Showing posts with label Bugzilla. Show all posts
Showing posts with label Bugzilla. Show all posts

Friday, July 3, 2009

Password masking considered harmful?

Private Folder password promptImage via Wikipedia

We've all seen it, it's ubiquitious... the little box to type your password into. The line of asterisks grows as you type the secret characters in.

We've had it drilled into us, make your password safe, use lots of different kinds of characters (some sites even require that you use 3 of the 4 types, lowercase uppercase, numeric, special characters), don't use a common dictionary word, make it long, and so on.

So there I am on some site or another that shall remain nameless, trying to enter in "RodgerD0dgerC0dger!" and all I see is a line of *********

The phone rings mid stride. What character am I on anyway? hmm.. let me count backwards... I think I got it... OK.

"wrong password". Let's try that again ... A bird chirps outside the window Hey, did I remember to make that third 0 a zero but not the first one? Ah, must be right... OK.

"wrong password". Drat... Give it another try. Almost done.... Did my hand slip when I was holding down the 1 to make the ! ? No way... OK...

"wrong password" followed by "You have entered an incorrect password three times in a row and are now locked out of the system, please call our help desk between the hours of 8 AM and 6 PM Mumbai time to get it reset"

Argh! It's happened to all of us. And it's so needless. What do those asterisks do for us anyway? Unless we are being shoulder surfed, nothing.

As reported on Out-law.com there may finally be a realisation dawning that this is needless, and mindless, security. Well known usability expert Jakob Nielsen recently wrote about this in his AlertBox of 23 June 2009, opining that it's not needful, cleartext is better, and it may actually make things less secure. For those that actually have to deal with shoulder surfing, a checkbox to make the system use asterisks in that one case (or default to that for high security sites) is the easy way to handle that.

High time this was done. Start suggesting it to the sites you frequent. I think I'll go open a Bugzilla bug for MediaWiki if there isn't one already.


Oh, and RodgerDodgerCodger isn't actually my password.


Enhanced by Zemanta

Wednesday, April 30, 2008

Stemming the rise of the machines?

Wikipedia Checkuser Icon Use Wikipedia Logo and :Image:Gnome-searchtool.svg(upload by User:Seahen)The machines are reading
(c) Wikimedia Foundation
Sometimes events move faster than we plan.

Another tidbit of my visit to the Wikimedia Foundation office Monday was that I got a preview of this post by Cary Bass, which addresses robots.txt, the bit of magic that controls what is searched and what is not. (more specifically, well behaved robots/spiders honor what it says and do not scan pages it names off... Less well behaved robots/spiders eventually get blocked completely once their bad behaviour is discovered.) Specifically, it makes the case that non articlespace pages ought not to be quite as visible in searches as articles, because unlike articlespace pages, which were designed to be read by the intended audience of the encyclopedia itself, they often contain bickering, name calling, or even worse, "userified" pages that contain clear BLP violations, fringe theories given undue weight or all sorts of other problematic content.

Unbeknownst to Cary, after Cary had written that blog post but before it published (the wonders of delayed publishing) Newyorkbrad posted this to the english wikipedia and foundation mailing lists. In it, he advances a remarkably similar thesis, that we should act to avoid giving undue weight to material that really isn't intended for the readership.

BugzillaBugzilla mascot, Image
via Wikimedia Commons

Partially in support of this, I entered an enhancement request in Bugzilla for code changes to make it easier to control what is and isn't in robots.txt... your thoughts or comments on that bug would be appreciated.

See also this mailing list post by Jimmy Wales in which he expresses agreement with the general idea that we should use this as a way to avoid doing unnecessary harm. Bravo!

As it turns out, this topic (among others) has been getting considerable discussion at the dreaded Wikipedia Review, but I believe Brad advanced the idea because it's a good idea, not because of the pressure that some were trying to exert. More on that topic later, but for a taste of it you can review this thread.