<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Let&#8217;s Fail-To-Log-In Again, Like We Did Last Summer</title>
	<atom:link href="http://www.somethinkodd.com/oddthinking/2005/09/22/lets-fail-to-log-in-again-like-we-did-last-summer/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.somethinkodd.com/oddthinking/2005/09/22/lets-fail-to-log-in-again-like-we-did-last-summer/</link>
	<description>A blog for odd things and odd thoughts.</description>
	<lastBuildDate>Wed, 01 Feb 2012 22:21:16 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: OddThinking &#187; Browser Comparison: Password Management</title>
		<link>http://www.somethinkodd.com/oddthinking/2005/09/22/lets-fail-to-log-in-again-like-we-did-last-summer/comment-page-1/#comment-2427</link>
		<dc:creator>OddThinking &#187; Browser Comparison: Password Management</dc:creator>
		<pubDate>Sat, 07 Jan 2006 06:30:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.somethinkodd.com/oddthinking/?p=90#comment-2427</guid>
		<description>[...] Fail-To-Log-In Again, Like We Did Last Summer &#124; Humpty Dumpty sat on a RAID drive &#187;   Browser Comparison: Password Management Filed by: Julian on September 25th2005 [...]</description>
		<content:encoded><![CDATA[<p>[...] Fail-To-Log-In Again, Like We Did Last Summer | Humpty Dumpty sat on a RAID drive &raquo;   Browser Comparison: Password Management Filed by: Julian on September 25th2005 [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Julian</title>
		<link>http://www.somethinkodd.com/oddthinking/2005/09/22/lets-fail-to-log-in-again-like-we-did-last-summer/comment-page-1/#comment-771</link>
		<dc:creator>Julian</dc:creator>
		<pubDate>Sun, 25 Sep 2005 10:02:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.somethinkodd.com/oddthinking/?p=90#comment-771</guid>
		<description>&lt;!-- UnMarkedDown_2_01132522670--&gt;&lt;p&gt;Casey,&lt;/p&gt;

&lt;p&gt;You are assuming two things about the user:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;That they are aware that they are performing the dance. I recently listened to someone complain about the buggyness of an Intranet web-site, unaware that he was actually just stepping through the moves.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;That they could be bothered to perform this step. &quot;Well, I am in a hurry, and I am logged in now. I will clean it up next time I come to this site.&quot;&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Alastair, &lt;/p&gt;

&lt;p&gt;It sounds like Safari is acting very much like Firefox does. See the next post - coming very soon.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p><!-- UnMarkedDown_2_01132522670-->
<p>Casey,</p>
<p>You are assuming two things about the user:</p>
<ol>
<li>
<p>That they are aware that they are performing the dance. I recently listened to someone complain about the buggyness of an Intranet web-site, unaware that he was actually just stepping through the moves.</p>
</li>
<li>
<p>That they could be bothered to perform this step. &#8220;Well, I am in a hurry, and I am logged in now. I will clean it up next time I come to this site.&#8221;</p>
</li>
</ol>
<p>Alastair, </p>
<p>It sounds like Safari is acting very much like Firefox does. See the next post &#8211; coming very soon.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alastair</title>
		<link>http://www.somethinkodd.com/oddthinking/2005/09/22/lets-fail-to-log-in-again-like-we-did-last-summer/comment-page-1/#comment-757</link>
		<dc:creator>Alastair</dc:creator>
		<pubDate>Thu, 22 Sep 2005 22:41:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.somethinkodd.com/oddthinking/?p=90#comment-757</guid>
		<description>&lt;!-- UnMarkedDown_2_01132522670--&gt;&lt;p&gt;I have seen that problem before, but I just tried to recreate it with Safari and failed.&lt;/p&gt;

&lt;p&gt;I tried logging into a website with an incorrect password, and Safari remembered the incorrect password. I think this is actually reasonable because there are rarely any clues to the browser as to whether the login was successful or not.&lt;/p&gt;

&lt;p&gt;But when I finally entered the correct password, Safari overwrote the incorrect password with the correct one in it&#039;s database (after prompting a second time). I verified this by looking in the password database and verifying only one entry for that website. I also logged out and logged back in again using Safari&#039;s password and it worked OK.&lt;/p&gt;

&lt;p&gt;From the above description of Opera, it seems that Safari works a similar way with multiple usernames for a given website.&lt;/p&gt;

&lt;p&gt;The trick is to make sure that you either log in successfully to a given website, or remember to remove the website from the password database. I agree this is far from an ideal situation, but I believe my browser is doing the best it can under the circumstances. What we really need is a change to the underlying technology, such as the use of HTTP digest authentication perhaps? The key here is to enable the browser to know when authentication failed.&lt;/p&gt;

&lt;p&gt;For what it&#039;s worth I don&#039;t use the browser&#039;s password database that much these days. The main reason is that I have lots of browsers on lots of machines, and AFAIK you can&#039;t copy and merge their password databases. I am slowly migrating from a fairly weak set of password generation &#039;rules&#039;, backed up by a separate (i.e. non-browser) password database, to the &lt;a href=&quot;http://www.xs4all.nl/~jlpoutre/BoT/Javascript/PasswordComposer/&quot; rel=&quot;nofollow&quot;&gt; PasswordComposer tool&lt;/a&gt;. Results are inconclusive so far, because I have difficulty remembering which accounts I have migrated and which ones I haven&#039;t...&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p><!-- UnMarkedDown_2_01132522670-->
<p>I have seen that problem before, but I just tried to recreate it with Safari and failed.</p>
<p>I tried logging into a website with an incorrect password, and Safari remembered the incorrect password. I think this is actually reasonable because there are rarely any clues to the browser as to whether the login was successful or not.</p>
<p>But when I finally entered the correct password, Safari overwrote the incorrect password with the correct one in it&#8217;s database (after prompting a second time). I verified this by looking in the password database and verifying only one entry for that website. I also logged out and logged back in again using Safari&#8217;s password and it worked OK.</p>
<p>From the above description of Opera, it seems that Safari works a similar way with multiple usernames for a given website.</p>
<p>The trick is to make sure that you either log in successfully to a given website, or remember to remove the website from the password database. I agree this is far from an ideal situation, but I believe my browser is doing the best it can under the circumstances. What we really need is a change to the underlying technology, such as the use of HTTP digest authentication perhaps? The key here is to enable the browser to know when authentication failed.</p>
<p>For what it&#8217;s worth I don&#8217;t use the browser&#8217;s password database that much these days. The main reason is that I have lots of browsers on lots of machines, and AFAIK you can&#8217;t copy and merge their password databases. I am slowly migrating from a fairly weak set of password generation &#8216;rules&#8217;, backed up by a separate (i.e. non-browser) password database, to the <a href="http://www.xs4all.nl/~jlpoutre/BoT/Javascript/PasswordComposer/" rel="nofollow"> PasswordComposer tool</a>. Results are inconclusive so far, because I have difficulty remembering which accounts I have migrated and which ones I haven&#8217;t&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Casey</title>
		<link>http://www.somethinkodd.com/oddthinking/2005/09/22/lets-fail-to-log-in-again-like-we-did-last-summer/comment-page-1/#comment-756</link>
		<dc:creator>Casey</dc:creator>
		<pubDate>Thu, 22 Sep 2005 15:29:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.somethinkodd.com/oddthinking/?p=90#comment-756</guid>
		<description>&lt;!-- UnMarkedDown_2_01132522670--&gt;&lt;p&gt;Opera is now free, and has an excellent solution to this problem. Opera calls it the &quot;Magic Wand&quot; or some such, basically the same as Password Manager or whatever. Forms with saved answers are shown with gold highlighting, which is very nice. When there are multiple saved passwords, and you use the Wand (Ctrl-Enter = magic!), it shows you all possible usernames (not passwords) and lets you choose which to use. They are listed in order of addition, and you can delete them from the same window. When this happens to me, I first check which (if any) of the saved passwords works, and then delete all the others so that the Wand is instantaneous again.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p><!-- UnMarkedDown_2_01132522670-->
<p>Opera is now free, and has an excellent solution to this problem. Opera calls it the &#8220;Magic Wand&#8221; or some such, basically the same as Password Manager or whatever. Forms with saved answers are shown with gold highlighting, which is very nice. When there are multiple saved passwords, and you use the Wand (Ctrl-Enter = magic!), it shows you all possible usernames (not passwords) and lets you choose which to use. They are listed in order of addition, and you can delete them from the same window. When this happens to me, I first check which (if any) of the saved passwords works, and then delete all the others so that the Wand is instantaneous again.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

