On Wednesday, October 22, 2003 2:31 PM [EDT], Kai Schaetzl <[EMAIL PROTECTED]> wrote: >> Tucows is pleased to announce that we have streamlined access to >> the Reseller Resource Center (RRC). Effective immediately, >> Resellers can sign-in using their user name only. The password >> is no longer required. [snip] > > What the heck is this supposed to be good for? It took me TWO > guesses to guess the username of a member of this list and get > in. Username verified, now up for brute-forcing the password ...
And what purpose does this serve anyway? If the password is not required, why not just track the user with a cookie? Why is the username needed?
