Author Message
mario
PostPosted: Mon Feb 03, 2020 5:34 am    Post subject:

I found the problem, thank you. It had nothing to do with the interface switch, something else happened.
microshnik
PostPosted: Sun Feb 02, 2020 2:57 pm    Post subject: Update!

The weak password warning is now gone even with my snipe list being empty. Methinks it had something to do with the interface switch, which, by the way, I only saw by happenstance when I wondered if Mario had responded to any other posts lately. Was there going to be an announcement of that??
microshnik
PostPosted: Sat Feb 01, 2020 9:28 pm    Post subject:

mario wrote:
Can you please email me and include your Gixen username? I need to see this for myself, I don't see why you should be getting the weak password warning.


Done. Thanks for looking into it!
mario
PostPosted: Sat Feb 01, 2020 7:58 am    Post subject:

Can you please email me and include your Gixen username? I need to see this for myself, I don't see why you should be getting the weak password warning.
Cupid
PostPosted: Sat Feb 01, 2020 4:11 am    Post subject:

The reason that warning only appears when you have no snipes is historic.

It goes back to when Gixen used your Ebay account credentials as your login credentials here too. So at that time the password on the snipes had to match both your eBay and Gixen login... so changing it on Ebay would invalidate all the snipes already set, which was not the aim of the message... therefore it was only displayed at a time when changing it would not also result in those adverse consequences, ie when there are no snipes set.

It may be the case that it still has to stay that way now because changing your Gixen password is still going to cause you to loose access to those existing snipes, that is if the Gixen password is used as part of the primary key in looking up the snipes as it used to be the case with the old authorisation system... I do not know that is the case though I just suspect it still might be... Only Mario can confirm on deny this.
microshnik
PostPosted: Fri Jan 31, 2020 11:37 pm    Post subject: New info: strange correlation

The message first appeared when I cleared out my ended items and had no items remaining. When I imported items from my Watch List just now the message went away -- even without any snipes actually set -- and it reappeared when I deleted them all again. I have no idea why the password warning would be triggered by a lack of items, but that's the case for me at least.
microshnik
PostPosted: Fri Jan 31, 2020 6:19 pm    Post subject: Re: Algo definitely needs looking at...

ABullWithYogurts wrote:
Logged into Gixen today to be presented with "Your password may not be strong enough. If you believe Gixen is misjudging the strength of your password, you can turn off this warning on your settings page."

I use a passwords with 50 random chars and ints. The entropy is huge.

Can you have a look at the algo please.


My password isn't quite that strong, but I'm also suddenly getting that message. What changed?
ABullWithYogurts
PostPosted: Thu Jan 30, 2020 1:25 am    Post subject: Algo definitely needs looking at...

Logged into Gixen today to be presented with "Your password may not be strong enough. If you believe Gixen is misjudging the strength of your password, you can turn off this warning on your settings page."

I use a passwords with 50 random chars and ints. The entropy is huge.

Can you have a look at the algo please.
mario
PostPosted: Mon Jan 27, 2020 8:42 am    Post subject: Re: Password strength

bizzox14 wrote:
It seems odd that you allow only letters and numbers when one of the key components of password strength is the use of non alaphanumeric characters. Without those my Gixen password will always be weaker than optimum!


This is just not so. Non-alphanumerics allow you to have a (somewhat) shorter password of equal strength, but passwords made of alphanumerics only are not weaker per se. Is this a weak password: "fz32M43R8YXew69Hg3PRWg5d"? I don't think so. So it's just a matter of length.

Could I add non-alphanumerics? Sure, but between many interfaces, scripting languages and necessary encodings used by Gixen that significantly complicates things, a complication I would rather avoid and invest my time in other things.
bizzox14
PostPosted: Mon Jan 27, 2020 8:27 am    Post subject: Password strength

Hi,

I'm frustrated about password strength. Having got a warning about possible weakness I tried to strengthen but it rejected my strengthening due to non alphanumeric characters. Am I alone in thinking there is an anomoly in the password strength functionality? It seems odd that you allow only letters and numbers when one of the key components of password strength is the use of non alaphanumeric characters. Without those my Gixen password will always be weaker than optimum! To cap it all when I randomised a little to improve the password I was still being warned about on log in, so iturned the option off.

Let me know if you tweak this and I'll restrengthen and turn it back on.
Rickajho
PostPosted: Sun Jan 26, 2020 4:31 pm    Post subject:

Hi. When do you get this warning? When you log in to your eBay account? Or when you log in here at gixen?

Rick
gunrunnerjohn
PostPosted: Sun Jan 26, 2020 6:34 am    Post subject: Your password may not be strong enough??

Why do I get this warning? I have a 12 character randomly generated password with numbers and letters, it's hardly "not strong enough". I think maybe the algorithm that checks the strength of the passwords may need a little "tweaking".

Powered by phpBB © 2001, 2005 phpBB Group