Thursday, 2011-09-08

*** Lake_Lurker (~Just@h200.9.30.71.dynamic.ip.windstream.net) has joined #wikid11:55
*** Lake_Lurker has parted #wikid (None)11:55
*** perestrelka has quit (*.net *.split)13:09
*** perestrelka (~vladdy@194.242.5.47) has joined #wikid13:09
*** nowen (~nowen@adsl-74-176-212-133.asm.bellsouth.net) has joined #wikid14:05
*** CowboyPride (~BartSimps@cpe-075-183-170-059.sc.res.rr.com) has joined #wikid15:10
*** CowboyPride_ has quit (*.net *.split)15:18
*** CowboyPride has quit (Excess Flood)15:21
*** CowboyPride (~BartSimps@cpe-075-183-170-059.sc.res.rr.com) has joined #wikid15:21
*** CowboyPride has quit (Read error: Connection reset by peer)15:26
*** KDelande_Firstso (410584de@gateway/web/freenode/ip.65.5.132.222) has joined #wikid18:42
KDelande_FirstsoNick, quick question -- do you have any intention of supporting email delivery as a method for the OTP?18:42
nowenKDelande_Firstso: we're not sure how to do that securely18:43
nowenis this about your users that can't install a token?18:43
KDelande_Firstsoyes18:44
KDelande_Firstsowe're trying to explore all options18:45
nowenhow many users do you estimate fall into this category?18:45
KDelande_FirstsoHard to say, we have hundreds of total onsites but it's not until we reach out  to them do we fully understand what are options are due to poor prior record keeping18:45
nowenhmm18:46
nowenare smart phone tokens an option?18:46
KDelande_Firstsonot ideal, many don't have cell phones18:46
KDelande_Firstsoor at least not company cell phones18:46
KDelande_Firstsowe're looking at doing something via SMS as well, which is what brough up the possibility for just straight email18:47
KDelande_Firstsowhich is likely to be more accessible then a cell phone18:47
nowenIt is also difficult to secure SMS, perhaps harder.  no guarantee of encryption18:47
KDelande_Firstsounderstood18:48
nowendid something go wrong with the html5 token?18:48
nowenI don't think it would be too hard to add an sms token, but that would mean that they would have to have a cell phone18:49
KDelande_Firstsonot per se but we're skeptical that the sites in question will allow retention of cache/cookies to allow the token setup to remain persistent day to day18:49
nowenwhat about a USB drive?18:50
KDelande_FirstsoRight, the cell phone is an issue which is again why we're tryin g to check any email options as opposed to cell18:50
KDelande_FirstsoUSB sticks are usually highly restricted at hopspitals18:50
nowenI suppose we could add that too.18:50
KDelande_Firstsoer, hospitals18:50
KDelande_Firstsodata theft, etc.18:50
nowensure18:50
KDelande_Firstsowhat's the process for adding something like a feature request?18:51
nowenI can handle it, but I ask that  you be sure it will do the trick18:52
nowenand that it will meet your security requirements18:53
nowenwhat if we could somehow handle the html5 cache issue?18:55
nowenKDelande_Firstso: are you using the email address as the userid?19:04
nowenKDelande_Firstso: we might also be able to do a 'server-side' token of some kind19:34
KDelande_Firstsosorry Nick, i had a meeting pop up and coudnt respond19:45
nowennp19:45
KDelande_Firstsowe're using ad account for user name and it currently works as a legacy email as well19:46
KDelande_Firstsoso, effectively yes19:46
KDelande_FirstsoI understand about the whole "make sure it does the trick" issue before committing to the changes, I'll talk to my folks and assess that19:46
nowenok19:47
KDelande_Firstsobut if we felt adding email was a go, how long do you think that would take, so we could plan our deployment.  Best guess19:47
nowenI think the 'server-side' token thing could be interesting19:47
nowenprobably like two weeks plus some beta time.  probably less for the server-side token idea19:50
KDelande_Firstsook, thanks20:29
*** KDelande_Firstso has quit (Quit: Page closed)21:28

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!