Generate username & password or let new signup create their own?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • McFly85
    Registered User
    • Jul 2007
    • 11

    #1

    Generate username & password or let new signup create their own?

    I wanted to get some different opinions on whether it's better to automatically generate a more secure username and password for a new signup or give them the option to create their own? I currently let them create their own but think I would have far fewer hacks and shared ids if I didn't. Not sure if it has any impact on a sale.
  • Chosen
    • Aug 2001
    • 63151

    #2
    Their own

    Comment

    • Barefootsies
      Choice is an Illusion
      • Feb 2005
      • 42635

      #3
      Should You Email Your Members?

      Link1 | Link2 | Link3

      Enough Said.

      "Would you rather live like a king for a year or like a prince forever?"

      Comment

      • CurrentlySober
        Too lazy to wipe my ass
        • Aug 2002
        • 38948

        #4
        Originally posted by Barefootsies
        is that the 'Spock' death grip from star trek?


        👁️ 👍️ 💩

        Comment

        • DWB
          Registered User
          • Jul 2003
          • 31779

          #5
          When you generate for them, prepare for an endless amount of support mails because most of them can't remember "76eYfsh25" and never seem to remember they have an email with that pass in it, or the fact that they can set their browser to remember the password.

          We cut our support mails down by around 99% when we let them choose their own user/pass. I trust Strongbox will take care of most the hackers and password traders.

          Comment

          • EDepth
            Confirmed User
            • Nov 2005
            • 510

            #6
            I say let the user create their own. They will remember it by heart, won't have to email you asking for it, etc... If they are going to share it with friends, they will whether it's randomly generated or not. Same goes with the hacked accounts, it will be stolen from an end user via some malware either way.
            ICQ: 275335837

            Comment

            • seeandsee
              Check SIG!
              • Mar 2006
              • 50945

              #7
              create by yourself, store somewhere and encrypt
              BUY MY SIG - 50$/Year

              Contact here

              Comment

              • PromoterX
                Confirmed User
                • Sep 2010
                • 949

                #8
                Originally posted by DWB
                When you generate for them, prepare for an endless amount of support mails because most of them can't remember "76eYfsh25" and never seem to remember they have an email with that pass in it, or the fact that they can set their browser to remember the password.

                We cut our support mails down by around 99% when we let them choose their own user/pass. I trust Strongbox will take care of most the hackers and password traders.
                ...and thread closed.... everyone can go home now.

                Comment

                • jimmycooper
                  Confirmed User
                  • May 2010
                  • 4016

                  #9
                  Let them create their own.

                  Comment

                  • Barry-xlovecam
                    It's 42
                    • Jun 2010
                    • 18083

                    #10
                    We let them use their own password and then use strong encryption to store it in the database ...

                    Comment

                    • CurrentlySober
                      Too lazy to wipe my ass
                      • Aug 2002
                      • 38948

                      #11
                      Dont even let the fuckers into your members area in the first place!

                      Just take their money, and tell em to go fuck themselves...

                      ZERO PIRACY that way...


                      👁️ 👍️ 💩

                      Comment

                      • Chosen
                        • Aug 2001
                        • 63151

                        #12
                        Originally posted by CurrentlySober
                        Dont even let the fuckers into your members area in the first place!

                        Just take their money, and tell em to go fuck themselves...

                        ZERO PIRACY that way...

                        Comment

                        • raymor
                          Confirmed User
                          • Oct 2002
                          • 3745

                          #13
                          We favor a kind of middle ground, and have built a free tool to make it easy for you to do.

                          When users choose their own, approximately 15% will choose password from the top
                          10 most popular. These are things like "password" and "123456". The bad guys know
                          what those top ten passwords are, and they will be guessed. So letting users choose
                          their own doesn't work too well. At least, not as most adult sites do it. The way
                          banks do it is a little better - you can choose your own, but subject to certain rules,
                          so you're not allowed to have "password" as your password. Of course, many sites
                          are TOO restrictive in their rules -- 8-10 characters, must start with a letter, must not ...
                          Longer passwords are always better, so 8-10 characters is a dumb rule.

                          Assigning random passwords also has problems. Paying customers are often people
                          who are not technically sophisticated enough to find what the want for free, so
                          they have trouble even TYPING "lI1Kg`O0^}+", much less REMEMBERING it.

