<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<title type="html"><![CDATA[FrontAccounting forum — Username login security?]]></title>
	<link rel="self" href="https://frontaccounting.com/punbb/extern.php?action=feed&amp;tid=9395&amp;type=atom" />
	<updated>2021-11-04T04:34:57Z</updated>
	<generator>PunBB</generator>
	<id>https://frontaccounting.com/punbb/viewtopic.php?id=9395</id>
		<entry>
			<title type="html"><![CDATA[Re: Username login security?]]></title>
			<link rel="alternate" href="https://frontaccounting.com/punbb/viewtopic.php?pid=40208#p40208" />
			<content type="html"><![CDATA[<p>VPN?<br />htaccesspwd?</p>]]></content>
			<author>
				<name><![CDATA[apmuthu]]></name>
				<uri>https://frontaccounting.com/punbb/profile.php?id=364</uri>
			</author>
			<updated>2021-11-04T04:34:57Z</updated>
			<id>https://frontaccounting.com/punbb/viewtopic.php?pid=40208#p40208</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Username login security?]]></title>
			<link rel="alternate" href="https://frontaccounting.com/punbb/viewtopic.php?pid=40147#p40147" />
			<content type="html"><![CDATA[<p>I&#039;m not sure what it is based on but it presents itself as a Remote Desktop login. Once authenticated to a desktop one browses to a local address:port and the FA login is presented.</p>]]></content>
			<author>
				<name><![CDATA[Technicavolous]]></name>
				<uri>https://frontaccounting.com/punbb/profile.php?id=44575</uri>
			</author>
			<updated>2021-10-25T00:43:32Z</updated>
			<id>https://frontaccounting.com/punbb/viewtopic.php?pid=40147#p40147</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Username login security?]]></title>
			<link rel="alternate" href="https://frontaccounting.com/punbb/viewtopic.php?pid=40132#p40132" />
			<content type="html"><![CDATA[<p>May I ask what software the front server is using and if it is chargeable.?</p>]]></content>
			<author>
				<name><![CDATA[rafat]]></name>
				<uri>https://frontaccounting.com/punbb/profile.php?id=41964</uri>
			</author>
			<updated>2021-10-22T12:12:01Z</updated>
			<id>https://frontaccounting.com/punbb/viewtopic.php?pid=40132#p40132</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Username login security?]]></title>
			<link rel="alternate" href="https://frontaccounting.com/punbb/viewtopic.php?pid=40131#p40131" />
			<content type="html"><![CDATA[<p>We ended up putting another server in front of the FA machine that meets their requirement, then log in to FA from there. Makes me log in twice but meets their demands ...</p>]]></content>
			<author>
				<name><![CDATA[Technicavolous]]></name>
				<uri>https://frontaccounting.com/punbb/profile.php?id=44575</uri>
			</author>
			<updated>2021-10-21T21:35:06Z</updated>
			<id>https://frontaccounting.com/punbb/viewtopic.php?pid=40131#p40131</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Username login security?]]></title>
			<link rel="alternate" href="https://frontaccounting.com/punbb/viewtopic.php?pid=40010#p40010" />
			<content type="html"><![CDATA[<p>Hire a FA&nbsp; developer and make him to create a module and connect the login with hooks as well as replace the user account page with a custom one which will have to ask those combinations in password. This way you can make this happen. </p><p>FA can provide support to many things. But it has to common needs for all users. Except you no one is active to seek this enhancement.</p><p>Or may be you can create and contribute it to FA development community , it&#039;s depends on your interest towards the contribution of the FA&nbsp; community.</p><p>Thank you</p>]]></content>
			<author>
				<name><![CDATA[kvvaradha]]></name>
				<uri>https://frontaccounting.com/punbb/profile.php?id=19348</uri>
			</author>
			<updated>2021-09-23T02:36:10Z</updated>
			<id>https://frontaccounting.com/punbb/viewtopic.php?pid=40010#p40010</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Username login security?]]></title>
			<link rel="alternate" href="https://frontaccounting.com/punbb/viewtopic.php?pid=40006#p40006" />
			<content type="html"><![CDATA[<p>BTW</p><p>The security co is requiring us to have usernames that are basically passwords - 12+ characters that must have a combination of upper and lower case letters, numbers and punctuation, no dictionary words, no repeating characters, etc ...</p><p>Also, they&#039;re suggesting spaces in passwords be acceptable as the trend is going to &#039;pass phrases&#039; vs passwords.</p>]]></content>
			<author>
				<name><![CDATA[Technicavolous]]></name>
				<uri>https://frontaccounting.com/punbb/profile.php?id=44575</uri>
			</author>
			<updated>2021-09-22T16:11:59Z</updated>
			<id>https://frontaccounting.com/punbb/viewtopic.php?pid=40006#p40006</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Username login security?]]></title>
			<link rel="alternate" href="https://frontaccounting.com/punbb/viewtopic.php?pid=40005#p40005" />
