Click here to Skip to main content
15,891,184 members

Welcome to the Lounge

   

For discussing anything related to a software developer's life but is not for programming questions. Got a programming question?

The Lounge is rated Safe For Work. If you're about to post something inappropriate for a shared office environment, then don't post it. No ads, no abuse, and no programming questions. Trolling, (political, climate, religious or whatever) will result in your account being removed.

 
GeneralRe: Not for the faint of heart... Pin
MichaelLuna14-Jun-21 5:40
MichaelLuna14-Jun-21 5:40 
GeneralRe: Not for the faint of heart... Pin
Dan Neely11-Jun-21 4:51
Dan Neely11-Jun-21 4:51 
GeneralRe: Not for the faint of heart... Pin
Sander Rossel11-Jun-21 4:57
professionalSander Rossel11-Jun-21 4:57 
GeneralRe: Not for the faint of heart... Pin
Dan Neely11-Jun-21 5:12
Dan Neely11-Jun-21 5:12 
GeneralRe: Not for the faint of heart... Pin
Mycroft Holmes11-Jun-21 12:34
professionalMycroft Holmes11-Jun-21 12:34 
GeneralRe: Not for the faint of heart... Pin
HuntrCkr13-Jun-21 21:41
HuntrCkr13-Jun-21 21:41 
GeneralRe: Not for the faint of heart... Pin
Sander Rossel13-Jun-21 21:56
professionalSander Rossel13-Jun-21 21:56 
GeneralRe: Not for the faint of heart... Pin
HuntrCkr14-Jun-21 0:14
HuntrCkr14-Jun-21 0:14 
Sander Rossel wrote:
Yes always, there's a very good chance that user uses this password everywhere.
If you know their password you could probably login to their Facebook, Google, Instagram and bank accounts.
If someone hacks your database and the passwords are not sufficiently secured (and personally I think anything less than a strong hash is not sufficient), those hackers can now login to those accounts too.
And if those hackers post everything online, everyone can login to those accounts.
It doesn't matter what data a password secures, the password in itself is private and VERY SENSITIVE data.
In a perfect world it would be some "unhackable" randomly generated string of at least 24 characters, but we're living in a world where 123456 is still the most used password.
It's actually far worse than that... the users don't even get to choose their own passwords. They are assigned by IT (Not a policy I approve of or had any hand in), so the chances of that password being reused elsewhere is very slim, unless this might be the first password they ever use and they then decide to use it everywhere. But honestly, what's the chances.
Edit: Forgot to add that surprisingly enough, these password are quite strong passwords with no pattern on how they are created... not 24 char random strings, but at least decent enough to keep most at bay I would say. For example, Ap@rtmentDataC0nnect10n was one memorable one I saw (relax...no longer in use Poke tongue | ;-P Wink | ;) )
Sander Rossel wrote:
Schedule a call with the user, add boatloads of logging, get only that part what you need from the production database (preferably from a "privileged" individual who has rights to that database).
Did that before too when working with a client where impersonation was not possible. Sometimes the effort and time involved in getting multiple cycles of changes deployed to a production environment just to debug a problem is not realistic or in the client's best interests.
BTW, when I say impersonation, I am by no means advocating something like a button allowing ordinary or even support staff to impersonate someone. I mean impersonation by somebody that in any case has full access to the entire production database(s) and code base. Typically the most senior 2 or 3 devs/architects/whatever on the team would be my exception here, and as you say, only when the system does not store sensitive personal information.
Sander Rossel wrote:
And that invalidates all reasons why you should have an impersonation button or make passwords recoverable
Agreed... Passwords should never be stored readable, and impersonating someone should never be as simple as a button. I'm just saying that impersonation as a method for solving a serious problem should be a last resort, but not an absolute hard limit.

modified 14-Jun-21 6:30am.

GeneralRe: Not for the faint of heart... Pin
Dan Neely14-Jun-21 3:16
Dan Neely14-Jun-21 3:16 
GeneralRe: Not for the faint of heart... Pin
W Balboos, GHB15-Jun-21 2:14
W Balboos, GHB15-Jun-21 2:14 
GeneralRe: Not for the faint of heart... Pin
Member 916705713-Jun-21 21:07
Member 916705713-Jun-21 21:07 
GeneralRe: Not for the faint of heart... Pin
Sander Rossel13-Jun-21 21:57
professionalSander Rossel13-Jun-21 21:57 
GeneralRe: Not for the faint of heart... Pin
Member 916705713-Jun-21 22:24
Member 916705713-Jun-21 22:24 
GeneralRe: Not for the faint of heart... Pin
KateAshman14-Jun-21 22:09
KateAshman14-Jun-21 22:09 
GeneralSound of the Week Pin
Sander Rossel11-Jun-21 0:41
professionalSander Rossel11-Jun-21 0:41 
GeneralRe: Sound of the Week Pin
Kris Lantz11-Jun-21 2:20
professionalKris Lantz11-Jun-21 2:20 
GeneralRe: Sound of the Week Pin
Sander Rossel11-Jun-21 12:30
professionalSander Rossel11-Jun-21 12:30 
GeneralRe: Sound of the Week Pin
Choroid14-Jun-21 6:16
Choroid14-Jun-21 6:16 
GeneralRe: Sound of the Week Pin
Sander Rossel14-Jun-21 7:13
professionalSander Rossel14-Jun-21 7:13 
GeneralGoogle AI == Giggle ? the giant that ate the internet targets paid-for ads at random ? Pin
BillWoodruff11-Jun-21 0:23
professionalBillWoodruff11-Jun-21 0:23 
JokeRe: Google AI == Giggle ? the giant that ate the internet targets paid-for ads at random ? Pin
Nelek11-Jun-21 0:33
protectorNelek11-Jun-21 0:33 
GeneralRe: Google AI == Giggle ? the giant that ate the internet targets paid-for ads at random ? Pin
BillWoodruff11-Jun-21 10:11
professionalBillWoodruff11-Jun-21 10:11 
JokeRe: Google AI == Giggle ? the giant that ate the internet targets paid-for ads at random ? Pin
Greg Utas11-Jun-21 0:45
professionalGreg Utas11-Jun-21 0:45 
GeneralRe: Google AI == Giggle ? the giant that ate the internet targets paid-for ads at random ? Pin
DRHuff11-Jun-21 5:26
DRHuff11-Jun-21 5:26 
GeneralRe: Google AI == Giggle ? the giant that ate the internet targets paid-for ads at random ? Pin
BillWoodruff11-Jun-21 10:06
professionalBillWoodruff11-Jun-21 10:06 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.