To LUGNET HomepageTo LUGNET News HomepageTo LUGNET Guide Homepage
 Help on Searching
 
Post new message to lugnet.admin.generalOpen lugnet.admin.general in your NNTP NewsreaderTo LUGNET News Traffic PageSign In (Members)
 Administrative / General / 6056
6055  |  6057
Subject: 
Re: Automated password appraisal (Re: New feature: Article rating)
Newsgroups: 
lugnet.admin.general
Date: 
Thu, 13 Apr 2000 04:23:52 GMT
Viewed: 
3949 times
  
In lugnet.admin.general, Matthew Miller writes:
Todd Lehman <lehman@javanet.com> wrote:
  http://www.lugnet.com/people/members/pwsa/

Oh, hey, I'd missed this. Two suggestions:

1. Can you use https for this?

What's involved in setting up an https server?  I remember reading once upon
a time (it must've been about 2 years ago) that it could be kind of a mess,
and that connections often took 1 second to authenticate.  That would be a
problem for random HTTP requests using cookies, but the password isn't plain-
text there so it's less risky.  For a sign-in or a change-password page, it
would be OK if it took a second or two.


2. How about a 'passwords submitted aren't logged' privacy statement?

OK.


Why? 'Cause it's so cool I was instantly tempted into typing in old
passwords that I no longer use, and was almost tempted into typing in
passwords _currently_ in use. (And by Larry's posts, I see he was tempted
too...) Bad. :)


Also:

/|\@++|>/|\ =  361%  Excellent (PASS)

Do those symbols that supposed to mean something?

--Todd


:)





Message has 1 Reply:
  Re: Automated password appraisal (Re: New feature: Article rating)
 
(...) It's not too hard. But I forgot; you're using a web hosting place. (Pair?) Depending on what level of service you're paying for, you may already have ssl support. (Or conversely, it may not be an option.) (...) I've not noticed that bad of a (...) (25 years ago, 13-Apr-00, to lugnet.admin.general)

Message is in Reply To:
  Re: Automated password appraisal (Re: New feature: Article rating)
 
(...) 1. Can you use https for this? 2. How about a 'passwords submitted aren't logged' privacy statement? Why? 'Cause it's so cool I was instantly tempted into typing in old passwords that I no longer use, and was almost tempted into typing in (...) (25 years ago, 12-Apr-00, to lugnet.admin.general)  

309 Messages in This Thread:
(Inline display suppressed due to large size. Click Dots below to view.)
Entire Thread on One Page:
Nested:  All | Brief | Compact | Dots
Linear:  All | Brief | Compact

This Message and its Replies on One Page:
Nested:  All | Brief | Compact | Dots
Linear:  All | Brief | Compact
    

Custom Search

©2005 LUGNET. All rights reserved. - hosted by steinbruch.info GbR