			<content type="html"><![CDATA[<p>Our parent company has given us until Dec 31 2021 to comply with their security guidelines. Account Security is a major part of their focus, and <em>we will not be allowed to use FA after that date if the login is not case sensitive.</em></p><p>This SUCKS. </p><p>I&#039;ve build into FA for many years and it&#039;s great for us. The learning curve of a financial package is extreme and we anticipate many difficulties during the transition.</p><p>PLEASE FIX THE LOGON SECURITY OF FRONTACCOUNTING SO WE CAN CONTINUE USING IT!<br />The security team states there are other vulnerabilities in FA but that they can be remedied by firewall magic. The login security is a show stopper.</p><p>Thanks for your serious and timely consideration.</p>]]></content>
			<author>
				<name><![CDATA[Technicavolous]]></name>
				<uri>https://frontaccounting.com/punbb/profile.php?id=44575</uri>
			</author>
			<updated>2021-09-22T16:07:11Z</updated>
			<id>https://frontaccounting.com/punbb/viewtopic.php?pid=40005#p40005</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Username login security?]]></title>
			<link rel="alternate" href="https://frontaccounting.com/punbb/viewtopic.php?pid=39745#p39745" />
			<content type="html"><![CDATA[<p>@joe , basically we have md5 encryption,&nbsp; which is ok for Password. But now a days. Securing our framework is more important.&nbsp; Than enhancing it. People are looking with two step authentications to prevent unknown tries.&nbsp; But I feel the username case sensitive is a good to have for customers.</p>]]></content>
			<author>
				<name><![CDATA[kvvaradha]]></name>
				<uri>https://frontaccounting.com/punbb/profile.php?id=19348</uri>
			</author>
			<updated>2021-07-23T07:19:10Z</updated>
			<id>https://frontaccounting.com/punbb/viewtopic.php?pid=39745#p39745</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Username login security?]]></title>
			<link rel="alternate" href="https://frontaccounting.com/punbb/viewtopic.php?pid=39740#p39740" />
			<content type="html"><![CDATA[<p>Thanks for the reply and consideration.</p><p>More and more user / pass is looking at user rules. I used admin as example, we had set up users with upper / lower case and characters and determined case was insensitive. It&#039;s nothing new -</p><p>https://passwordbits.com/usernames-need-unique/</p><p>just for your consideration ...</p><p>Thanks!!</p>]]></content>
			<author>
				<name><![CDATA[Technicavolous]]></name>
				<uri>https://frontaccounting.com/punbb/profile.php?id=44575</uri>
			</author>
			<updated>2021-07-21T16:28:19Z</updated>
			<id>https://frontaccounting.com/punbb/viewtopic.php?pid=39740#p39740</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Username login security?]]></title>
			<link rel="alternate" href="https://frontaccounting.com/punbb/viewtopic.php?pid=39739#p39739" />
			<content type="html"><![CDATA[<p>@joe<br />I like the Fort Knox analogy... <img src="https://frontaccounting.com/punbb/img/smilies/smile.png" width="15" height="15" alt="smile" /> <img src="https://frontaccounting.com/punbb/img/smilies/big_smile.png" width="15" height="15" alt="big_smile" /><br />I still agree that we need a stronger userid. Most of the sites I visit now have userid rules (not passwords only). This admin is very trivial... of course users need to change it anyway..</p>]]></content>
			<author>
				<name><![CDATA[rafat]]></name>
				<uri>https://frontaccounting.com/punbb/profile.php?id=41964</uri>
			</author>
			<updated>2021-07-21T15:50:11Z</updated>
			<id>https://frontaccounting.com/punbb/viewtopic.php?pid=39739#p39739</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Username login security?]]></title>
			<link rel="alternate" href="https://frontaccounting.com/punbb/viewtopic.php?pid=39738#p39738" />
			<content type="html"><![CDATA[<p>I am not so sure about this. It is very common to let the username be case insensitive.<br />It is more important that the password is strong. And, really, this is not a Fort Knox issue. </p><p>Joe</p>]]></content>
			<author>
				<name><![CDATA[joe]]></name>
				<uri>https://frontaccounting.com/punbb/profile.php?id=3</uri>
			</author>
			<updated>2021-07-21T15:37:52Z</updated>
			<id>https://frontaccounting.com/punbb/viewtopic.php?pid=39738#p39738</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Username login security?]]></title>
			<link rel="alternate" href="https://frontaccounting.com/punbb/viewtopic.php?pid=39737#p39737" />
			<content type="html"><![CDATA[<p>I agree..</p>]]></content>
			<author>
				<name><![CDATA[rafat]]></name>
				<uri>https://frontaccounting.com/punbb/profile.php?id=41964</uri>
			</author>
			<updated>2021-07-21T14:55:30Z</updated>
			<id>https://frontaccounting.com/punbb/viewtopic.php?pid=39737#p39737</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Username login security?]]></title>
			<link rel="alternate" href="https://frontaccounting.com/punbb/viewtopic.php?pid=39736#p39736" />
			<content type="html"><![CDATA[<p>Can we have upper / lower case enforcement on the username for the login screen?</p><p>Right now to login any combination of upper or lower case letters logs in successfully</p><p>Admin <br />is the same as <br />admin<br />or<br />aDmin<br />or admiN</p><p>all work.</p><p>Username is half the login key, should have same check as passwords ...</p><p>Thanks!!</p>]]></content>
			<author>
				<name><![CDATA[Technicavolous]]></name>
				<uri>https://frontaccounting.com/punbb/profile.php?id=44575</uri>
			</author>
			<updated>2021-07-21T13:30:57Z</updated>
			<id>https://frontaccounting.com/punbb/viewtopic.php?pid=39736#p39736</id>
		</entry>
</feed>
