๐Ÿ”’ Authentication Fixes

If you've been having issues logging in for the last two weeks, I'm incredibly sorry. After making the change to the new authentication system, a (very large) handful of users could no longer access their account, and the new lost password flow didn't work correctly.

I've fixed the issue, so if you're still not able to log in, please make your way to kumos login page and start the lost password flow. You'll get an email, and be able to set a new password.

We've created a new free gift page that gives you a visit for the bath house days, updates your melody achievement and some CSC for the trouble. I know this doesn't give the prizes for those bath house / melody days, but we'll be making those items available (like always! we hate gateekeeping melody items!) soon.
User Avatar: 1

Posted by Keith

jersey
Thank you!
Saturnine
oh phew, nice, thank you @Jess
Jess
@Saturnine Keith confirmed on Discord that it is for everyone. Freebies like this have historically always been open to everyone.
Nebet
Thank you!
Saturnine
I feel like if it wasn't intended for everyone, the affected parties would be told to send in a ticket (or attempt to), but can we get a ruling if the freebie is open to everyone, or if we who got it without hving trouble should make a ticket? @Keith.
Socialist
Thank you!
DimDim
Thank you sooo much for doing this for us. I loose all my hundret's of Bathhouse Points, but --- geting this csc is so much better and the items from Melody i miss i bought after checking the Lodge, what she gave. Important is that we all can play now, tytyty for doing this
youngexplorer
Echoing Oreo and Mich. Thank you Subeta.
Bliss
@Puncture
I'm not sure if it's for everyone, or only those who lost streaks and melody
Puncture
@Bliss I didn't miss bathhouse or melody to my knowledge and got the prizes. You just click open gift?
L0stS0ul
@Saturnine
No, click around some more. I didn't miss my melody or bathhouse streaks and I was still able to claim the 500CSC. I got the 404 error page too at first. I don't know exactly what I did but I clicked around some more and managed to get it working.
Saturnine
The page doesn't give a 404 anymore. Is the prize for everybody or just people who didn't / couldn't log in? I'm not sure if I was supposed to get it but I clicked and it all showed up for me ._.
Bliss
I had a hard time logging in during thise 2 weeks. I was also unable to change my email, had a lot of blank pages and errors๐Ÿคท‍โ™€๏ธ
Tomorrow
Thank you Keith!! I missed some of the melody items ;-; You and your staff are awesome <3
Mort
Awe thank you for everything. Long live Subeta! :raised_hands:
Bliss
Not to complain, but, the users who missed bathhouse and melody will get their prizes and 500 csc. What about the rest of us, who had a hard time logging in, or had other issues with bank pages, errors and unable to change their email and unable to purchase csc don't get anything?
Saturnine
Oh it's for people who missed bathhouse days? That's a neat way to do it :o
Saturnine
Thank you; My CSC didn't increase and the page is a 404 so idk maybe it's hit or miss who gets it.
HYPEBEAST
Claiming on mobile seemed to work for some reason? At least my CSC amount increased
LizardLady
This is incredible. Thank you guys so much.. best team ever!
HYPEBEAST
I get a 500 SERVER ERROR while trying to claim. Crying
Senti
Thank you for all your hard work Keith! And also the rest of the Subeta team!
Kaje
A friend of mine was having general trouble with a password reset. Will this fix also help that? Thank you so much for this!
splendabae
so sweet of u! thank u for working so hard on fixing it for everyone. and thanks for the csc~
Keith STAFF
TLDR: I've tried to migrate us from using md5, the incredibly, horribly, outdated hashing algorithm that is now easily breakable for years. Every time, we've kept a bridge to the old passwords for folks who don't update, and just use newer algorithms on new passwords. That finally came to bite us, and I had to move to remove all of the md5 hashed passwords from our database. We didn't have a security breach, but it just needed to be done.

Your password in the database is stored as a hash of what you type in when you log in (or created when you registered). We never see what the actual password is after you log in, we just compare it with the hash in our database. That makes upgrading it to newer schemes very difficult without forcing everyone to reset their password.

There were a group of users who'd been in one of those migrations, and this new method didn't work (just completely error'd in a way I couldn't see in my tests). That's resolved now, and all of those accounts can get new, very very secure hashed passwords in the database.
Oreo
This is so kind ;v; thank you so much, subeta staff ♥๏ธ your kindness never fails to make me feel all warm inside c: you guys care for us users greatly and it has always shown!
Mich
Thank you guys!! I've always appreciated how much you care for your userbase. <3

Leave Comment

Comments are currently on a short cache, meaning your comment may take a few minutes to show up after you post it.