Winhost blog

Open sesame

We have a lot of discussions and meetings about security. Not only back-end network security, but security of the customer interface, and security policies as far as communicating with customers.

If you have ever locked yourself out of an online account because you forgot a username or password, you know what a frustrating experience it can be to try to get that access back. At Winhost we have a system in place that is email and temporary password based, so you can usually regain access to your account without even contacting us. In the event that fails, you can always contact the billing department and provide the answer to your security question to regain access.

We are working on extending the authentication system even further to include a second security question. The meeting about that was interesting because there were as many different opinions on security as there were people in the room, and a common question becomes how much security is too much?

And like everyone in that meeting, every one of our customers also has a different idea of “perfect” security. The thing is, you cannot design and build a system that accommodates everyone’s idea of perfect security. It would have so many barriers to entry that it would be unusable. So we have to design systems that meet most people’s needs. Which means some people will find flaws with it…

“Why don’t you require a password change every thirty days for Control Panel?”

“Why can’t I enter a 255 character password?”

“Send me my login information, but do NOT send my username via email!”

“Can I register my retina scan with you, and then you don’t allow access to my account unless it is accompanied by a live retina scan that matches the retina scan that you have registered? Oh, and I’ll register a new retina scan with you every seven days. Please? Why not?!”

Okay, I made the last one up. But we’ve heard all the others. Some more than once.

We take security very seriously, but there is a line somewhere between ultra-strict security and usability, and we have to straddle that line to provide a usable service to a large number of people. That isn’t to say our security isn’t strict – I won’t bore you with our multitude of internal security policies regarding customer data and information – but we hope we provide a secure, yet user-friendly, experience.

And whatever you do, don’t make your account password, “password.” Okay? Really, just don’t do it.


Exit mobile version