GBA Logo horizontal Facebook LinkedIn Email Pinterest Twitter X Instagram YouTube Icon Navigation Search Icon Main Search Icon Video Play Icon Plus Icon Minus Icon Picture icon Hamburger Icon Close Icon Sorted

Community and Q&A

Trouble with GBA Login

ARMANDO COBO | Posted in General Questions on

The GBA inform me that its in the “process of upgrading our subscriber experience” and I needed to change my password, except I can’t find a place to change it. The temporary password will expire in 72 hours. Does my name needs to be in all CAPS? Any thoughts?

GBA Prime

Join the leading community of building science experts

Become a GBA Prime member and get instant access to the latest developments in green building, research, and reports from the field.

Replies

  1. Expert Member
    BILL WICHERS | | #1

    There is a link from the email GBA will send you when you request a temporary password through the "I forgot my password" link on the login page. Go to the page at that link, it will automatically fill in the temporary password, then enter a new password that meets their requirements. I typed in my username in all lower case, which is pretty standard. The password box REQUIRES a mix of upper and lower case, and at least one special character, which you can think of as "something you type while holding down the 'shift' key". Usually people use something from shift+[any number key] as their special character.

    I'm not a fan of forcing a bunch of special characters in passwords like the new GBA system is requiring. People think "wow, this will make it SO much harder to brute force a password!", which is true. But it's easier to just put a timeout in the login (after three attempts, lock out for five minutes, something like that), which makes brute force login attempts impractical regardless of the structure of the password as long as there are enough characters.

    In my old sysadmin days (which were a long time ago), I remember always thinking to myself that the more complex I required passwords to be, or the more frequently I required passwords to be changed, the more often I would, as the sysadmin, by tied up chaning peoples passwords when they forgot what their new one was.

    Bill

    1. Deleted | | #2

      Deleted

Log in or create an account to post an answer.

Community

Recent Questions and Replies

  • |
  • |
  • |
  • |