Skip to Content.
Sympa Menu

discuss - Re: [opennic-discuss] Announcement: New registrar for OSS and Parody

discuss AT lists.opennicproject.org

Subject: Discuss mailing list

List archive

Re: [opennic-discuss] Announcement: New registrar for OSS and Parody


Chronological Thread 
  • From: Calum McAlinden <calum AT mcalinden.me.uk>
  • To: discuss AT lists.opennicproject.org
  • Subject: Re: [opennic-discuss] Announcement: New registrar for OSS and Parody
  • Date: Sat, 8 Mar 2014 23:09:31 +0000

On 8 March 2014 22:34, Quinn Wood <wood.quinn.s AT gmail.com> wrote:
> On Saturday, March 8, 2014, Peter Green <peter AT greenpete.free> wrote:
>>
>> I'm not sure requiring phone numbers is good idea.
>>
> Multiple forms of second factors is definitely a good idea. Maybe something
> like a new code displayed each login that you need to use in addition to
> your password next time?

Use of phone numbers and SMS would be unnecessary, although as an
option I think it would be great. Time based authentication tokens
generated by smartphone apps such as Authy or Google Authenticator are
more simple to implement, cheap and reliable. They would be used along
with a username and password if the user wanted.
There's a lot of documentation on using TOTP (Time-based One-time
Password Algorithm) around, for various languages. I believe systems
like this are an important security measure especially after reading
about incidents such as the Twitter @N name (where a hacker was able
to reset the twitter password via hijacking the domain at the
registrar)

In my opinion, CAPTCHAs are horrible and should be avoided at all costs.

--
Calum McAlinden
http://www.mcalinden.me.uk



Archive powered by MHonArc 2.6.19.

Top of Page