Quote:
Originally Posted by raymor
|
They could start by making the username/password for the surfer. CCBILL has an admin function for this. Removes the ability to supply one by the surfer.
Why is this important?
Because if I hacked a web site... and I do mean hacked. Not cracked. And I got its password file and decrypted it. And this web site was for a solo model similar to Lil Candy... Then I might as well have Lil Candy's password file too. Because out of the 800 members in the other site, about 25 of them are currently active on Lil Candy.
Then add in form protection on the members login. That way at least it slows things down to people really desperate. Instead of being an always easily crackable site you go into the "a lot harder and therefor less of a target" group.