in reply to Re: Requiring old password in order to change your password
in thread Requiring old password in order to change your password

Only for when logging in, yes.

- tye        

  • Comment on Re^2: Requiring old password in order to change your password (https)

Replies are listed 'Best First'.
Re^3: Requiring old password in order to change your password (https)
by andreas1234567 (Vicar) on Jan 03, 2011 at 15:03 UTC
    Thanks, that's one step in the right direction. Additionally, it would be great to consider (optionally) allowing https for all communications (not just logins) in your on-going security review of the site. Some claim SSL/TLS is not computationally expensive any more but that is of course subject to debate.

    Https everywhere is getting a lot of traction and the number of sites that supports https "all the way" is large and growing. It would be great to add perlmonks.org to the list:

    $ ls https-everywhere/src/chrome/content/rules/*.xml | wc -l 426
    --
    No matter how great and destructive your problems may seem now, remember, you've probably only seen the tip of them. [1]

      Yes, allowing https always is on the list after web server performance mitigation is sustained.

      - tye        

      Count me in. I strongly support the widespread use of https.