Jump to content

Security best practices


Recommended Posts

Forum security is an issue of striking a balance between degree of bulletproofness and usability. If Squad really wanted to use industry best practices for security it'd require 2-part authentication... but it would be too much of a hassle for folks to make them dig around for their phone or tablet or whatever just to log in. If personally-identifiable information (PII) was stored here like purchase orders or the like, maybe it would be acceptable degree of inconvenience; but not for a non-commercial social forum.

During the Great Forum Whoopsies this week with v0.21's release, I got Error-500'd while logging in and tripped the "failed to log in too many times" threshold somehow. This made me wait for I think it was an hour before allowing me to sign back in. I think that's enough protection while keeping the forums simple to use.

-- Steve

Link to comment
Share on other sites

This thread is quite old. Please consider starting a new thread rather than reviving this one.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...