                          The middle ground we use is to assign passwords that are easy for most people to
                          type and can even be remembered, but are not easy for the bad guys to guess.
                          The passwords created by our free tool look like words and can be pronounced
                          like words, so they can be typed. An example would be "betorling". That's easier to
                          type than "J(dD?/gW", and certainly easier to remember. "betorling" isn't really a
                          word, though, so it's not in the bad guy's dictionary.

                          The free password generator can be found at:
                          https://bettercgi.com/strongbox/passgen/
                          For historical display only. This information is not current:
                          support@bettercgi.com ICQ 7208627
                          Strongbox - The next generation in site security
                          Throttlebox - The next generation in bandwidth control
                          Clonebox - Backup and disaster recovery on steroids

                          Comment

                          • MaDalton
                            I am Amazing Content!
                            • Feb 2004
                            • 39861

                            #14
                            Originally posted by DWB
                            When you generate for them, prepare for an endless amount of support mails because most of them can't remember "76eYfsh25" and never seem to remember they have an email with that pass in it, or the fact that they can set their browser to remember the password.

                            We cut our support mails down by around 99% when we let them choose their own user/pass. I trust Strongbox will take care of most the hackers and password traders.
                            i surely dont have thousands of members, but i havent gotten one email yet from someone who forgot his username or password. and i use 16 digit random for both.
                            AmazingContent.com - providing only the best content and service since 2003
                            Monetize your content on Veegaz.com - one of Germanies largest VOD sites
                            Got German traffic? We convert it into money for you!
                            Email: oltecconsult [at] gmail [dot] com

                            Comment

                            • raymor
                              Confirmed User
                              • Oct 2002
                              • 3745

                              #15
                              Originally posted by Barry-xlovecam
                              We let them use their own password and then use strong encryption to store it in the database ...
                              The right encryption is important, especially if you use a lot of PHP to drive your
                              site, as many sites do these days. Especially on a PHP powered site, you have to
                              assume that the bad guys can see your database. That means that unless the passwords
                              are properly encrypted, they can see ALL of your passwords. Having thousands of
                              passwords posted everywhere is not a fun experience, so they need to be encrypted to
                              keep the bad guys from reading them and posting them. (Technically, they are hashed

                              So what's the proper encryption? By default, the processors use a type of encryption
                              called a DES hash. It's used because it's always available, having been a standard
                              since 1972. In 1972, it was pretty hard to crack. Of course, computers of the time
                              had 500 kHz processors and 8 KB of RAM. It would take a few years to crack a DES
                              password, since the 8 bit CPU ran at 0.0005 Ghz. In 2011, with quad core 64 bit
                              2 Ghz processors, they can be cracked over 80,000 times faster. Running a typical
                              DES password list on a modern machine gives up passwords in under one second.
                              So DES is useless, but it's still the default.

                              For modern attackers, rather than 1972 attackers, you want modern encryption.
                              Given the Blowfish bug, that means salted SHA if your server supports it or salted
                              MD5 if not. The geeks who make Linux made it very easy to upgrade your encryption.
                              All that needs to be done is to adjust your processor's script pass a different salt
                              value, and we can take care of that for you. Today's encryption is expected to be
                              solid for another 30 years or so, so in 2041 you can upgrade again.
                              Last edited by raymor; 07-18-2011, 05:05 AM.
                              For historical display only. This information is not current:
                              support@bettercgi.com ICQ 7208627
                              Strongbox - The next generation in site security
                              Throttlebox - The next generation in bandwidth control
                              Clonebox - Backup and disaster recovery on steroids

                              Comment

                              • raymor
                                Confirmed User
                                • Oct 2002
                                • 3745

                                #16
                                MacFly, Troy just posted a good analysis of what happens when users
                                choose passwords. The one sentence summary is that they choose easily guessed
                                passwords 70% of the time.

                                http://www.troyhunt.com/2011/07/scie...selection.html
                                For historical display only. This information is not current:
                                support@bettercgi.com ICQ 7208627
                                Strongbox - The next generation in site security
                                Throttlebox - The next generation in bandwidth control
                                Clonebox - Backup and disaster recovery on steroids

                                Comment

                                Working...