[jira] Commented: (OFBIZ-1151) Passwords are not seeded

2007-11-15 Thread Michael Jensen (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-1151?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel#action_12542952 ] Michael Jensen commented on OFBIZ-1151: --- One option is to use the same field for the hash, but adding a colon

Re: release4.0: OFBIZ-1106 (in or out?)

2007-11-15 Thread Michael Jensen
on of how decisions are made w/ofbiz. Mike Jacopo Cappellato wrote: > Michael Jensen wrote: >> ... >> I'm curious to see how things pan out on this. It will tell me how >> seriously security is taken by the people driving ofbiz. >> > > Wow... this is a

[jira] Commented: (OFBIZ-1151) Passwords are not seeded

2007-11-15 Thread Michael Jensen (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-1151?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel#action_12542844 ] Michael Jensen commented on OFBIZ-1151: --- Is anyone working on this already? I'd like to help out wi

Re: release4.0: OFBIZ-1106 (in or out?)

2007-11-15 Thread Michael Jensen
Using that logic, you could say that almost any previous bugs were really "as-implemented" features and no changes should ever be made to the current release branch. If it was found somewhere in ofbiz that sensitive information was submitted over http instead of https, would that be considered a bu

Re: release4.0: OFBIZ-1106 (in or out?)

2007-11-14 Thread Michael Jensen
I agree with Tim. It's a security related bug fix. Displaying passwords in plaintext on a screen is a bug. It is industry standard practice to not show passwords on the screen (either by replacing w/asterisks or not displaying characters at all.) Mike Adrian Crum wrote: > Tim, > > From my

Amazon Flexible Payments Service (Amazon FPS)

2007-08-08 Thread Michael Jensen
Sorry for the cross post, but I thought this would be relevant to both lists... Amazon now has a payment system in limited beta. It looks like it's similar to PayPal, but geared more to developers (yay!) Their pricing seems to be competitive with Paypal's, but their "in network" transfer fees blo

Re: Apache OFBiz Time Zone Support Strategy

2007-07-11 Thread Michael Jensen
Out of curiosity, would this new strategy also take into account Daylight Savings time? Being an inexperienced java programmer, I'm not sure if this is built into java.util.TimeZone already or if it would have to be built into ofbiz. Mike Adrian Crum wrote: > I'm starting a new thread for us to

Re: release?

2007-04-17 Thread Michael Jensen
I like the information that the struts project has on their release plan page. Maybe something similar? http://struts.apache.org/2.x/docs/release-plan-201.html Mike BJ Freeman wrote: > David, > what needs to be said on the release Plan, for it to be implemented? > > BJ Freeman sent the followin