Icon test

Sep. 7th, 2010 10:28 pm
nancylebov: (green leaves)
[personal profile] nancylebov
Checking to see whether my icon goes through. If it does, real posts will follow.

Date: 2010-09-08 11:01 am (UTC)
madfilkentist: Carl in Window (CarlWindow)
From: [personal profile] madfilkentist
Just by the way, how did you set up crossposting?

According to this page, Dreamwidth wants your LJ password. Soliciting passwords used on competing sites is vastly worse than even LJ's crossposting of comments on locked posts.

I get the impression from this discussion that there's some way to crosspost using OpenID, which doesn't require giving away any passwords (though it strikes me as very prone to user error and spoofing). Is that what you're using?

Date: 2010-09-08 01:29 pm (UTC)
From: [identity profile] nancylebov.livejournal.com
I let them have my lj password as part of importing my lj journal. I don't know whether that was excessively trusting.

I'm not the best person to ask about the details of DW.

Date: 2010-09-08 02:36 pm (UTC)
madfilkentist: Carl in Window (CarlWindow)
From: [personal profile] madfilkentist
That's the problem; you can't know what they'll do with your password, in this case or in general. There's never a good reason to give a third-party password to a website. Look up "Quechup" for the kind of things they can do with them.

Date: 2010-09-08 04:04 pm (UTC)
From: [identity profile] beautyofgrey.livejournal.com
Random stranger here, but they do not store your password. You must re-enter it everytime you crosspost.

They realized this was an issue early on and worked around it: http://dw-news.dreamwidth.org/7298.html

It was resolved here: http://dw-news.dreamwidth.org/16019.html
Edited Date: 2010-09-08 04:04 pm (UTC)

Date: 2010-09-09 11:52 am (UTC)
From: [identity profile] nancylebov.livejournal.com
They store a hashed version of the password-- I'm not sure if that means they can't recover it, but at least it means they're less likely to lose it by accident.

If I don't think I can trust someone with a password, I'm not going to trust their assurances that that they won't keep it.

Date: 2010-09-09 01:57 pm (UTC)
From: [identity profile] beautyofgrey.livejournal.com
Honestly, I'm more likely to trust Dreamwidth with my password than Livejournal, but that's a personal preference based on my experiences with both communities and how the operators interact with the users.

Date: 2010-09-09 04:51 pm (UTC)
From: [identity profile] beautyofgrey.livejournal.com
A developer answers the question here: http://dw-news.dreamwidth.org/24656.html?thread=2859088#cmt2859088

"If you select the 'save password' option, then DW saves an encrypted version of the password. Now, because of the way LJ passwords work, that encrypted password is sufficient to get full access to your account. But it does mean that if, say, you use that same password for other things, then nobody would be able to get from the encrypted version to the plaintext password.

You can also choose not to save your password, in which case you'll be asked for your LJ password every time you crosspost. In that case, all the DW servers ever get is a one-time authentication token."

May 2025

S M T W T F S
    123
45678910
11 121314151617
18192021222324
25262728293031

Most Popular Tags

Page Summary

Style Credit

Expand Cut Tags

No cut tags
Page generated Aug. 1st, 2025 08:57 am
Powered by Dreamwidth Studios