|
meep-online
|
 |
« Reply #140 on: March 30, 2008, 12:25:42 PM » |
|
This kinda would be great if this became like the new email 
|
|
|
|
|
Logged
|
|
|
|
|
meep-online
|
 |
« Reply #141 on: March 30, 2008, 12:34:20 PM » |
|
Btw, I lost my password. Maybe a password reset feature would be good 
|
|
|
|
|
Logged
|
|
|
|
inp o҉rtb
The Gangsta
Global Moderator
Official 110mb Guru
   
Offline
Posts: 15645
experimental theologian
|
 |
« Reply #142 on: March 30, 2008, 05:17:13 PM » |
|
dude. that is a must-have feature. and one should be able to change the password. i'll work on it in the morning. thanks for the tip 
|
|
|
|
|
Logged
|
|
|
|
|
meep-online
|
 |
« Reply #143 on: April 01, 2008, 05:00:42 AM » |
|
Its ok 
|
|
|
|
|
Logged
|
|
|
|
inp o҉rtb
The Gangsta
Global Moderator
Official 110mb Guru
   
Offline
Posts: 15645
experimental theologian
|
 |
« Reply #144 on: April 01, 2008, 07:58:31 AM » |
|
It requires a bit more thought than I expected. We'll need some way of authenticating the user before letting the user change the password ;]
|
|
|
|
|
Logged
|
|
|
|
|
iKsbjA
|
 |
« Reply #145 on: April 01, 2008, 05:30:44 PM » |
|
An email should do it.
|
|
|
|
|
Logged
|
  I am a completely fair, non-biased, prejudice free and neurotic Apple fan. 110MB user FAQ
Paranoia means having all the facts. ~ William S. Burroughs, US author (1914 - 1997)
Dilber MC forever!
|
|
|
inp o҉rtb
The Gangsta
Global Moderator
Official 110mb Guru
   
Offline
Posts: 15645
experimental theologian
|
 |
« Reply #146 on: April 01, 2008, 05:46:23 PM » |
|
though that would require an email address. i'm thinking something along the lines of birth date and security question. or maybe also include random things like favorite color  what do you think? and meep-online, i'll dig up your credentials.
|
|
|
|
|
Logged
|
|
|
|
|
iKsbjA
|
 |
« Reply #147 on: April 01, 2008, 07:26:30 PM » |
|
though that would require an email address. i'm thinking something along the lines of birth date and security question. or maybe also include random things like favorite color  what do you think? and meep-online, i'll dig up your credentials. I understand. Well, Gmail and Hotmail allow you to have an additional email address. In your case, it might be better to ask a security question, or show a 'password reminder' entered at registration or in account settings like "Mom's maiden name with 2nd 'D' capitalized and your phone number's first three numbers", "My first cat's name", "5318008" (enter on a calculator and turn it upside down). This is the most simple to make, can be unsafe though. It could be also a self-made question that must be answered correctly (I don't like given security questions).
|
|
|
|
|
Logged
|
  I am a completely fair, non-biased, prejudice free and neurotic Apple fan. 110MB user FAQ
Paranoia means having all the facts. ~ William S. Burroughs, US author (1914 - 1997)
Dilber MC forever!
|
|
|
inp o҉rtb
The Gangsta
Global Moderator
Official 110mb Guru
   
