Hotmail Adds New Feature "My Friend's Been Hacked"
tekgoblin.com
tekgoblin.com
Awesome. Not like I use Hotmail, but... So now if someone's password generator just happen to generate "weak" password not containing, for example, a digit (uh, even `openssl rand -base64 12` provides such outputs from time to time) user'll have to step away from usual password generation scheme and create special password just for hotmail.com.
Please, for the love of sanity, never ever forbid any passwords (except for too short ones, with a reasonable minimal length). Just freak user out so he'll think twice before using possibly weak password. You'll educate users this way instead of frustrating them.
(And never limit maximum length or set of possible characters, except for rare cases where there are technical obstacles requiring to do so - like non-8-bit-safe protocols. If user wants to authenticate with a passpoem, written in runic alphabet — let him have it.)
sigh
:|
The interesting thing to note is that if they had any significant problem with this scheme, they would have changed it. Maybe we worry too much about the strength of passwords. The password verification process may be hardened enough, even for the needs of a bank.
I believed that it's generally expected that a password generator would produce passwords of a certain minimal length. At least I considered that nobody would write a generator (intended for a real-world usage) that'd produce, say, 3-character password for some edge case.
However, you sound reasonable. This leads us right to the extreme case - should empty passwords be allowed? (Considering that the user will be bugged like hell before letting him to do so.)
I should think more about this.
What does it mean? Can you answer in a way that isn't couched in the fashion of the day? There was a time when a Hotmail account was not looked down upon. What makes this instant in time so different, besides fashion?
You might wish to read this: http://lesswrong.com/lw/yp/pretending_to_be_wise/
Peace.
I have simply found that people's technical competence generally (GENERALLY) corresponds to what domain they are using. It's an observation, not a fashion trend.
Actually my choice to use hotmail is a reflection of me X years ago when I created the account. It is also a reflection of the state of free web based providers X years ago. You don't know the value of X, which makes it difficult to draw any conclusions from my email address.
I guess it's also a reflection of the current me in that I don't see the point of going through the hassle of ditching an email address just to have something slightly more trendy (and slightly more usable).
Tip: Hook your old and new accounts into Thunderbird with IMAP (IMAP is key. No POP3). Drag-and-drop your folders full of email from Old to New. Wait for it... you're done! Now turn on forwarding in your old email account, and never log in to it again.
I wouldn't write off a Hotmail address as a 'joke' though.. some of those who still have them may have had them a long, long time.
I couldn't tell if you were joking, so I just logged into my hotmail account after years. Wow, some things never change. What do your friends love more - the flashing banner ads or the Outlook-style frames with scrollbars?
This sounds like it could be easily abused. How will the password reset work if the hotmail address is the only one a user has? What will he need to do to reclaim access to his account?
- Only friends that communicate "a lot" should be able to report it (and not repeatedly).
- If the account's password was compromised, then the attacker will enter the account recovery flow on next login attempt. So the AR flow will need to ensure that the user is not the attacker (SMS and e-mail that are trusted, based on age and usage, is pretty good).
But why not just create a system that will alert the user when a successful login was made from a new device on their account? And include an account lock link in the e-mail, so they can quickly lock their account from anywhere with cell phone access.
I know plenty of people that have active and inactive Hotmail accounts and I don't get spam from them.
Maybe you and your circle all happened to use some of those other big profile sites (Gawker, Sony, etc.) that have had their e-mails and password lists stolen...