Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. The Lounge
  3. Ridiculous safety or not

Ridiculous safety or not

Scheduled Pinned Locked Moved The Lounge
testingbeta-testing
18 Posts 8 Posters 0 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M Mark_Wallace

    John R. Shaw wrote:

    I propose a two level login. A login to pay the bill and a login to access account information. Most of the time you just want to pay your bill, so if someone compromised that password - who cares. If they want to pay the bill for you - let them.

    So knock up a library/plug-in for it, and charge several times what you think it's worth (if it's cheap, people won't trust it). You've put the idea out there, now, so you'd better hurry, before someone else gets early retirement from it.

    I wanna be a eunuchs developer! Pass me a bread knife!

    J Offline
    J Offline
    John R Shaw
    wrote on last edited by
    #6

    :laugh: You think I am the first person that thought of that. I doubt that cracker's are going to request more services or a change of address. But one level entry point is a security issue, no matter how you phrase it.

    INTP "Program testing can be used to show the presence of bugs, but never to show their absence." - Edsger Dijkstra "I have never been lost, but I will admit to being confused for several weeks. " - Daniel Boone

    M 1 Reply Last reply
    0
    • J John R Shaw

      :laugh: You think I am the first person that thought of that. I doubt that cracker's are going to request more services or a change of address. But one level entry point is a security issue, no matter how you phrase it.

      INTP "Program testing can be used to show the presence of bugs, but never to show their absence." - Edsger Dijkstra "I have never been lost, but I will admit to being confused for several weeks. " - Daniel Boone

      M Offline
      M Offline
      Mark_Wallace
      wrote on last edited by
      #7

      John R. Shaw wrote:

      You think I am the first person that thought of that.

      It's bleeding obvious but it's not ubiquitous, so either no-one has thought about doing it like that or no-one has done it. All it needs is a little div, about the same size and shape as the godawful recaptcha thing, that allows the site owner to easily wire it up to accept context-sensitive user names and passwords.  Sites that currently do things like that don't exist (from what I've seen), and pre-written password-entry scripts are mostly unsafe, too simple, or so complicated to use that you might as well write your own -- and making them context sensitive would be an exercise in futility, because they only do the easy bit. You want better: write it, sell it. Don't give it away, because many business don't like trusting this kind of security to unsupported freeware.

      I wanna be a eunuchs developer! Pass me a bread knife!

      1 Reply Last reply
      0
      • J John R Shaw

        Really, one word. I spelled sites wrong, so what?

        INTP "Program testing can be used to show the presence of bugs, but never to show their absence." - Edsger Dijkstra "I have never been lost, but I will admit to being confused for several weeks. " - Daniel Boone

        M Offline
        M Offline
        Mark_Wallace
        wrote on last edited by
        #8

        You odviously have to do a site better, if your posting in the CP Lounge.  People can be very critical they're.

        I wanna be a eunuchs developer! Pass me a bread knife!

        N 1 Reply Last reply
        0
        • M Mark_Wallace

          You odviously have to do a site better, if your posting in the CP Lounge.  People can be very critical they're.

          I wanna be a eunuchs developer! Pass me a bread knife!

          N Offline
          N Offline
          Nelek
          wrote on last edited by
          #9

          Mark_Wallace wrote:

          People can be very critical cynical

          FTFY :rolleyes: :rolleyes:

          M.D.V. ;) If something has a solution... Why do we have to worry about?. If it has no solution... For what reason do we have to worry about? Help me to understand what I'm saying, and I'll explain it better to you Rating helpful answers is nice, but saying thanks can be even nicer.

          M J 2 Replies Last reply
          0
          • R RickZeeland

            Quote:

            There are many sights

            That must be spelled like this: There are many sighs :-\

            Sander RosselS Offline
            Sander RosselS Offline
            Sander Rossel
            wrote on last edited by
            #10

            People Who Constantly Point Out Grammar Mistakes Are Pretty Much Jerks, Scientists Find[^] That makes you a scientifically proven jerk! :D

            Best, Sander sanderrossel.com Migrating Applications to the Cloud with Azure arrgh.js - Bringing LINQ to JavaScript Object-Oriented Programming in C# Succinctly

            R 1 Reply Last reply
            0
            • N Nelek

              Mark_Wallace wrote:

              People can be very critical cynical

              FTFY :rolleyes: :rolleyes:

              M.D.V. ;) If something has a solution... Why do we have to worry about?. If it has no solution... For what reason do we have to worry about? Help me to understand what I'm saying, and I'll explain it better to you Rating helpful answers is nice, but saying thanks can be even nicer.

              M Offline
              M Offline
              Mark_Wallace
              wrote on last edited by
              #11

              Nelek wrote:

              Mark_Wallace wrote:

              People can be very critical cynical

              FTFY :rolleyes: :rolleyes:

              I'm sure I have no idea what you mean :cool:

              I wanna be a eunuchs developer! Pass me a bread knife!

              1 Reply Last reply
              0
              • J John R Shaw

                I have a service provider whose site for paying my bill is ridiculous. I sign in an then watch a doughnut spin forever. Basically, I put it on a separate screen or sit down and watch a movie or two. Occasionally it will pop up a dialog asking if I am still there. My first thought is that it is some sort of VM, and my second thought is that this is BS. There are many sights that have multiple ways to ensure you are you (location, email, text, etc.). None of them require you to sit back an wait for them to eventually let you in to pay your bill. I propose a two level login. A login to pay the bill and a login to access account information. Most of the time you just want to pay your bill, so if someone compromised that password - who cares. If they want to pay the bill for you - let them.

