![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
View Poll Results: Is it better to Auto-Genarate your New Member's User/Password? | |||
Yes |
![]() ![]() ![]() ![]() |
10 | 58.82% |
No |
![]() ![]() ![]() ![]() |
7 | 41.18% |
Voters: 17. You may not vote on this poll |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Industry Role:
Join Date: Mar 2003
Location: San Diego
Posts: 32,235
|
![]() Please vote.
The advantage of auto-gen is, its a strong password vs. they usually choose a easy one which gets hacked. ![]()
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
I am Amazing Content!
Industry Role:
Join Date: Feb 2004
Posts: 39,828
|
yes
45678
__________________
AmazingContent.com - providing only the best content and service since 2003 Monetize your content on Veegaz.com - one of Germanies largest VOD sites Got German traffic? We convert it into money for you! Skype: madalton02826 - Email: oltecconsult [at] gmail [dot] com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Confirmed User
Join Date: Apr 2003
Location: Loveland, CO
Posts: 5,526
|
I hate auto-generated passwords... just more crap I have to hunt down and change. If a site auto generates my pass, and also requires an email confirmation link I need to click, I hate the site. Email confirmation is one thing, but I can't see how auto-generating something I should create myself; my login credentials, regardless of how retarded they may be, should be left up to me.
Really, how is "asd%$#908sd!!" as a password different from "fuck" when both can get posted somewhere or pasted into a scraper?
__________________
Your post count means nothing. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 | |
Industry Role:
Join Date: Mar 2003
Location: San Diego
Posts: 32,235
|
Quote:
![]()
__________________
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 | |
I am Amazing Content!
Industry Role:
Join Date: Feb 2004
Posts: 39,828
|
Quote:
does not prevent posting of user/pass somewhere, but decreases the chances of password hacks
__________________
AmazingContent.com - providing only the best content and service since 2003 Monetize your content on Veegaz.com - one of Germanies largest VOD sites Got German traffic? We convert it into money for you! Skype: madalton02826 - Email: oltecconsult [at] gmail [dot] com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Confirmed User
Industry Role:
Join Date: Sep 2002
Posts: 5,391
|
Technically yes, practically no
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
Confirmed User
Join Date: Apr 2008
Location: Always "Travelin Light"
Posts: 622
|
You could let them generate the password themselves and then auto-expire every 30 days to protect from content theivin...
![]()
__________________
http://mega.co.nz |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
jellyfish
![]() ![]() Join Date: Dec 2003
Posts: 71,528
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
Cherry Pimps
Industry Role:
Join Date: Aug 2005
Location: Arizona
Posts: 1,198
|
Auto Gen
![]()
__________________
![]() Traffic Pimps Webmaster / Content Manager Email: [email protected] Skype: kellie_az ICQ: 216375050 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 | |
Confirmed User
Join Date: Apr 2003
Location: Loveland, CO
Posts: 5,526
|
Quote:
Then again, what is one trying to protect: user stupidity or content of a site the user joins up with? As we all know, "security is a myth". Does one make the user jump through hoops to join, or just let the user in. One can even implement a solution that keeps track of logged in accounts and denies subsequent logins from the same account if a threshold is met. Then you run into dumb users sharing their logins and not realizing they were stupid and you have a help desk issue as Manowar pointed out. I've got no answers. I just hate auto-generated passes.
__________________
Your post count means nothing. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
Amateur Pimpin
Industry Role:
Join Date: Aug 2004
Location: Orlando, FL
Posts: 13,075
|
I just hate auto-generated passes when I'm the one getting them
__________________
Make easy money with Webcams |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
Doin fine
Industry Role:
Join Date: Oct 2005
Posts: 24,983
|
I wish we didn't have to auto generate as I hate it too, but honestly people pick fucking retarded user / pass combo. Just stupid. lol
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
Confirmed User
Join Date: Nov 2003
Location: San Diego
Posts: 4,274
|
auto gen with RoboForm or 1Password(mac). That way all your passwords are different but you have 1 master to access/fill
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 | |
Confirmed User
Join Date: Jun 2004
Location: email: exhelp(AT)bibar|DOT|com
Posts: 1,171
|
![]() Quote:
on the other hand "asd%$#908sd!!" is unlikely to be on a brute force attack.
