Tyromaniac : Truth will triumph in the end... after everybody has left
Updated: 10/20/05; 7:51:51 AM.

 

Click to see the XML version of this web page.

Subscribe to "Tyromaniac" in Radio UserLand.

Click here to send an email to the editor of this weblog.

 
 
Tuesday, July 20, 2004




9:07:51 PM  What do you think? ( Thoughts) Who linked? []   



Why registration-sites suck. Wired News has a good piece on the backlash against the growing trend of news-sites requiring logins to read their articles, covering automated tools like the Mozilla bugmenot plugin that automatically spoofs your logins to 14,000+ sites.

The point that everyone seems to miss is that no one can possibly keep track of a thousand passwords for a thousand websites, which means that these sites undoubtably contain recycled passwords (admonishments from security experts to never recycle a password are the infosec equivalent of telling people to "eat less and exercise more" -- simplistic doctrine that is vanishingly unlikely to be adhered to in the field).

The more you recycle a password, the higher the likelihood that you will use it in a sensitive context -- a bank site, a message board, an IM client, an auction site -- where someone might impersonate you or even commit identity theft crimes against you.

What's even worse is that while these news-sites are willing to spend the computational cycles necessary to receive your password, none that I've seen use SSL for their login, which means that the NYT and others demand that you send your password in the clear when you sit down at a WiFi cafe and want to read the password. This is a potential disaster if that NYT password is also a sensitive one somewhere else: it's a case of really callous disregard for user privacy and security.

Link [Boing Boing]

The solution is quite simple. Have a password common to all non-sensitive stuff. That includes all news sites provided you don't put real info in them. Don't use the same as the login name, 'cause there may be a site that won't accept that, you may have to do variations on a theme to satisfy the requirements of different sites. Please, don't do this with sensitive stuff sites. A bad apple at Amazon can hurt you a lot, but it will be harder to discover and can do a lot more damage if s/he can use your password on another site.
7:47:27 AM  What do you think? ( Thoughts) Who linked? []   

© Copyleft 2005 Alfredo Octavio.


July 2004
Sun Mon Tue Wed Thu Fri Sat
        1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31
Jun   Aug

Google


Search Web Search Tyromaniac

Dictionary

Enlace - HyperlinkDiccionario RAE (Click Here)
Webrolling:
Chase me ladies, I'm the Cavalry
Linux para Venezuela
ZonaGeek
Jerry Kindall
Recent Titled Posts
 10/16/05
 10/15/05
 10/14/05
 10/14/05
 10/14/05
 10/14/05
 10/14/05
 10/14/05
 10/14/05
 10/14/05
 10/13/05
 10/12/05
 7/28/05
 7/23/05
 7/23/05
 7/23/05
 7/21/05
 7/11/05
 7/8/05
 7/7/05
 7/6/05
 7/3/05
 7/1/05
 6/29/05
 6/27/05
 6/27/05