                INTP "Program testing can be used to show the presence of bugs, but never to show their absence." - Edsger Dijkstra "I have never been lost, but I will admit to being confused for several weeks. " - Daniel Boone

                W Offline
                W Offline
                W Balboos GHB
                wrote on last edited by
                #12

                Something I always try to get through to telephone bill paying 'personnel'. If someone wants to pay my bill, don't worry about their ID - just take their money. I mean really!

                Ravings en masse^

                "The difference between genius and stupidity is that genius has its limits." - Albert Einstein

                "If you are searching for perfection in others, then you seek disappointment. If you seek perfection in yourself, then you will find failure." - Balboos HaGadol Mar 2010

                J 1 Reply Last reply
                0
                • J John R Shaw

                  Really, one word. I spelled sites wrong, so what?

                  INTP "Program testing can be used to show the presence of bugs, but never to show their absence." - Edsger Dijkstra "I have never been lost, but I will admit to being confused for several weeks. " - Daniel Boone

                  R Offline
                  R Offline
                  RickZeeland
                  wrote on last edited by
                  #13

                  Ok, I forgive you and must admit that even I sometimes make spelling mistakes, but hey I'm Dutch :-\ btw. bonus points for quoting Edsger Dijkstra.

                  1 Reply Last reply
                  0
                  • Sander RosselS Sander Rossel

                    People Who Constantly Point Out Grammar Mistakes Are Pretty Much Jerks, Scientists Find[^] That makes you a scientifically proven jerk! :D

                    Best, Sander sanderrossel.com Migrating Applications to the Cloud with Azure arrgh.js - Bringing LINQ to JavaScript Object-Oriented Programming in C# Succinctly

                    R Offline
                    R Offline
                    RickZeeland
                    wrote on last edited by
                    #14

                    What would this world do without jerks :-\

                    1 Reply Last reply
                    0
                    • J John R Shaw

                      I have a service provider whose site for paying my bill is ridiculous. I sign in an then watch a doughnut spin forever. Basically, I put it on a separate screen or sit down and watch a movie or two. Occasionally it will pop up a dialog asking if I am still there. My first thought is that it is some sort of VM, and my second thought is that this is BS. There are many sights that have multiple ways to ensure you are you (location, email, text, etc.). None of them require you to sit back an wait for them to eventually let you in to pay your bill. I propose a two level login. A login to pay the bill and a login to access account information. Most of the time you just want to pay your bill, so if someone compromised that password - who cares. If they want to pay the bill for you - let them.

                      INTP "Program testing can be used to show the presence of bugs, but never to show their absence." - Edsger Dijkstra "I have never been lost, but I will admit to being confused for several weeks. " - Daniel Boone

                      H Offline
                      H Offline
                      H Brydon
                      wrote on last edited by
                      #15

                      John R. Shaw wrote:

                      I propose a two level login. A login to pay the bill and a login to access account information. Most of the time you just want to pay your bill, so if someone compromised that password - who cares. If they want to pay the bill for you - let them.

                      My car and home insurance bill works like that. You only need to know the account number to pay it. Partial or full payment. Hmmmm I suppose there is a problem there. Okay, nothing to see here. Move along.

                      I'm retired. There's a nap for that... - Harvey

                      1 Reply Last reply
                      0
                      • N Nelek

                        Mark_Wallace wrote:

                        People can be very critical cynical

                        FTFY :rolleyes: :rolleyes:

                        M.D.V. ;) If something has a solution... Why do we have to worry about?. If it has no solution... For what reason do we have to worry about? Help me to understand what I'm saying, and I'll explain it better to you Rating helpful answers is nice, but saying thanks can be even nicer.

                        J Offline
                        J Offline
                        John R Shaw
                        wrote on last edited by
                        #16

                        How did they miss "they're".

                        INTP "Program testing can be used to show the presence of bugs, but never to show their absence." - Edsger Dijkstra "I have never been lost, but I will admit to being confused for several weeks. " - Daniel Boone

                        N 1 Reply Last reply
                        0
                        • W W Balboos GHB

                          Something I always try to get through to telephone bill paying 'personnel'. If someone wants to pay my bill, don't worry about their ID - just take their money. I mean really!

                          Ravings en masse^

                          "The difference between genius and stupidity is that genius has its limits." - Albert Einstein

                          "If you are searching for perfection in others, then you seek disappointment. If you seek perfection in yourself, then you will find failure." - Balboos HaGadol Mar 2010

                          J Offline
                          J Offline
                          John R Shaw
                          wrote on last edited by
                          #17

                          Exactly! Who cares who is paying the bill, as long as if gets payed.

                          INTP "Program testing can be used to show the presence of bugs, but never to show their absence." - Edsger Dijkstra "I have never been lost, but I will admit to being confused for several weeks. " - Daniel Boone

                          1 Reply Last reply
                          0
                          • J John R Shaw

                            How did they miss "they're".

                            INTP "Program testing can be used to show the presence of bugs, but never to show their absence." - Edsger Dijkstra "I have never been lost, but I will admit to being confused for several weeks. " - Daniel Boone

                            N Offline
                            N Offline
                            Nelek
                            wrote on last edited by
                            #18

                            Thread got in the 3rd page and they are also lazy? ;P

                            M.D.V. ;) If something has a solution... Why do we have to worry about?. If it has no solution... For what reason do we have to worry about? Help me to understand what I'm saying, and I'll explain it better to you Rating helpful answers is nice, but saying thanks can be even nicer.

                            1 Reply Last reply
                            0
                            Reply
                            • Reply as topic
                            Log in to reply
                            • Oldest to Newest
                            • Newest to Oldest
                            • Most Votes


                            • Login

                            • Don't have an account? Register

                            • Login or register to search.
                            • First post
                              Last post
                            0
                            • Categories
                            • Recent
                            • Tags
                            • Popular
                            • World
                            • Users
                            • Groups