Coder Social home page Coder Social logo

ap4rc's People

Contributors

darix avatar hirsm avatar jdsn avatar listerr avatar lrupp avatar

Stargazers

 avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar

ap4rc's Issues

Increase default expire interval for ap4rc passwords

In your default configuration, you have:

$config['ap4rc_expire_interval'] = "2 MONTH";
$config['ap4rc_warning_interval'] = "1 WEEK";

Could you please explain, why such (especially: short) intervals are needed?

I like to vote for longer times, as latest studies show that it's even better for security to allow users to have longer intervals for changing their own, memorized secrets - which are seen as much more insecure than generated ones.

Even the NIST guidelines removed the need for regular password (memorized secrets) changes since a while: "Users should change their password if they are compromised (or suspected to have been compromised)."

Enforcing a change of a generated application password in such short time frames looks contra-productive in this regard, but I agree that it can be an additional option for certain circumstances.

But your defaults will result in additional load for people inside support and confuse people. Just think about customers, who just notice that their application does not allow them to log in any longer. They will open support tickets just because they did not visit the WebUI.

Therefor I like to suggest longer default expiry times - or even allow to set the expiry time to '0', to disable expiry times completely.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.