Re: [nyphp-talk] Relax your password rules

2014-06-10 Thread David Krings
On 6/10/2014 9:26 AM, Jerry B. Altzman wrote: The notion of "I don't have FB, therefore nobody should force FB auth" is equivalent to saying "we must absolutely positively backwards support IE6". This is 2014, sorry, if you don't want any social media accounts, that's your prerogative, but the va

Re: [nyphp-talk] Relax your password rules

2014-06-10 Thread Gary Mort
On 06/09/2014 11:02 AM, Chris Snyder wrote: More and more people just use "I forgot my password", and deal with it that way. Either you've exchanged the password for a security question, or just access to a user's email. For casual access, it's okay to just skip the p

Re: [nyphp-talk] Relax your password rules

2014-06-10 Thread Gary Mort
On 06/09/2014 10:44 AM, Jerry B. Altzman wrote: on 6/7/2014 10:38 AM Gary Mort said the following: A plea to anyone setting up a website where you will have users log on. Make your default password rule something simple, like any 4 charectors. A password complexity system should allow for mul

Re: [nyphp-talk] Relax your password rules

2014-06-10 Thread Jerry B. Altzman
on 6/10/2014 9:55 AM Federico Ulfo said the following: The notion of "I don't have FB, therefore nobody should force FB auth" Oauth should be an extra option not the only option!!! s/should force/should encourage/ Most people do use Social Networks but there's a small minority tha

Re: [nyphp-talk] Relax your password rules

2014-06-10 Thread Federico Ulfo
> > The notion of "I don't have FB, therefore nobody should force FB auth" Oauth should be an extra option not the only option!!! Most people do use Social Networks but there's a small minority that doesn't use or use them in a different way context, for example I use Google+ only with my work e

Re: [nyphp-talk] Relax your password rules

2014-06-10 Thread Jerry B. Altzman
on 6/9/2014 7:04 PM David Krings said the following: On 6/9/2014 10:44 AM, Jerry B. Altzman wrote: on 6/7/2014 10:38 AM Gary Mort said the following: A plea to anyone setting up a website where you will have users log on. Make your default password rule something simple, like any 4 charectors.

Re: [nyphp-talk] Relax your password rules

2014-06-09 Thread David Krings
On 6/9/2014 10:44 AM, Jerry B. Altzman wrote: on 6/7/2014 10:38 AM Gary Mort said the following: A plea to anyone setting up a website where you will have users log on. Make your default password rule something simple, like any 4 charectors. A At that point why bother with a password at all?

Re: [nyphp-talk] Relax your password rules

2014-06-09 Thread Bill Patterson
I was once scammed by a site proporting to be using my facebook account and requiring my facebook user name and password. I thought I'd smell those situations by now but missed that one until my sister noticed some things originating from my facebook account that weren't like anything I'd send

Re: [nyphp-talk] Relax your password rules

2014-06-09 Thread Federico Ulfo
I share the same feeling on too pretending password rules: "Your password must contain a capital letter, a number, an emoji, 8 elements from the periodic table and a plot containing a protagonist with some character development and a twist ending." but I couldn't suggest to make password less rest

Re: [nyphp-talk] Relax your password rules

2014-06-09 Thread Pierpaolo D'Aimmo
I had issues with FB authentication when trying to login from a mobile. Last time it happened it was with Grooveshark. I created the account with a FB login from a desktop, then tried to login on mobile and it was impossible, since their mobile interface doesn't use FB login. Pierpaolo D'Aimmo +1

Re: [nyphp-talk] Relax your password rules

2014-06-09 Thread Chris Snyder
> > More and more people just use "I forgot my password", and deal with it >> that way. Either you've exchanged the password for a security question, or >> just access to a user's email. >> > > For casual access, it's okay to just skip the password field altogether and use a token sent to email or

Re: [nyphp-talk] Relax your password rules

2014-06-09 Thread Jerry B. Altzman
on 6/7/2014 10:38 AM Gary Mort said the following: A plea to anyone setting up a website where you will have users log on. Make your default password rule something simple, like any 4 charectors. A password complexity system should allow for multiple tiers of rules with configurable default ru

[nyphp-talk] Relax your password rules

2014-06-07 Thread Gary Mort
A plea to anyone setting up a website where you will have users log on. Make your default password rule something simple, like any 4 charectors. A password complexity system should allow for multiple tiers of rules with configurable default rule that is set, by default :-), to something simple