On storing passwords securely

Fascinating stuff to read if you're in the business of handling login credentials on a server:

Quick thoughts:

  • Don't use the same password everywhere, at the very minimum use a unique one for your online bank account!
  • The exploding trend in social software of asking people for their credentials to check if they've got "friends" around is not just leading to social spam, it's helping phishing as well. Plus having credentials floating in the clear on the cloud from servers to servers doesn't inspire security, does it? Well, when you know it takes only a chocolate bar, what can you do anyway?
  • If a web service you're using is capable of emailing your forgotten password back in the clear (in the clear!), you can only assume that its security is plain crap. The right way should be to reset your password (and only after you've clicked on a link sent to your legitimate email address, or at least some challenge question, so that no one can lock you out by just knowing your login name.)

Leave a comment

Recent Entries

  • Moving on

    If everything goes well, next week I shall be the happy founder and owner of a shiny brand new company, under which I'll incorporate my...

  • Movable Type 4.2 is out

    Movable Type 4.2 is here with a lot of good news and new features. The new set of licences, if I get things correctly, is...

  • Using Movable Type as a CMS and NewsML feeds generator

    I'm putting the last touches on a CMS to generate custom NewsML feeds for internet portals. It's based on Movable Type 4.2 and allows for...

  • Google lets GMail certificate expire

    This expired certificate alert just showed up for my GMail account. Apparently Google let the SSL certificate expire for the smtp.gmail.com domain. In the...

  • Bon appétit

    We wanted to strip away all the nonsense. Do we really need a sommelier? Do we really need all the other accoutrements that you see...

Close