![]() |
2010-06-25
, 22:50
|
|
Posts: 186 |
Thanked: 192 times |
Joined on Jan 2010
@ Finland
|
#22
|
Finally, I like/hate the idea of OpenID. If anyone can get into the loop at some point I'm doomed.
![]() |
2010-06-25
, 23:49
|
Posts: 336 |
Thanked: 610 times |
Joined on Apr 2008
@ France
|
#23
|
![]() |
2010-06-26
, 07:53
|
|
Posts: 584 |
Thanked: 700 times |
Joined on Jan 2010
|
#24
|
![]() |
2010-06-26
, 09:27
|
|
Posts: 284 |
Thanked: 498 times |
Joined on Jun 2009
@ Poland
|
#25
|
Recently I've tried multi calendar widget just to try what it is. Because i didn't like it. after a few minutes of testing I've decided to uninstall it. The process was going ok but suddenly I saw that it is downloading and installing something. Later I saw in the app manager an other widget- eve on-line. I don't like the de that something is installing to my phone without my permission. I'm starting to lose faith in those community applications. How can I know that it is not recording somewhere my bank account password?
![]() |
2010-06-26
, 10:07
|
|
Posts: 186 |
Thanked: 192 times |
Joined on Jan 2010
@ Finland
|
#26
|
They are really, far, far more than simple RNG's; so no need to try and simplify them in that way.
![]() |
2010-06-26
, 10:32
|
Posts: 336 |
Thanked: 610 times |
Joined on Apr 2008
@ France
|
#27
|
![]() |
2010-06-27
, 18:23
|
|
Posts: 2,050 |
Thanked: 1,425 times |
Joined on Dec 2009
@ Bucharest
|
#28
|
Rather, the value is specifically computed every time you actually ask it to do so (VeriSign doesn't implement Time counters, but others do, which is far more secure).
I've been toying with the idea of writing my own OpenID provider that would require me to approve account access from my N900.
![]() |
2010-06-27
, 20:29
|
Posts: 336 |
Thanked: 610 times |
Joined on Apr 2008
@ France
|
#29
|
I have one of those, it computes a reply from the challenge request from the server and internal clock (and PIN), meaning that the password is only valid that minute (among other things). They do have the drawback of time desync. If I don't use it often enough, clocks desync and I have to call them.
![]() |
2010-06-27
, 20:38
|
|
Posts: 2,050 |
Thanked: 1,425 times |
Joined on Dec 2009
@ Bucharest
|
#30
|
No. When you use it in async mode (challenge/response), then there is absolutely no use of the internal clock. It can be that the authentication server only allows a specific challenge for a specific length of time.
If you want, I can go into much further detail of the algorithms. Three months have passed, so I'm legally allowed to disclose stuff now.
Which reminds me, if you see me suddenly posting odd stuff, please reset my password to "blubbers". :D
Finally, I like/hate the idea of OpenID. If anyone can get into the loop at some point I'm doomed. Only thing I got through OpenID is very low level stuff, tier 4 and 5. At tier 3, only one person knows my password, and it's dictionary-proof. At 2, I have a single password nobody knows. At tier one, I use a long password combined with special chars when limited, and hardware-assisted login when not (I carry a card and a digital token at all times).
N900 dead and Nokia no longer replaces them. Thanks for all the fish.
Keep the forums clean: use "Thanks" button instead of the thank you post.