__________________
exhelp AT bibar | DOT | com (please include your ICQ when emailing me) What ppl say about BlackElf |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 | |
It's coming look busy
Join Date: Mar 2001
Location: "Ph'nglui mglw'nafh Cthulhu R'lyeh wgah'nagl fhtagn".
Posts: 35,299
|
Quote:
Makes it harder for brute shit, and for username/passwords being compromised at one site and then the person gets nailed everywhere else on top of it for using the same ones. Just remind the people to click the save log in detail box or whatever.
__________________
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 | |
Confirmed User
Join Date: Oct 2008
Posts: 770
|
Quote:
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 |
Registered User
Join Date: Apr 2009
Location: London(UK)
Posts: 38
|
Depends on the type of site, e.g a dating site, allow users to enter thier own, as getting onto the site is part of the sales funnel, and you don't want to loose a customer when they can't remember a pass and thier email is bolloxed. For a paysite, I would autogen to ensure that its strong.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 |
Confirmed User
Join Date: Mar 2008
Location: Colorado Springs
Posts: 618
|
Isn't that the truth - we went to auto generated passwords about two years ago - we get the occasional help desk request for a lost password but it hasn't been a real problem.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 | |
Confirmed User
Industry Role:
Join Date: Mar 2007
Posts: 7,771
|
Quote:
and this increases the pass word strength. However when the user creates the pass word the pass word traders can sometimes be spotted right away by the pass word they chose. When a join comes in and the pass word is "123456" I just immediately delete the user and issue a refund. It's going to chargeback/bounce anyway so just kill the account before that happens. I wouldn't catch those if I generate the password myself.
__________________
![]() ![]() ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 | |
Industry Role:
Join Date: Mar 2003
Location: San Diego
Posts: 32,235
|
Quote:
![]()
__________________
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 |
Confirmed User
Join Date: Oct 2002
Posts: 3,745
|
Letting users choose their own passwords sucks because so many choose "password"
for their password, or something equally as easy to guess. A great many will choose a dictionary word or a variation on a dictionary word, such as adding a single digit to the end, so that's easy for the bad guys to guess. Typical auto generated passwords suck because "Ad%O$#908sD^!" is very hard to remember and easy to mistype. We found another approach which doesn't suck, and we made a free online tool for anyone who wants to use it. We generate passwords which LOOK like English words, so they are very easy to type and aren't too hard to remember. They are NOT actually words, though, so they won't be in the cracker's dictionary. Examples are frucspin and relitemer . The free tool to generate these can be found at: http://www.bettercgi.com/strongbox/passgen/
__________________
For historical display only. This information is not current: support@bettercgi.com ICQ 7208627 Strongbox - The next generation in site security Throttlebox - The next generation in bandwidth control Clonebox - Backup and disaster recovery on steroids |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 |
Too lazy to set a koala
Industry Role:
Join Date: Jan 2007
Location: CZ/EU forever!
Posts: 16,139
|
its not about random or not random if you use protection as strongbox. random passes are good for sites that cannot afford sb, pennywize or some ip blocking software ... but users dont like it ... even if you have hole in system and their random passes are "hacked" ... its not about random or not ...
![]()
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#23 |
Two fresh affiliate progs
Industry Role:
Join Date: Nov 2004
Location: Inside teen pussy
Posts: 29,602
|
Autogenerate with random is the best as well as using Proxypass.
__________________
[email protected] Skype: 17026955414 Vacares Web Hosting - Protect Your Ass with Included Daily Backups |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#24 |
Industry Role:
Join Date: Mar 2003
Location: San Diego
Posts: 32,235
|
keep the votes coming!
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |