
9

frederick

@capper09 Subeta has switched to a new, more secure login system that does a better job of making sure you're you and protecting your password from hackers. In the near future you will be asked to change your password just to make sure your account is safe. You will also be able to enable two factor authentication using SMS or an app for extra security if you'd like.

(I think that covers it for nontechnical stuff?)
4

Petlover

ok thanks for letting me know
0

Galaxia

@Petlover
If someone takes your device, they can get into your accounts with saved passwords, yes. However, one of the things this change lets us do is provide a button that allows you to log out across all devices. So if you save your password on your phone but you lose it or someone steals it, you can use another device (your computer, a friend's computer or phone that you trust) to log out even if you don't have your phone.
6

Anrivef

That worked flawlessly for me, I entered my email and password and was brought to a handy page where I got to choose to redirect to either Subeta 2.0 (where the wardrobe, CW market are held) or Legacy Subeta (where everything else remains so far). I can understand some of the hesitancy but I guarantee each and every one of y’all are constantly having your data sold by every company you purchase from, even the pharmacy. And I won’t even delve into all the ways our phones betray us. So please don’t allow a fear of new things to keep you away from this site. As Subeta moves into the future, so should we users.
12

capper09

what.. ??? is there anyone here who can please translate this into german for a non-technical user...? ? the translator tells something about keys, baking and secret pages... ??? please via priv. message.... thank you, thank you... i didn't understand anything... i am happy when i get a plug into the socket without an accident and now so much technical...
3

Petlover

euh how does that work i never save passwords on my pc in the case it gets stolen and the thief can go in all my accounts then
1

Chef

Bitwarden is a good free password manager if anyone is looking for one. It has a mobile app as well.
4

Chef

I'm glad that I checked that I had a current email address about a month ago when this was first mentioned in a News post. It made logging in pretty simple. :-)
1

Ciannwn

It worked when I tried again.
0

Galaxia

@Petlover
Can you save it in your browser, so you don't have to put it in all the time?
8

Petlover

i sadly problbly have to quit subeta now i'm autistic and really can't take to remember a new too hard to remember password with all the extra's
2

FCoD

It worked this time.
0

red5luke

Had to change my password in order to use the new auth site, but it wasn't the strongest, so understandable. Also wish it used username instead of email address for login, but that's not that big of a deal.
1

Galaxia

@-HyperBlossom-
It's totally cool and my pleasure to help, I'd rather get double-pinged than no notice at all.
You should be all set, then!
3

-HyperBlossom-

@Galaxia I did change it though the preferences.php?act=profile so that should work fine. I'm just trying to make sure I understand everything right before I change my password. Sorry I hit the wrong button that's my fault again super sorry Galaxia
1

-HyperBlossom-

0

Narshe

Worked fine on the first try.
2

Celesdragon

Worked perfectly for me on the first try.
2

Solas

This whole thing hurts my brain. It took forever for me to figure out how to log in right πŸ˜’
4

Galaxia

@Targaryen @Tammynoneed20
Please try again, there was an issue where the first time did not go through even if you were entering the information correctly. This should be fixed for you now, as well as for people trying the first time going forward.
2

Lucifer

took my email and password just fine, logged me in right away.
3

FCoD

I used my correct email but it says it is invalid.
1

Galaxia

@skydreamer

You can see what email you currently have set at https://subeta.net/preferences.php?act=profile. If it doesn't match or you need to set it to something else, send a message to support@Subeta.net.
5

skydreamer

As an add-on to my last comment..

Her account has been part of subeta for over 15 Years. It would be ... Frustrating to say the Least if it were lost due to this not being mentioned in the news Before it was implemented.
1

skydreamer

VERY IMPORTANT...

What if we have forgotten what email we signed up with because we Always leave our account logged in and/ or logged in using username and password for the last who-knows-how-many years? Is there a way to change our email and Then log in using the new method? What if we already tried logging in using the new method and didn't realize our account was on an old email (and therefore cannot be accessed)? (There is someone I know who is Already having issues with this..)
1

Bathory

Completed
0

Eivor

I guess I did it right because the banner went away. Even though it rejected my correct email and correct password the first time around.
2

Wizardpinky

finally works after hours of trying ^^
0

lightnight99

hmm.. I'm just guessing here, I tried numerous time to login in, didnt work, changed password, still didnt work. But I changed my passw again with 1 capital word and special others, I didnt with old pasw, but this did worked after that. So I Finally got in, ^-^
0

NekoHime

@Galaxia just making sure, thanks for understanding
0

Targaryen

It will will not let me sign into the new system! I guess user not found needs to be found!
1

Galaxia

@Hyperblossom
You shouldn't have to switch back to using gmail for Subeta! See if you can change your email on https://subeta.net/preferences.php?act=profile. If not, you can email support@Subeta.net to set your protonmail address as where you want Subeta emails sent.
4

spookypeach

I did have to reset my password but it seems to have worked fine for me otherwise.
0

Galaxia

@Loki
We are hoping to polish the page further and add some more elements to really solidify the look and feel, yeah! We just know that people have had to work around authorization issues for a while and wanted to get this out there, especially with the other changes such as the new email provider.
2

-HyperBlossom-

Hey wait I switch my email to my proton mail does that mean I have to switch back to my Google mail?
0

kytten

eyo it worked eventually! (i swear complain about a thing and it works just to shut you up lol)
2

Someone

Worked on the second try.
0

Loki

I understand, it is the easiest and most secure method for Subeta. Keith is literally a one more show holding everything together (we appreciate you).

That being said, it still feels like a gotcha page/phishing attempt.
1

frederick

@KeithTest Maybe this might be of use if you have time, but as you point out, it may be too much work with very little payoff.
3

Galaxia

@Loki @NekoHime
The Internet is a tricky place, especially these days, and your caution is understandable. But a centralized auth system/site is the best way to integrate old and new Subeta, and be able to make changes as needed to the process. If Keith tried to design it separately and implement it across different pieces, changes would be immensely more complicated as well as break features individually.

For instance, the fix that Keith just deployed for emails/passwords not matching wouldn't be so easy without that centralized site. This also means that if there's a leak or vulnerability from somewhere upstream that needs patching, it can be done immediately across everything. It's way easier to fix vulnerabilities this way as well as make improvements.
2

Mikestoker51

Galaxia it seems to be working for the time being, I logged out of the site all together and tried to log in and I managed to log in this time although I had a choice of two options classic subeta or something dealing with the wardrobe (not sure now) I clicked on the classic subeta and I was in and so far I am not seeing the banner at the top of the page anymore about logging into the new site. Hope the fix worked for me.
0

Tammynoneed20

I tried it in chrome on my phone and all I get is this error Incorrect username/password combo! So I'm staying in firefox forever n I'm too scared to try it in firefox cuz I might not be able to log back in
2

KeithTest

Galaxia mentioned email, and I think that's another good example of a change that happened behind the scenes here. We're testing the transaction e-mail flow (lost password) from a new provider that does not track clicks or opens, and is generally more privacy and consumer focused.

Our normal emails up to this point come from one of the major email providers, who's job it is to get as much data about you as possible from us. Data that we never investigate (I've never once looked at how many people open our emails -- that is probably why I'm not a millionaire ;p) or use is packaged and sold downstream without any of us knowing, and tbh I'd rather not do that.

Anyway, just a fun lil tidbit!
7

Reaper

@KeithTest @Keith (sorry not sure which to ping)
Before I do any of this, do you know how this might affect third party sites that allow users to log in (like SubetaLodge) and maintain lists like collections or allow the staff for the sites to add new items as they're added here?
0

Ciannwn

The email on my profile is the one I've always had and which received Subeta newsletters when you used to send them. I deleted Subeta cookies in my browser but the new link login still said invalid email or password. I was able to log in again, though, using the old login. I'm just going to leave it for now until whatever bugs there are have bee sorted out.
4

frederick

@KeithTest yubikey might also cause a lot of CS tickets in the event people lose their keys. The benefit, though, is it being a brick wall to account takeover. For me personally, it's sent a stalker packing after I got tired of them attempting to get through the time based code on my email. i wish more sites supported it.
1

