composr installer wierd warning messages
Posted
#6473
(In Topic #1434)
Are you sure you want such an insecure Master password password? This will leave your installation and webhosting wide open to attack. You should use at least 8 characters and a combination of lower case, upper case, digits, and punctuation symbols.
after clicking OK, I get this further message:
REALLY? Are you sure you want such an insecure Master password password? This will leave your installation and webhosting wide open to attack. You should use at least 8 characters and a combination of lower case, upper case, digits, and punctuation symbols.
I am stunned because I used the generated password the installer suggested, which by the way was the same one as it suggested for the Administration password! What?
I never got these messages on my previous install of another website - that one went through all the steps without a hitch.
Posted
Actually Composr doesn't recommend any passwords at all. My guess is this is the browser doing form autofill from some past password.
The concern is bots automatically hammering against the master password. As things like the config editor, code editor, and upgrader, are simple scripts, there's really no kind of special flood protection, and the presence of bots online means nobody may even intend to be trying to hack you specifically but you could still be a target.
Further, there are corporate security standards we meet that say we do need to apply certain standards.
0 guests and 0 members have recently viewed this.
