26 August 2008

Issuing Web Site User Names Safely

I am often asked how to select and then send out web site login user names. If you have a relatively small number of users and they don't change often, don't get complicated - just send them in the post.

User names identify an individual during authentication processes like logging on. Self-registration systems can often be used to help guess current ones.

But if you have a known set of users such as customers, members or clients, select the user names yourself, don't use the internet (such as email) to communicate these to the users. Transfer them some other way ("out-of-band" is security jargon), perhaps using conventional post, signed for on receipt, to an address you already have on record, by hand (perhaps at an event or conference) or possibly by telephone or fax.

It's also better to disable user accounts which are not used within a reasonable period of the communication being sent as this may indicate the address was incorrect.

Posted on: 26 August 2008 at 09:49 hrs

Comments Comments (0) | Permalink | Send Send | Post to Twitter

Comments

Comments are filtered automatically and should appear shortly after they been checked.

Post a comment
Confirm acceptance and understanding of the terms of use
New posts to this thread will be sent to your email address
Issuing Web Site User Names Safely
http://www.clerkendweller.com/2008/8/26/Issuing-Web-Site-Usernames-Safely
ISO/IEC 18004:2006 QR code for http://clerkendweller.com

Page http://www.clerkendweller.com/2008/8/26/Issuing-Web-Site-Usernames-Safely
Requested by 38.107.179.222 on Tuesday, 7 February 2012 at 21:21 hrs (London date/time)

Please read our terms of use and obtain professional advice before undertaking any actions based on the opinions, suggestions and generic guidance presented here. Your organisation's situation will be unique and all practices and controls need to be assessed with consideration of your own business context.

Terms of use http://www.clerkendweller.com/page/terms
Privacy statement http://www.clerkendweller.com/page/privacy
© 2008-2012 clerkendweller.com