Donteatacowman

OK, I got it to work! I had to clear out my cookies on my browser, which also logged me out. Then I went to the new login site. (A link to this on the old login page would be appreciated, but presumably those changes are on the way.) It still didn't work with my autofill password for some reason, but when I manually typed it in, it worked!
0

KeithTest

@Darkersolstice 🀦‍♂️ Fix for that typo incoming.
5

Galaxia

@Sleeb

You can see what email you have set at https://subeta.net/preferences.php?act=profile.
5

Darkersolstice

You may want to check some of the spelling on the new login page. Things like "catious" instead of "cautious" make it look kinda scammy.
7

KeithTest

lol forever logged into my testing account because of all of the auth stuff 😭
9

Bunny20

Okay, I finally got it to accept. Changed the pw AGAIN and then it finally took. *fingers crossed*
0

Sleeb

I don't know which email I used to sign up. It was a long time ago. ;u;
0

KeithTest

@frederick We'll offer time-based & SMS based (both via twilio, so authy/g authenticator will work). I honestly dunno how to support yubikey / it likely wouldn't be worth the time to learn it.
0

Synth

Hm, ok, well, looking through the comments here I think I'm just gonna wait awhile before I mess with this...
4

KeithTest

@feral I tried to be as clear as possible in the news post that there was no immediate danger of being logged out, or kicked out of your account if you couldn't use the new system, I guess not enough πŸ˜…

I'm glad it worked in the end, that was the deploy that Galaxia mentioned I pushed out to fix the issue and I hope it's not a problem again!
2

Konichu

Logging it without problems!
0

frederick

Please consider the use of out of band 2FA:
Time based token (Authy, Google Authenticator)
FIDO2 key (Yubikey, Titan, Solokey)
3

Galaxia

@Mikestoker51
Are you still having this issue as of 12:53pm? Keith deployed a fix for the password/email issue, but please let us know if it's not working!
2

Mort

Personally I was able to change my password, thanks for the fix!
0

Loki

I have logged in via the new method, but I still have the "using old cookies" bar. It disappeared for a few and came back.

Also agree with the going to have to agree with others. Using an external site to log in seems phishy.
6

Mikestoker51

Same thing here I tried to log into the new site and it is telling me that my e-mail is invalid and I know for a fact that my e-mail address is correct, because that is the only one I have ever had and used, I have no other e-mail address. I have no problem at all logging into the old system.
0

Galaxia

@Raven
Make sure that the URL is https://auth.subeta.net, and that it has a little yellow lock next to the kumos. Thank you for being security-conscious and asking!

Keith has also deployed a fix, so please try again now if it wasn't working before.

We're currently working through emails as well; as part of the backend work we've gone to a new email provider and there's a bit of a backlog, but that is in progress!
5

Hamda

Going "I forgot my password" did nothing. Never got an email... oddly enough double pressing after getting "invalid password/email" worked.

I guess this responds to the metaphoric banging on top of the TV to get the station
2

NekoHime

Are you sure that's not a fake link? 🧐
2

feral

Well this was horribly stressful.
I logged out and tried to log back in, got the same as a lot of people here are posting: "Password invalid"
Tried to reset my password about 5 times (waiting a few minutes between each and checking every folder in my email).
I had logged out so there felt like there was nothing I could do?
I ended up just spamming trying to log in with my email / pass I knew was correct and after trying REPEATEDLY, it suddenly accepted the password.

