[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RE: [cobalt-users] CGI Script Question
- Subject: RE: [cobalt-users] CGI Script Question
- From: "Dan" <dan@xxxxxxxxxxxxx>
- Date: Sun Aug 13 21:29:55 2000
> Creating usernames that do not match email address aliases and are
> difficult to guess is an excellent idea. I do so myself. I never have to
> worry about email sent to one user accidentally going to another b/c of a
> conflict b/w a username on one site and an alias on another. Plus, from
> the username alone I know exactly what server and what site that user is
> part of. It also reduces the ability of a hacker to gain access by trying
> to login using the left-hand side of an email address as a username since
> that is never a username on my servers.
>
It's one of those things where you have to be firm with your clients and
remember they're "tenants" in your "building" (server). Just as any landlord
has certain terms in the lease, assigning passwords should be one of yours.
"Yes, you can have the email address webmaster@ sales@ info@ but your user
name will be joe_4fJc. You wouldn't want your web site easily hacked, would
you?" Seems to work.
--
Dan Kriwitsky