Sign in or Join FriendFeed
FriendFeed is the easiest way to share online. Learn more »
The Problem with Password Masking - http://www.schneier.com/blog...
"Shoulder surfing isn't very common, and cleartext passwords greatly reduces errors. It has long annoyed me when I can't see what I type: in Windows logins, in PGP, and so on." - Panagiotis Astithas
In my mind this is a non problem. Sure Nielsen is a usability expert and Schneier is God, but they are wrong. If we are to do what the users expect us to do, then either we password mask everywhere or not (*including* public terminals and ATMs). Could it be that Nielsen wrote this article after misspelling a password a few times and getting blocked from his system? - Yiorgos Adamopoulos
Why should the options be black or white? Mask everywhere or nowhere? Why not mask only where it is absolutely critical to do so (i.e. the security risks outweigh the inconvenience)? - Panagiotis Astithas
Because as Nielsen says, we must do what the users expect us to do. This makes it black or white. I am all for variations, but I am not an ordinary user. - Yiorgos Adamopoulos
Nielsen's piece is strictly about computers and mainly about web apps. Schneier generalizes the discussion to ATMs, etc. So, regarding Schneier's take, wouldn't you agree that there is no black and white? If you frame the discussion strictly around Nielsen's piece, then what is the counter-argument about removing masking from "many web sites (and many other applications)"? - Panagiotis Astithas
Both classes of applications have the same (dumb / bored / careless) userbase. So yes, Nielsen discusses web usability, but what the user expects from a password entry point is the same, regardless of it being a web application, a login window or prompt or even the PIN keypad and screen. This makes it all or nothing. The problem is not solved by unmasking passwords. The problem is that we need a different kind of authentication for these users. What kind? I do not know. - Yiorgos Adamopoulos
Besides your apparent dislike of a non-generalized solution, you still haven't described what do we lose by removing the masking, only in the specified use cases. - Panagiotis Astithas
We do not lose spelling mistakes. For more than a lifetime we educate users to use hard to guess passwords. Hard to guess passwords are hard to type by heart regardless of whether the field is masked or not. On the other hand, "easy" passwords are easy to type regardless of the situation. So while it may seem logical that unmasking helps, we virtually gain nothing. In this case Nielsen and Schneier suffer from "groupthink". My userbase instructs me otherwise and I can privately offer graphic examples. - Yiorgos Adamopoulos
You almost convinced the man http://www.schneier.com/blog... - Christos Stathis
Firefox 3.5 on Ubuntu seems to have noticeably improved font rendering. Either that, or I need to change my default fonts.
Beyond Relational Databases: http://thinkvitamin.com/dev...
OAuth, here she comes - http://technically.us/code...
Hilarious! If you are a programmer, that is... - Panagiotis Astithas
FireStatus 1.8.1 is out, with bug fixes and Firefox 3.5 compatibility https://addons.mozilla.org/en-US...
Intuition, Peformance, and Scale - http://www.addsimplicity.com/adding_...
Predictably Irrational: The Hidden Forces That Shape Our Decisions - http://www.amazon.co.uk/dp...
Predictably Irrational: The Hidden Forces That Shape Our Decisions
A good use of web technology: http://ub0.cc/3p/0S
@christias: FLOSS we trust: FreeBSD #ellakconf
Dimitris Andreadis: "Work with developers better than you" #ellakconf
Implementing OAuth with GWT http://raibledesigns.com/rd...
Hoping to catch up with old friends at #ellakconf
Η ΕΤ3 έχει συζήτηση με 4 παράθυρα, εκ των οποίων στο ένα είναι ο Ανδριανόπουλος από webcam. The shape of things to come?
Retrying transactions with exponential backoff - http://astithas.blogspot.com/2009...
On Carving Your Initials - http://www.tbray.org/ongoing...
"Build something that you need yourself". I keep telling you over and over. - Christos Stathis
And he replies what? - Yiorgos Adamopoulos
He seems to agree, but I 'm not quite certain - Christos Stathis
Agreeing is the easy part. - Panagiotis Astithas
So what do you need? - Yiorgos Adamopoulos
Exactly. - Panagiotis Astithas
An Optimistic View of Net Neutrality - http://paulspontifications.blogspot.com/2009...
"Unlike many commentators I believe that in the long run this argument will be irrelevant, and that whatever various governments do on the subject will make little or no difference, and I believe this because of Metcalf's Law." - Panagiotis Astithas
Cryptographic Right Answers http://www.daemonology.net/blog...
Retrying transactions in Java - http://astithas.blogspot.com/2009...
Ruby at ThoughtWorks - http://martinfowler.com/article...
"Our strength is that we hire highly talented people who are difficult to attract to the typical IT organization. Ruby has a philosophy of an environment that gives a talented developer more leverage, rather than trying to protect a less talented developer from errors. An environment like Ruby thus gives our developers more ability to produce their true value." - Panagiotis Astithas
"One of the great benefits of these dynamic objects is that schema migrations become very easy. With a traditional RDBMS, releases of code might contain data migration scripts. Further, each release should have a reverse migration script in case a rollback is necessary. ALTER TABLE operations can be very slow and result in scheduled downtime. With a schemaless database, 90% of the time adjustments to the database become transparent and automatic." - Panagiotis Astithas
As always I have just one question: Where is the math? - Yiorgos Adamopoulos
Would you ask the same question if the debate was about the relative beauty of jazz vs. classical music? - Panagiotis Astithas
No I would not. For Xenakis music and the like, yes I would. On the subject: Either one can prove mathematically the validity of speed, or cannot. So unless I see complexity measures on time and space and a mathematical formalization on the queries, I still consider any such view as a plain hack. Returning to the era before Codd's mathematical model is hardly innovation. Keep in mind... more... - Yiorgos Adamopoulos
Why do you see this as an attack against the relational model? All I can see is a different solution to some of the problems relational DBMSs address, albeit with different tradeoffs. You may belittle such approaches as hacks, but this doesn't change the fact that they provide important tangible benefits in some scenarios. Unix was a hack compared to Multics. A PC was a hack compared to a workstation. Ruby was a hack compared to Java. - Panagiotis Astithas
Or, as Ralph Waldo Emerson eloquently put it: "A foolish consistency is the hobgoblin of little minds, adored by little statesmen and philosophers and divines." :-) - Panagiotis Astithas
I see such articles as attacks on the relational model for one simple reason: They compare their "innovative" (as in 30+ years old) approach with the relational model to prove they are better. Only had they done their homework right, they would already know that for the last 30 years we already know what the relational model is good for and where it does not fit. So comparing a "new... more... - Yiorgos Adamopoulos
Nah, you are too harsh to these people. It may be clear to you and me that the relational model is a poor choice in some situations, but for the majority of developers who need to persist data, RDBMSs are the only way to do it. It says so in the manual, and I have worked with many of them. And of course, not everyone had a chance to work in or near a dblab :-) - Panagiotis Astithas
As always we violently agree. Yes I am harsh when people operate under the illusion that data in a table equals relational data. When working on a project it saves time. - Yiorgos Adamopoulos
Στη Χάρητος και πάλι. Μετά από χρόνια. Στη λάθος μεριά.
The Median Isn't the Message http://www.cancerguide.org/median_...
OK, now I _must_ see the new Star Trek: http://cinemascopian.com/2008...
Typing The Letters A-E-S Into Your Code? You’re Doing It Wrong! http://www.matasano.com/log...
SWT toolkit creator leaves IBM: http://inside-swt.blogspot.com/2009...
@hakmem As the Apple ad used to say: Think different!
@keramida What would be really depressing is if in this day and age the benefits of open-source were obvious only to the left
How could we get more MEPs to sign The Free Software Pact? http://www.freesoftwarepact.eu/signato...
Other ways to read this feed:Feed readerFacebook