journal
all ![]() | Rob is 20,118 days old today. |
Aug 2009 01 02 03 04 05 06 07 08 09 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31
Oct 2009 01 02 03 04 05 06 07 08 09 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 2008 jan feb mar apr may jun jul aug sep oct nov dec
2010 jan feb mar apr may jun jul aug sep oct nov dec |< << more >> >| |
Entries this day: AM_sleepy Green,_University_of_the Shigoto emiko,_lesson_with AM sleepy 9:35am JST Friday 4 September 2009 (day 14408) While on Shonan Liner, I just wrote about last night, and now on Yamanote, writing about this morning, during which I flopped around in bed until 8am instead of getting up at 6am to rock hop. When the 6:45 alarm to come home after the beach went off, I was holding the phone in my hand and it beeped weirdly and I woke up to see it had called Soness upstairs! I heard her in the loo; I had apparently woken her up, and got up to say "oops sorry" as she asked in the kitchen on her way back upstairs, "did you call me??" Both back to our respective beds and I didn't even get up at 7:45 for the reminder to take out the trash. Snoozed that alarm a couple times until 8 and finally was like "oh yeah I gotta eat" Oh wait; I think it was around 7am that I sat up to do my morning meditation practice for 15 minutes, and then conked back asleep. Anyway, I didn't do much but sleep, meditate, eat, dress, leave, come back, grab the trash, leave again. Sorta had to negotiate how to get ready again; my clean shirts and socks were upstairs, so I quietly got them without waking up Soness and then where to put my shorts and where to put on my pants... Man, having people in the house is tricky! permalinkGreen, University of the HI Thank you for supporting the greening of our earth! I'd like to make three suggestions to your system if I may. First, the return address of the email I received below is from admin@universitygreen.com On quick glance, that does *not* appear to be a domain you guys own. Second, if I'm logged in, I still see the "Enroll" tab as the first on the left. Seems to me that I shouldn't be able to enroll if I'm already enrolled (and logged in). Third, I recommend you do *not* store passwords in plaintext. No modern website should store passwords in plaintext. Don't send passwords to users over email. If users forgot their password, send to their email address a link that allows choosing a new password. You should store the passwords with MD5 encryption and compare the MD5 of their entered password with the one stored in your DB. Also, it's not because you emailed my password that I know you store it in plain text. It's because your system only allows 10 characters for a password! Ten? Ten? Come on. I use http://supergenpass.com for my passwords, and my master password is longer than ten characters. You should allow *any* length of password (truncate it at 100 chars if you're afraid of injection attacks), then store a 32 byte MD5 of their password. Change it now before you get a ton of users. Peace - Rob ---------- Forwarded message ---------- From: <admin@universitygreen.com> blah blah blah Your password is: __________ blah blah blah permalink |