Friday, March 26, 2010

Pet Peeve

I'm not a big fan of having to create an account on a website in order to use it. I can understand why they ask people to register, but I don't have to like it.

So when I do finally succumb and create an account, I do expect a certain level of... proficiency. And to achieve this goal, they just have to manage one simple thing: DON'T SEND ME MY PASSWORD IN AN EMAIL. This is such a flagrant disregard for basic security that it's likely to make me blacklist the site altogether.

In this day and age, with identity theft such a common event, the lazy developer responsible for this atrocity should be run out of town. If you've implemented such a system and don't know why this is a bad idea, shame on you.

If you don't want to put the effort into designing something more secure, just take advantage of one of the single sign-on authentication schemes like OpenID or Facebook Connect.

No comments: