Uploaded image for project: 'OFBiz'
  1. OFBiz
  2. OFBIZ-11244

Remove the user login security question

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Closed
    • Major
    • Resolution: Implemented
    • Trunk
    • 22.01.01
    • ecommerce, framework, party
    • None

    Description

      After our discussion in dev ML at https://markmail.org/message/2dhc4al4adwgvl7z we will remove this feature. This paulfoxworthy's remark is notably important:

      Security is only as good as its weakest link ( https://s.apache.org/xp8da) , and security questions can be a real weakness. Any organisation using OFBiz that really hates passwords could look at security keys from Yubico or the like.

      Attachments

        1. OFBIZ-11244-plugins.patch
          4 kB
          Wiebke Paetzold
        2. OFBIZ-11244-framework-correction.patch
          0.9 kB
          Wiebke Paetzold
        3. OFBIZ-11244-framework.patch
          34 kB
          Wiebke Paetzold

        Activity

          People

            mbrohl Michael Brohl
            jleroux Jacques Le Roux
            Votes:
            0 Vote for this issue
            Watchers:
            5 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: