photo.self-portrait.flickr-avatar

Bothell, Seattle, Washington

Web Developer

tinkers with designing and building websites and web apps to keep sharp

Game Developer

programs Unity Engine, iPhone, Nintendo DS and games that make children all over the world scream “SPIDER-MAN!!!” at Christmas

Hobby Photographer

shoots whatever fits his fancy and has done a couple fine-art series

Slippy Douglas…

RT @hotdogsladies: Dismissing the iPad for not running Flash is like hating a salad fork for not playing 8-tracks.

Recent Thoughts

more Thoughts…

Personal Security Tip: Passwords in E-Mails

A quick way to keep your accounts from getting hi-jacked or otherwise vulnerable to security risks is to take care of passwords in cleartext in e-mails.

What do I mean by that? Well, often when you reset your password on a website, they’ll send you an e-mail back with a one-time-use link for resetting your password via the website itself. However, some poorly-written websites will just send you your username and password in a normal e-mail that could be sniffed by a hacker as it’s being sent.

Frankly, the website shouldn’t even have your password in a non-encrypted form. The proper way they should have their site set-up is to store your password in an encrypted form, then when you type it in to log in, they encrypt and check the password entered against your encrypted password in their database

To fix this:

  1. Go into your e-mail and do a full-text search for each of the passwords you normally use (yes, everyone does it). This is fairly easy to do and only takes a few seconds in most mail applications and web apps (i.e. Apple Mail and GMail), though some mail programs could take hours (i.e. Outlook).
  2. Then note the companies that sent your password in cleartext.
  3. Lastly, delete the offending e-mails (make sure to go into the trash and delete them again to fully get rid of them).

Then, I would boycott the site(s) that violated your password privacy. If you really must use a particular site, you could give it a completely unique password and write it down somewhere safe (I suggest an online note-taking tool so that you have access to it wherever you have Internet access).

That’s it! repeat every once in a while, or just watch for new e-mails with passwords in them. Some services will send your password monthly (i.e. the MailMan mailing list server), so those are ones that should definitely be unique.

Until next time… good luck!

Recursion error: already rendering the `body' part.
Recursion error: already rendering the `body' part.
Recursion error: already rendering the `body' part.
Recursion error: already rendering the `body' part.
Recursion error: already rendering the `body' part.
Recursion error: already rendering the `body' part.
Recursion error: already rendering the `body' part.
posted on Monday, November 30, 2009 at 5:25 PM PST by Slippy Douglas | 3 comments
read more…

Recent Projects

more Projects…

OrgClut

I'm currently working on a personal organization web app called OrgClut.

In OrgClut, all content is added to the user's own personal “Pile”, which is one giant deeply nested list. This can be "scoped into" to get at the information needed. Each item in these lists can have check boxes, priorities, labels, links, dates/times, images, videos, etc attached to it, then be sorted, filtered, and shared based on the needs of each Pile. I'm targeting both desktop and mobile platforms; and have some unique design goals for the app: it uses CSS3 and HTML5 heavily, allow it to have zero image files.

Currently, I'm accepting beta invite requests; check out the screenshot(s) and sign up if you want to try it out once it's ready. (Sign-up for an invite at the bottom of OrgClut.com.)

Recent Photos

more photos on flickr