Menu

Main Menu
Talk Get Daily Search

Member's Online

    User Name
    Password

    The new talk.maemo.org theme

    Reply
    Page 24 of 24 | Prev | 14   22     23   24 |
    sjgadsby | # 231 | 2009-05-22, 22:00 | Report

    Originally Posted by sirfelix View Post
    There is a security issue:
    The old site masked your password while typing. This new site exposes it to all.
    With which browser & theme? MicroB & the default theme do not reveal my password.

    Edit | Forward | Quote | Quick Reply | Thanks
    The Following 4 Users Say Thank You to sjgadsby For This Useful Post:
    GeneralAntilles, Jaffa, qole, timsamoff

     
    ARJWright | # 232 | 2009-05-25, 17:15 | Report

    Originally Posted by sirfelix View Post
    There is a security issue:
    The old site masked your password while typing. This new site exposes it to all.
    This is a pet peeve of mine...

    You are using a handheld device; where is the security risk when you are the only one looking at it?

    If anything; you should see what you are typing. Its not like you password is any more encrypted than your user name (its only validated with javascript). Or maybe I'm missing that the appearance of security is better than the reality.

    Edit | Forward | Quote | Quick Reply | Thanks
    The Following 3 Users Say Thank You to ARJWright For This Useful Post:
    BrentDC, qole, timsamoff

     
    fragos | # 233 | 2009-05-25, 17:31 | Report

    Originally Posted by sirfelix View Post
    I don't like the new site. Do you think you can require us to scroll any more? I'll be in China before I get to the bottom of the page.
    Have you tried the other themes available at the end of each page. "--Classic Dark" is very similar to the old site.

    Edit | Forward | Quote | Quick Reply | Thanks

     
    Bundyo | # 234 | 2009-05-25, 18:29 | Report

    Originally Posted by ARJWright View Post
    If anything; you should see what you are typing. Its not like you password is any more encrypted than your user name (its only validated with javascript). Or maybe I'm missing that the appearance of security is better than the reality.
    Um, what? The passwords are usually held on the server encrypted and checked directly in that form (and not with javascript at all, unless you are talking about AJAX means of transport). Of course there are tools that someone can use to intercept your http stream with, but if the Talk merges with the maemo.org authentication, it will use SSL for communication and the above scenario becomes even more unlikely to happen.

    Edit | Forward | Quote | Quick Reply | Thanks

     
    ARJWright | # 235 | 2009-05-28, 14:04 | Report

    Originally Posted by Bundyo View Post
    Um, what? The passwords are usually held on the server encrypted and checked directly in that form (and not with javascript at all, unless you are talking about AJAX means of transport). Of course there are tools that someone can use to intercept your http stream with, but if the Talk merges with the maemo.org authentication, it will use SSL for communication and the above scenario becomes even more unlikely to happen.
    Got ya. But speaking from the other side of things...

    ...user types in a password box and *thinks* its secure because they cannot see the letters they are typing. On a public terminal, sure. On a personal mobile device, why?

    Edit | Forward | Quote | Quick Reply | Thanks

     
    Jaffa | # 236 | 2009-05-28, 15:15 | Report

    Originally Posted by ARJWright View Post
    ...user types in a password box and *thinks* its secure because they cannot see the letters they are typing. On a public terminal, sure. On a personal mobile device, why?
    Of course, this isn't something that the website can adequately determine - but it does sound like an enhancement request for the browser.

    Edit | Forward | Quote | Quick Reply | Thanks

     
    Baloo | # 237 | 2009-05-28, 16:40 | Report

    Originally Posted by Jaffa View Post
    Of course, this isn't something that the website can adequately determine - but it does sound like an enhancement request for the browser.
    What about looking at the browsers user agent?

    Edit | Forward | Quote | Quick Reply | Thanks

     
    Jaffa | # 238 | 2009-05-28, 17:03 | Report

    Originally Posted by Baloo View Post
    What about looking at the browsers user agent?
    Which browser? What about people who change their UA string?

    If there's a case for not hiding them on the device because of the use case, I'd say that's the right place to do it.

    Having said that, the browser should be consistent with WEP/WPA key entry etc. And I can see this being one of the low-level things in the hallowed "UI Spec".

    Perhaps Greasemonkey would be a better approach?

    Edit | Forward | Quote | Quick Reply | Thanks

     
    GeraldKo | # 239 | 2009-05-28, 17:44 | Report

    The new forum still needs site-specific Google search like in my sig (first Newbie link). I've posted this request as a bug.

    Edit | Forward | Quote | Quick Reply | Thanks

     
    Page 24 of 24 | Prev | 14   22     23   24 |
vBulletin® Version 3.8.8
Normal Logout