|
|
|
|
![]() ![]() |
Jan 5 2007, 09:15 AM
Post
#1
|
|
|
Newbie ![]() Group: Members Posts: 2 Joined: 23-November 06 Member No.: 33,908 |
Hi,
I came across this website www.planmylifestyle.com which offers an innovative login system. In the traditional login system, a user is asked to enter a username and password besides many other personal information. In this website, to register the site creates an ID file that the user can download to the local hard drive. After registration, to login to the website, the user has to simply upload the registered ID file (browser and select ID file from local hard drive) and click on the Login Button. The user is then taken to the website which seems to be a search engine and submission service. All entries made in this site are then tagged on the basis of this ID file. Guru |
|
|
|
Jan 5 2007, 11:06 AM
Post
#2
|
|
|
Advanced Member ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 138 Joined: 30-September 06 From: Iasi, Romania Member No.: 30,851 |
well that would mean that I can login only from the computers which have that file downloaded...that is the biggest inconvenience that I see right now
and besides, why would such a login system be needed? I think that the traditional one, improved with an antispam (captcha) mechanism is good and secure enough...for now |
|
|
|
Jan 5 2007, 05:44 PM
Post
#3
|
|
|
$p4m 0n j00 $h4m3 m3 0nc3 $p4m 0n m3 $h4m3 m3 7\/\/1c3 ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: [HOSTED] Posts: 6,060 Joined: 21-September 04 From: 9r33|\| 399$ 4|\|D 5P4/\/\ Member No.: 1,218 ![]() |
Yeah it sounds good but this has so many security flaws that it's not even funny. If the users computer has already been cracked then the hacker just has to pay attention what that person does with that file, then have a field day with it.
Then assuming this is done by php and mysql other hackers just have to write the right code and then upload it with that file. But of course for that to happen, this code would have to be open source or the server this website is has bad security. Again it is different however, as mentioned above it is a hassle and a inconvenience since that file would have to be computer specific in order to work. |
|
|
|
Jun 22 2007, 10:44 AM
Post
#4
|
|
|
Newbie [Level 1] ![]() Group: Members Posts: 12 Joined: 22-June 07 From: India Member No.: 45,248 |
I think now the site has switched over to the plain username/password scheme.
|
|
|
|
Jul 19 2007, 07:39 AM
Post
#5
|
|
|
Advanced Member ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 143 Joined: 19-July 07 From: CA Member No.: 46,702 |
Very interesting idea but I agree with Saint Michael: way to many security issues. Good to see people are making an attempt and new things, though.
|
|
|
|
Jul 19 2007, 03:50 PM
Post
#6
|
|
|
Privileged Member ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: [HOSTED] Posts: 937 Joined: 14-April 05 From: West Chester, PA Member No.: 5,636 |
As nice as that sounds there are way too many things that are wrong from it. First of all, most people access secured systems from multiple computers which would mean you would have to store the file on all of them. Also, if you are using a public computer, you would have to remember to delete it before you leave that computer. Another issue is that one can learn how to decrypt these files and then make fake ones to access other users accounts. Finally, if a hacker was to get into the login code, they would be able to use these files to distribute malware and viruses since they gain access to your actual computer and not just the server. Overall, it could be a good idea but there are way to many security issues that would have to be addressed before any major system / company would use it.
|
|
|
|
Jul 21 2007, 11:33 AM
Post
#7
|
|
|
Super Member ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 219 Joined: 3-February 07 From: Algeria Member No.: 38,241 |
but how if you lost your ID file or damaged in your computer
|
|
|
|
Aug 13 2007, 12:44 PM
Post
#8
|
|
|
Advanced Member ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: [HOSTED] Posts: 136 Joined: 19-March 06 From: Mumbai, India Member No.: 20,314 |
Atleast they tried something innovative. Such trial n error methords will surely lead to a groundbreaking new login system. But when you are plannin new systems you need to know the flaws of the previous system. And as far as I see it, there is hardly any problem with the current system!!
|
|
|
|
Aug 13 2007, 01:30 PM
Post
#9
|
|
|
Advanced Member ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 116 Joined: 6-August 07 Member No.: 47,650 |
That's really cool and all, but it's pointless. For security reasons and because lets say you ruin your computer, you cant use the website anymore! I think thats annoying... Especially if its the type of website where you gain credits like Trap17 or you have a post count or whatever. It's never nice to have to start over with anything. Either way, I dont see a point of this besides being original and attracting visitors.
Thanks though. |
|
|
|
|
|