[jira] [Commented] (OFBIZ-11244) Remove the user login security question

Previous Topic Next Topic
 
classic Classic list List threaded Threaded
1 message Options
Reply | Threaded
Open this post in threaded view
|

[jira] [Commented] (OFBIZ-11244) Remove the user login security question

Nicolas Malin (Jira)

    [ https://issues.apache.org/jira/browse/OFBIZ-11244?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17060772#comment-17060772 ]

Wiebke Pätzold commented on OFBIZ-11244:
----------------------------------------

Hi [~holivier],

You are right, I accidently deleted the two buttons as well. In the correction.patch I added the lines again.

I hope this hasn`t caused any inconvenient for you.

 

> Remove the user login security question
> ---------------------------------------
>
>                 Key: OFBIZ-11244
>                 URL: https://issues.apache.org/jira/browse/OFBIZ-11244
>             Project: OFBiz
>          Issue Type: Improvement
>          Components: ecommerce, framework, party
>    Affects Versions: Trunk
>            Reporter: Jacques Le Roux
>            Assignee: Michael Brohl
>            Priority: Major
>             Fix For: Upcoming Branch
>
>         Attachments: OFBIZ-11244-framework-correction.patch, OFBIZ-11244-framework.patch, OFBIZ-11244-plugins.patch
>
>
> After our discussion in dev ML at https://markmail.org/message/2dhc4al4adwgvl7z we will remove this feature. This [~paulfoxworthy]'s remark is notably important:
> bq. Security is only as good as its weakest link ( https://www.schneier.com/essays/archives/2005/02/the_curse_of_the_sec.html) , and security questions can be a real weakness. Any organisation using OFBiz that really hates passwords could look at security keys from Yubico or the like.



--
This message was sent by Atlassian Jira
(v8.3.4#803005)