View Single Post
Old 06-22-2004, 11:30 AM  
svenski
Confirmed User
 
Join Date: Mar 2004
Location: Behind you
Posts: 227
Ok,

as the thread got serious.

A large part of the problem is the fact that there are lists with literally tens of thousands (if not more) of user/pwd combinations that will be hurled at your site.

Some of the hurlers learn as they go along.

The average surfer uses a username and password that is easy to remember and perhaps personal to them . They also tend to use the same login for site after site.

All it needs is for that user id/pwd to be compromised and it will get added to the numerous lists/hurler proggies.

If you use CCBill's random usernames and passwords that will prevent the above and the customer support impact is minimal.

If you use the random passes AND use the additional characters these will conflict with Password Sentry when it tries to update the records for each login.

Use the random passes without the additional characters and you'll be fine for use with Password Sentry.
svenski is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote