*** Lake_Lurker (~Just@h200.9.30.71.dynamic.ip.windstream.net) has joined #wikid | 11:55 | |
*** Lake_Lurker has parted #wikid (None) | 11:55 | |
*** perestrelka has quit (*.net *.split) | 13:09 | |
*** perestrelka (~vladdy@194.242.5.47) has joined #wikid | 13:09 | |
*** nowen (~nowen@adsl-74-176-212-133.asm.bellsouth.net) has joined #wikid | 14:05 | |
*** CowboyPride (~BartSimps@cpe-075-183-170-059.sc.res.rr.com) has joined #wikid | 15:10 | |
*** CowboyPride_ has quit (*.net *.split) | 15:18 | |
*** CowboyPride has quit (Excess Flood) | 15:21 | |
*** CowboyPride (~BartSimps@cpe-075-183-170-059.sc.res.rr.com) has joined #wikid | 15:21 | |
*** CowboyPride has quit (Read error: Connection reset by peer) | 15:26 | |
*** KDelande_Firstso (410584de@gateway/web/freenode/ip.65.5.132.222) has joined #wikid | 18:42 | |
KDelande_Firstso | Nick, quick question -- do you have any intention of supporting email delivery as a method for the OTP? | 18:42 |
---|---|---|
nowen | KDelande_Firstso: we're not sure how to do that securely | 18:43 |
nowen | is this about your users that can't install a token? | 18:43 |
KDelande_Firstso | yes | 18:44 |
KDelande_Firstso | we're trying to explore all options | 18:45 |
nowen | how many users do you estimate fall into this category? | 18:45 |
KDelande_Firstso | Hard to say, we have hundreds of total onsites but it's not until we reach out to them do we fully understand what are options are due to poor prior record keeping | 18:45 |
nowen | hmm | 18:46 |
nowen | are smart phone tokens an option? | 18:46 |
KDelande_Firstso | not ideal, many don't have cell phones | 18:46 |
KDelande_Firstso | or at least not company cell phones | 18:46 |
KDelande_Firstso | we're looking at doing something via SMS as well, which is what brough up the possibility for just straight email | 18:47 |
KDelande_Firstso | which is likely to be more accessible then a cell phone | 18:47 |
nowen | It is also difficult to secure SMS, perhaps harder. no guarantee of encryption | 18:47 |
KDelande_Firstso | understood | 18:48 |
nowen | did something go wrong with the html5 token? | 18:48 |
nowen | I don't think it would be too hard to add an sms token, but that would mean that they would have to have a cell phone | 18:49 |
KDelande_Firstso | not per se but we're skeptical that the sites in question will allow retention of cache/cookies to allow the token setup to remain persistent day to day | 18:49 |
nowen | what about a USB drive? | 18:50 |
KDelande_Firstso | Right, the cell phone is an issue which is again why we're tryin g to check any email options as opposed to cell | 18:50 |
KDelande_Firstso | USB sticks are usually highly restricted at hopspitals | 18:50 |
nowen | I suppose we could add that too. | 18:50 |
KDelande_Firstso | er, hospitals | 18:50 |
KDelande_Firstso | data theft, etc. | 18:50 |
nowen | sure | 18:50 |
KDelande_Firstso | what's the process for adding something like a feature request? | 18:51 |
nowen | I can handle it, but I ask that you be sure it will do the trick | 18:52 |
nowen | and that it will meet your security requirements | 18:53 |
nowen | what if we could somehow handle the html5 cache issue? | 18:55 |
nowen | KDelande_Firstso: are you using the email address as the userid? | 19:04 |
nowen | KDelande_Firstso: we might also be able to do a 'server-side' token of some kind | 19:34 |
KDelande_Firstso | sorry Nick, i had a meeting pop up and coudnt respond | 19:45 |
nowen | np | 19:45 |
KDelande_Firstso | we're using ad account for user name and it currently works as a legacy email as well | 19:46 |
KDelande_Firstso | so, effectively yes | 19:46 |
KDelande_Firstso | I understand about the whole "make sure it does the trick" issue before committing to the changes, I'll talk to my folks and assess that | 19:46 |
nowen | ok | 19:47 |
KDelande_Firstso | but if we felt adding email was a go, how long do you think that would take, so we could plan our deployment. Best guess | 19:47 |
nowen | I think the 'server-side' token thing could be interesting | 19:47 |
nowen | probably like two weeks plus some beta time. probably less for the server-side token idea | 19:50 |
KDelande_Firstso | ok, thanks | 20:29 |
*** KDelande_Firstso has quit (Quit: Page closed) | 21:28 |
Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!