Skip to navigation

Skip to additional stuff


Tuesday, May 17, 2005

Make accounts more secure

I’ve been recently working on this user authentication-login-thing which everyone of you should be familiar with. You sign up with username and password, wait for an e-mail and click on a link. Then you go to login and enter your username and password to be finally logged in. So what?

The system is actually not very secure. Besides using an unencrypted connection in many cases and insecure passwords, usernames are often visible on the whole website, while your e-mail address is kept safe. If anyone spiders through all sites he can get a whole bunch of usernames. Then he can run a list of typical passwords through each username. And if there are enough usernames, the chance to actually get into an account is 100%.

If you provide your e-mail address, why not use it for login? No one knows which e-mail addresses are associated with which account, so you cannot try typical passwords on them. The login gets more secure, your accounts are safer.

11:12 am | Filed under: 5 Comments | the j-blog

5 Comments on “Make accounts more secure”

  • 1.
    Posted by
    Steven A Bristol
    2005-7-5
    8:13 pm

    I would not want my email address visible on the whole website. Even if it more secure, it is not worth the spam price that will eventually follow.

  • 2.
    Posted by
    Julian
    2005-7-5
    8:25 pm

    Huh?
    Who said that the e-mail address has to be displayed? Am I crazy or what?
    It’s just more secure, because no one knows your address.

Leave a comment

Your e-mail address will never be displayed.

(required)

(required)



Navigation



© Copyright Julian Bez 2010. All rights reserved, unless otherwise mentioned.
For your convenience: All times are GMT.
Built with valid things such as XHTML and CSS.

PLEASE NOTE: This site will look much better in a browser that supports web standards, but it is accessible to any browser or Internet device. more info...