Yikes.
11

castyourshadow

Ditto to no email being sent to reset password. I was also a tester of this, so I'm not sure if that has anything to do with it.
0

Norn

So, email should be correct as I get the newsletters. Password is correct and it has special characters, numbers, capitalization. Yet invalid email/password at auth.subeta.net. Tried reset password - I'm still waiting for the email.
Anything else I am supposed to do?
0

Baikou

My password and/or email is somehow incorrect even though I double checked.
1

Meliora

Same thing here, can't log in, PW reset not working. Checked, using correct email.
1

fizz

Mine worked fine???
0

Raven

@Keith if it takes me to another site, how can I be sure that site is safe to login in with other sites being fake but looking authentic and those sites are doing phishing?
10

Dandelion

Yeah, same as a lot of other people, it's saying my password or email is invalid, and won't send a reset email, and the email is definitely correct.
2

Retro

not working for me. keeps saying invalid email and will not send the reset email ... it's the same email i have used for years and gotten emails from subeta before.
3

Donteatacowman

Ditto with everyone else - I checked my email address and password to confirm that they're correct. I did actually just reset my password, got booted off the site, and was unable to login through the new system - but able to log in with the old one.
4

Oak

I have to say I´m not a fan of anything centralized, these days, really.

Is that an external site?
4

Star

I just changed my old password to a new one, and it still says incorrect. I'm sure I used the correct email and password. Now I'm stuck on mobile πŸ™ƒ
2

Ronarah

Changed my email address a while back, went to login on new thing and says password is wrong. Went to reset password and haven't gotten an email to reset it. :(
1

Mort

The "Reset Password" button is greyed out for me, although my new password meets the requirements. πŸ€”
I hope I won't be logged out anytime soon, otherwise I'm in big trouble!
2

Ashalilly

Not working for me, it's saying the email or password is wrong, but I did just log in using the same password. Is there any way to check if there is soome other email associated with the account? Never needed anything but a username before.
1

ImpalaFreak8877

Says invalid email
2

kytten

Glad i'm not the only one having issues >_>; Not accepting my login, and not sending me a reset pw. 🀷
1

NekoHime

What in the name of...0.0;;
2

Aimee

It's saying my password is wrong... it also will not email me a reset link and i'm using the same email that's in my preferences.
2

Bunny20

I tried to do it and it said my password was invalid.
I changed my password, it tells me the email is invalid.
What do I do?
0

Ciannwn

I followed the link to auth.subeta.net. and tried to log in but was told "Invalid email or password"
0

lilybobilly

Resetting password managed to work for me!
0

Paula

It says to me, "Invalid e-mail or password", I even changed my PW today to make sure it was correct, and the e-mail I'm using is the same on my profile, I don't get what's wrong. ):
4

Laurey

Quick question though, if we changed our password now will we still have to change it again soon like was mentioned in the news post?
1

sushi

Resetting the password didn't work for me. :(
1

Deerest

wanted to use my old pass to log in too, had no choice but to reset it using the new site as it didn't take my old one. hopefully the new site solves the problem for some people not being able to do stuff cause they're constantly getting logged out!
0

Laurey

I also was having trouble logging in at first, but resetting my password worked (I was also using kind of an old and weak password that didn't meet the conditions of the new system).

I'm not seeing the banner at the top anymore either.
0

Evil

Scratch that - its gone now ^_^
2

lilybobilly

I'm having the same problem, too. I am very certain I'm using the right password and e-mail.
2

Avel

I might need to reset my password too but that's not a hassle I'm doing on my phone. That can wait a few hours.
1

Evil

I'm also getting the message that i'm using the old cookie still even after clearing all cookies and logging in fresh using the new auth.subeta.net website
3

SeleneOryx

It is still saying I'm logged in via old system at the top of the page, though
1

SeleneOryx

Resetting password worked. I think it was because I didn't have a special character in my old password, so wouldn't be accepted under the new security requirements for a strong password?
0

Avel

Yeah, ot having any luck logging in either.
1

KeithTest

@SeleneOryx I'll take a look, but in the meantime you can do a password reset on https://auth.subeta.net!
1

SeleneOryx

It's saying my password is incorrect, even though I'm using the saved password on my browser .... Tried every email I own, and even changed it under dashboard -> profile -> email.
6

Wizardpinky

thanks!
0

KeithTest

5

Wizardpinky

I click on the link and it says enter email. What happens if you forgot the email you used? Is there a way we can look it up? If not, would there be an option for username??
1

Leave Comment

Comments are currently on a short cache, meaning your comment may take a few minutes to show up after you post it.


-or-