Offline
Posts: 15645
experimental theologian
|
 |
« Reply #148 on: April 01, 2008, 07:36:50 PM » |
|
Great ideas. I'm thinking that the user should be challenged to enter: correct birth date answer to security question After passing this checkpoint, the user would be allowed to either reset the password or guess the password using a reminder, but not see the password itself. I'm not sure if this would be insecure or too much hassle. Ideally, one would not have to reset the password 
|
|
|
|
|
Logged
|
|
|
|
|
iKsbjA
|
 |
« Reply #149 on: April 01, 2008, 08:32:06 PM » |
|
I think this is good. I use one password for 99% of my web needs, I know this isn't very safe, but it's much easier to remember. I believe most people are like me, so practically they won't need that option very often. You made it very secure, and without the involving of e-mail confirmations (which are damn annoying!). So IMHO it's not too insecure or too much of a hassle.
|
|
|
|
|
Logged
|
  I am a completely fair, non-biased, prejudice free and neurotic Apple fan. 110MB user FAQ
Paranoia means having all the facts. ~ William S. Burroughs, US author (1914 - 1997)
Dilber MC forever!
|
|
|
|
meep-online
|
 |
« Reply #150 on: April 02, 2008, 07:49:32 AM » |
|
You should take a look at how hotmail and stuff does it. With hotmail you can have a secondry email. How about having a feature where you can send the reset password link to another account, or you have to enter birthdate and security question  Or I think theres nothing wrong with having an option to send it to an email address. Because you are never going to completly replace email in the short term, so that could be ok?
|
|
|
|
|
Logged
|
|
|
|
|
iKsbjA
|
 |
« Reply #151 on: April 02, 2008, 10:45:30 PM » |
|
Nooo! Please no loads of mails! I mean, c'mon, just look: 1) Answer security question and/or birthdate (to prevent spamming the secondary account) 2) Check mail for confirmation 3) Visit link 4) Get random password 5) Log in 6) Change password Now that's what I call too much hassle! Why not do like this (should be more simple to code, too): 1) Answer security question and birthdate; 2) Choose a reminder or a 'Change password' dialog (automatically logs you in). The only point of the upper one is the safety of involving a second mailbox, but 99% of all users will have same password for both sites anyways.
|
|
|
|
|
Logged
|
  I am a completely fair, non-biased, prejudice free and neurotic Apple fan. 110MB user FAQ
Paranoia means having all the facts. ~ William S. Burroughs, US author (1914 - 1997)
Dilber MC forever!
|
|
|
|
meep-online
|
 |
« Reply #152 on: April 03, 2008, 05:32:12 AM » |
|
No I don't mean have those 2 idea combined. I meant having 2 options:
1.) Send email with pword 2.) Answer security question
|
|
|
|
|
Logged
|
|
|
|
|
iKsbjA
|
 |
« Reply #153 on: April 03, 2008, 05:47:04 AM » |
|
If I would hate you (what I don't do) I could spam your secondary email with new password requests (as there wouldn't be any confirmation to see if it's sent by you). But that's not the biggest problem, but checking mail twice drives me crazy. 1) Check mail for confirmation 2) Visit link 3) Get random password 4) Log in 5) Change password is still worse than 1) Answer security question and birthdate 2) Choose a reminder or a 'Change password' dialog (automatically logs you in)
|
|
|
|
|
Logged
|
  I am a completely fair, non-biased, prejudice free and neurotic Apple fan. 110MB user FAQ
Paranoia means having all the facts. ~ William S. Burroughs, US author (1914 - 1997)
Dilber MC forever!
|
|
|
|
antimatter15
|
 |
« Reply #154 on: April 03, 2008, 11:38:39 AM » |
|
i had an idea.
What if you find a better way to replace the standard *email for finishing registration* thing?
|
|
|
|
|
Logged
|
Ajax Animator, a web-based, collaborative animation authoring environment with Flash, Silverlight, and GIF export.
|
|
|
inp o҉rtb
The Gangsta
Global Moderator
Official 110mb Guru
   
Offline
Posts: 15645
experimental theologian
|
 |
« Reply #155 on: April 03, 2008, 12:06:06 PM » |
|
Yeah, that's the tough part... thanks for the suggestions! I'll start implementing this stuff after my exams.
Meanwhile, if meep-online would please PM me his username (I think I know what it is; I just need to confirm)...
|
|
|
|
|
Logged
|
|
|
|
|
iKsbjA
|
 |
« Reply #156 on: April 03, 2008, 11:18:51 PM » |
|
i had an idea.
What if you find a better way to replace the standard *email for finishing registration* thing?
Yes, I hate it!!!
|
|
|
|
|
Logged
|
  I am a completely fair, non-biased, prejudice free and neurotic Apple fan. 110MB user FAQ
Paranoia means having all the facts. ~ William S. Burroughs, US author (1914 - 1997)
Dilber MC forever!
|
|
|
inp o҉rtb
The Gangsta
Global Moderator
Official 110mb Guru
   
Offline
Posts: 15645
experimental theologian
|
 |
« Reply #157 on: April 04, 2008, 08:13:21 AM » |
|
Yep, it's annoying, alright. The alternative would have to be something relatively constant for the person, and easy to handle. Hmm...
|
|
|
|
|
Logged
|
|
|
|
|
iKsbjA
|
 |
« Reply #158 on: April 05, 2008, 12:31:09 AM » |
|
If no email for your service (site) is required, no confirmation mail needed (it's for checking if the user really owns that address).
|
|
|
|
|
Logged
|
  I am a completely fair, non-biased, prejudice free and neurotic Apple fan. 110MB user FAQ
Paranoia means having all the facts. ~ William S. Burroughs, US author (1914 - 1997)
Dilber MC forever!
|
|
|
inp o҉rtb
The Gangsta
Global Moderator
Official 110mb Guru
   
Offline
Posts: 15645
experimental theologian
|
 |
« Reply #159 on: April 05, 2008, 06:18:44 AM » |
|
right. we need to authenticate the person, not the person's email account. so... what's needed is information that's specific to each individual, but not so private that anyone would have doubts about sending it online. birth date is one example. question/answer is another. SSN is a bad example.
|
|
|
|
|
Logged
|
|
|
|
|