Is your Password Safe?
|
Ciaran Laval
Mostly Harmless
Join date: 11 Mar 2007
Posts: 7,951
|
01-17-2009 03:02
From: SuezanneC Baskerville I'm supposed to remember a unique string like "s8Xam8aQzaq91" for each of these accounts, not written down anywhere? It really depends upon how important the password is, what people could do if they guessed your password. There ways and means of doing it that make it less taxing on the memory.
|
Argent Stonecutter
Emergency Mustelid
Join date: 20 Sep 2005
Posts: 20,263
|
01-17-2009 03:20
From: SuezanneC Baskerville I would never be able to remember my passwords if I tried to follow rules like these. You have to have SOME place you haven't tattooed them yet.
|
Eata Kitty
Registered User
Join date: 21 Jan 2005
Posts: 387
|
01-17-2009 18:15
With thousands of people moving thousands to tens of thousands of dollars every month (according to the economic stats page) I think LL should really offer RSA SecureID tokens, or similar. Thousands of dollars in credit/lindens really deserves a bit more security.
There would be costs but a fee for tokens should help and it also saves money for LL when anything is prevented.
|
Craig Altman
Second Life Resident
Join date: 11 Nov 2004
Posts: 131
|
01-18-2009 01:52
OK how about this:
Ive opened tickets on this before, your JIRA will not accept complex passwords, if you make a very secure complex SL password containing characters like %^&*(), letters and number, caps and lower case etc that password WILL work for logging into SL and accessing your account page, it will not however be accepted to log into the JIRA.
Thus if you want to use the JIRA you have to change your main SL password to something insecure like "fred" to get into it.
If you want people to make secure passwords, all facets of the SL site should be made to accept these complex passwords.
|
Atashi Toshihiko
Frequently Befuddled
Join date: 7 Dec 2006
Posts: 1,423
|
01-18-2009 07:02
From: Argent Stonecutter SL security would be better, also, if you separated the account and avatar names... so for example instead of logging in as "Argent Stonecutter", I'd log in as "Argent007" or something that isn't actually published... and then picked my "Argent Stonecutter" alt from a pulldown.
* Something else for attackers to have to guess. * Better account management. * Fewer name-password combinations for users to remember. I've seen suggestions along these lines numerous times since I joined SL and I can't understand why LL doesn't go this way. Right now, if someone wants to attack my account they already know 2/3 of the required info... first name and last name. If we had a separate login id that was unrelated to our avatar names, then potential attackers would know nothing at all. Being able to group avatars under a single logon id & password would be an extra bonus, but just for a start it would be nice to have our logon credentials separated from our inworld names. LL could implement this without having to force people to resubscribe or whatever, just behind-the-scenes add another field to the database, populate it with firstname + lastname, and then make it an option on the account page of the website to change your login id. Phase it in over time. Grouping alts under one RL account can be a separate issue tackled later. IMHO this would be a great step along the way to improved security. As has already been mentioned, for some folks we're talking about real money in the thousands of $, it's not enough to just make a feelgood post now and then to remind people about secure passwords, when there's a lot more that can be done on the service-provider's side to improve security. -Atashi
_____________________
Visit Atashi's Art and Oddities Store and the Waikiti Motor Works at beautiful Waikiti.
|
Argent Stonecutter
Emergency Mustelid
Join date: 20 Sep 2005
Posts: 20,263
|
01-18-2009 10:50
Good thoughts on implementation. I used them in http://jira.secondlife.com/browse/MISC-2222 ... I hope you don't mind.
|
Anny Helsinki
Registered User
Join date: 23 May 2008
Posts: 50
|
01-18-2009 14:10
who needs a secure password when LL stops each sunday working? how complicated can it be, to have a working system on sundays too? there where a big concert for Obama, i would lilke to share inworld with my friends from all over the world. its a software, not a secret. please, give us back the wednesdays, maybe on mondays, because u arent able to work out ure own failures u build in before the weekend or an update. greetings america, america.. lol you can listen to some of the best musicians at http://teal.neostreams.info:12902
_____________________
http://www.youtube.com/watch?v=OM0g-7sZeSo
|
Loki Ball
Registered User
Join date: 9 Oct 2006
Posts: 85
|
Compatibility on other SL sites with passwords
01-18-2009 16:10
I found that with having a secure password for the main Second Life site didn't jive with the jira site. So in order to log into the jira I had to change my passwords in their secure forms. They were originally upper case, lower case, and mixes of numerics and symbols. Unfortunately due to a difference in the way the sites handle passwords the jira will not except those types. So in order to ever log into the jira you need to change your password. At least I did anyway.
I did a variety of comparisons in the amount of security my passwords claimed to have on various sites and their password securities. I found my original passwords were at the top at a level 5. When I was done making them so they'd work on the jira they were about a 3. I really wish they'd change that.
|
Anny Helsinki
Registered User
Join date: 23 May 2008
Posts: 50
|
01-18-2009 17:16
and why the login screen still online?
sundays arent your days right, .....man man ......
_____________________
http://www.youtube.com/watch?v=OM0g-7sZeSo
|
Pol McLaglen
Registered User
Join date: 15 Feb 2007
Posts: 12
|
01-21-2009 23:30
Try and learn a really ancient obscure written language then pick the rarest used (long) word from that language and THEN turn it into 13375p34k.
Considering that I sat seminary I have Hebrew, Aramaic and Greek under my belt. So I am sorted at least....
|
Riko Jarman
Registered User
Join date: 2 Nov 2007
Posts: 68
|
01-22-2009 09:37
Since SL is in essence a financial transaction system I think LL should place more controls around passwords.
Some controls needed are: password expiration, enforcement of strong passwords (for example, must contain at least 3 numerics and at least 3 alpha characters) and account lockout after too many wrong password attempts. There are a lot of way to make the last one work without calls to support such as using the secret question/answer pair to validate the user then e-mailing an expired new password to the user.
|
Libertine Freund
Registered User
Join date: 24 Jan 2007
Posts: 1
|
Not too long
01-25-2009 04:33
I agree with Loki Ball's comment about the differences in handling passwords between Second Life and Jira. In my case my SL password was too long for Jira. After I shorten it, I could login to Jira again. So perhaps add an extra tip to the password article: "Don't make them too long"  , till you solved this problem.
|