Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. Other Discussions
  3. The Insider News
  4. Why Federate?

Why Federate?

Scheduled Pinned Locked Moved The Insider News
javascriptphprubygame-devsecurity
2 Posts 2 Posters 0 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • T Offline
    T Offline
    Terrence Dorsey
    wrote on last edited by
    #1

    ongoing by Tim Bray[^]:

    You’re putting up a new app and need to sign in users, so you use whatever’s popular with the package you’re using: On Rails, typically Devise, on NodeJS Drywall or Passport, on PHP Usercake, and so on. These things will take care of storing and checking usernames and passwords for you. But storing and checking passwords is a bad thing to do. Why? There are too many passwords.

    By playing the yet-another-password game, you’re decreasing the security of the whole Internet.

    A 1 Reply Last reply
    0
    • T Terrence Dorsey

      ongoing by Tim Bray[^]:

      You’re putting up a new app and need to sign in users, so you use whatever’s popular with the package you’re using: On Rails, typically Devise, on NodeJS Drywall or Passport, on PHP Usercake, and so on. These things will take care of storing and checking usernames and passwords for you. But storing and checking passwords is a bad thing to do. Why? There are too many passwords.

      By playing the yet-another-password game, you’re decreasing the security of the whole Internet.

      A Offline
      A Offline
      AnalogNerd
      wrote on last edited by
      #2

      I am a little hypocritical when it comes to Federation. Like a lot of the commenters on that article I will more often than not refuse to use a federated login when signing up for websites. If the only way in is through FaceBook or Google then I'm not signing up for your site. However, here's where the hypocrisy comes in, I'm working on a website for my own fun and because I'm lazy and don't want to deal with passwords and security right out of the gate, I'll probably make the only registration options go through Google/Facebook/Twitter. Eventually I'll probably roll my own, but initially I'd rather spend my time coding the core of the site, not registration.

      1 Reply Last reply
      0
      Reply
      • Reply as topic
      Log in to reply
      • Oldest to Newest
      • Newest to Oldest
      • Most Votes


      • Login

      • Don't have an account? Register

      • Login or register to search.
      • First post
        Last post
      0
      • Categories
      • Recent
      • Tags
      • Popular
      • World
      • Users
      • Groups