Welcome Guest, Not a member yet? Register   Sign In
Picking an Auth Library
#36

[eluser]theshiftexchange[/eluser]
[quote author="phpserver" date="1242511537"][quote author="Dam1an" date="1242510357"]WHat do you mean checking the passwords each and every day?
I'm assuming you don't intend on having a remember me option, so not sure what else it could mean :-S[/quote]

The it department wants to see the passwords of active accounts for the web based application daily.I dont have a remember me button on the app.The thing is already good with ssl i deem but they still insist.From what i know passwords dont change.[/quote]

huh??? let me see if I understand this:

The bank wants you to send a plain text file (email/printout/whatever) which will show the entire list of usernames and passwords each day, so some random guy in accounting can check to see if a password has changed?

I can think of about 200 reasons why that is unbelievable bad - but I'll list the top 3:

1. It will force you to make your passwords backword-compatiable - i..e you cant hash them, since hash is a one way process. Anything you can reverse, so can a hacker
2. Having passwords in any plain text format (printout/email/file) is just silly
3. Giving a list of passwords to any person, even the CEO of a company, is also silly - it just opens up all sorts of social-engineering issues.


I'd like to add a general comment here: there is a reason why security on 'basic' sites is such a security risk, is not for the site itself, but for other sites. It is well known that people use the same username/password combination on multiple sites. A well documented hacker's technique to steal online game passwords for World of Warcraft, EveOnline etc - is to hack a 3rd party forum site, and use those username/passwords of the forum and try them on the game. More often than not, the username/password combination of the forum is the same as the online game - giving the hacker access.

This same principle applies to the bank scenario. Giving someone a list of username/passwords is inappriopriate and wrong.


Messages In This Thread
Picking an Auth Library - by El Forum - 05-15-2009, 12:54 AM
Picking an Auth Library - by El Forum - 05-15-2009, 01:56 AM
Picking an Auth Library - by El Forum - 05-15-2009, 03:59 AM
Picking an Auth Library - by El Forum - 05-15-2009, 04:04 AM
Picking an Auth Library - by El Forum - 05-15-2009, 06:48 AM
Picking an Auth Library - by El Forum - 05-15-2009, 06:55 AM
Picking an Auth Library - by El Forum - 05-15-2009, 07:13 AM
Picking an Auth Library - by El Forum - 05-15-2009, 07:35 AM
Picking an Auth Library - by El Forum - 05-15-2009, 07:45 AM
Picking an Auth Library - by El Forum - 05-15-2009, 11:00 PM
Picking an Auth Library - by El Forum - 05-16-2009, 01:54 AM
Picking an Auth Library - by El Forum - 05-16-2009, 05:49 AM
Picking an Auth Library - by El Forum - 05-16-2009, 05:53 AM
Picking an Auth Library - by El Forum - 05-16-2009, 06:00 AM
Picking an Auth Library - by El Forum - 05-16-2009, 06:05 AM
Picking an Auth Library - by El Forum - 05-16-2009, 06:19 AM
Picking an Auth Library - by El Forum - 05-16-2009, 06:28 AM
Picking an Auth Library - by El Forum - 05-16-2009, 06:33 AM
Picking an Auth Library - by El Forum - 05-16-2009, 06:40 AM
Picking an Auth Library - by El Forum - 05-16-2009, 06:48 AM
Picking an Auth Library - by El Forum - 05-16-2009, 07:06 AM
Picking an Auth Library - by El Forum - 05-16-2009, 07:12 AM
Picking an Auth Library - by El Forum - 05-16-2009, 07:19 AM
Picking an Auth Library - by El Forum - 05-16-2009, 07:22 AM
Picking an Auth Library - by El Forum - 05-16-2009, 07:26 AM
Picking an Auth Library - by El Forum - 05-16-2009, 07:31 AM
Picking an Auth Library - by El Forum - 05-16-2009, 07:46 AM
Picking an Auth Library - by El Forum - 05-16-2009, 07:55 AM
Picking an Auth Library - by El Forum - 05-16-2009, 09:24 AM
Picking an Auth Library - by El Forum - 05-16-2009, 09:48 AM
Picking an Auth Library - by El Forum - 05-16-2009, 10:10 AM
Picking an Auth Library - by El Forum - 05-16-2009, 10:38 AM
Picking an Auth Library - by El Forum - 05-16-2009, 10:45 AM
Picking an Auth Library - by El Forum - 05-16-2009, 10:58 AM
Picking an Auth Library - by El Forum - 05-16-2009, 11:05 AM
Picking an Auth Library - by El Forum - 05-16-2009, 05:47 PM
Picking an Auth Library - by El Forum - 05-16-2009, 09:24 PM
Picking an Auth Library - by El Forum - 05-17-2009, 01:13 AM
Picking an Auth Library - by El Forum - 05-17-2009, 01:26 AM
Picking an Auth Library - by El Forum - 05-17-2009, 01:30 AM
Picking an Auth Library - by El Forum - 05-17-2009, 01:39 AM
Picking an Auth Library - by El Forum - 05-17-2009, 01:52 AM
Picking an Auth Library - by El Forum - 05-17-2009, 01:58 AM



Theme © iAndrew 2016 - Forum software by © MyBB