<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Get your error messages right, people.</title>
	<atom:link href="http://blog.sugarenia.com/archives/rantings/get-your-error-messages-right-people/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.sugarenia.com/archives/rantings/get-your-error-messages-right-people</link>
	<description>As Sweet As Bitter</description>
	<pubDate>Sat, 22 Nov 2008 08:59:40 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.3</generator>
		<item>
		<title>By: Sugar</title>
		<link>http://blog.sugarenia.com/archives/rantings/get-your-error-messages-right-people#comment-22936</link>
		<dc:creator>Sugar</dc:creator>
		<pubDate>Wed, 03 Jan 2007 08:20:52 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sugarenia.com/archives/rantings/get-your-error-messages-right-people#comment-22936</guid>
		<description>@ stelabouras: 

Happy new year, you! :)

I'll increase the font in comments when I return home tonight.
The whole site will be redesigned in some days, anyway. :)</description>
		<content:encoded><![CDATA[<p>@ stelabouras: </p>
<p>Happy new year, you! <img src='http://blog.sugarenia.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>I&#8217;ll increase the font in comments when I return home tonight.<br />
The whole site will be redesigned in some days, anyway. <img src='http://blog.sugarenia.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: stelabouras</title>
		<link>http://blog.sugarenia.com/archives/rantings/get-your-error-messages-right-people#comment-22441</link>
		<dc:creator>stelabouras</dc:creator>
		<pubDate>Wed, 03 Jan 2007 01:10:30 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sugarenia.com/archives/rantings/get-your-error-messages-right-people#comment-22441</guid>
		<description>Happy New Year Sugar!

Maybe Cocomment isn't the service anyone wants to hack, but I would rather agree with John by saying that it is done for safety reasons ;)
Also the Cocomment programmers maybe used a kind of framework to build their web app so the whole login procedure is handled from it (although I believe they have double checked all the messages).
Anyways there are a lot of web services that return same error messages so what's the big deal :P

Tip: I have a hard time reading the comments due to the small font...Can it be increased? Plz? :P</description>
		<content:encoded><![CDATA[<p>Happy New Year Sugar!</p>
<p>Maybe Cocomment isn&#8217;t the service anyone wants to hack, but I would rather agree with John by saying that it is done for safety reasons <img src='http://blog.sugarenia.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /><br />
Also the Cocomment programmers maybe used a kind of framework to build their web app so the whole login procedure is handled from it (although I believe they have double checked all the messages).<br />
Anyways there are a lot of web services that return same error messages so what&#8217;s the big deal <img src='http://blog.sugarenia.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
<p>Tip: I have a hard time reading the comments due to the small font&#8230;Can it be increased? Plz? <img src='http://blog.sugarenia.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sugar</title>
		<link>http://blog.sugarenia.com/archives/rantings/get-your-error-messages-right-people#comment-22431</link>
		<dc:creator>Sugar</dc:creator>
		<pubDate>Tue, 02 Jan 2007 17:15:46 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sugarenia.com/archives/rantings/get-your-error-messages-right-people#comment-22431</guid>
		<description>Sigh... fine. You've proved me wrong and this kind of messages is OK, eventually.

But it still poses some usability issues for the real users of this dang login form. 

:P</description>
		<content:encoded><![CDATA[<p>Sigh&#8230; fine. You&#8217;ve proved me wrong and this kind of messages is OK, eventually.</p>
<p>But it still poses some usability issues for the real users of this dang login form. </p>
<p> <img src='http://blog.sugarenia.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Titanas</title>
		<link>http://blog.sugarenia.com/archives/rantings/get-your-error-messages-right-people#comment-22429</link>
		<dc:creator>Titanas</dc:creator>
		<pubDate>Tue, 02 Jan 2007 16:19:31 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sugarenia.com/archives/rantings/get-your-error-messages-right-people#comment-22429</guid>
		<description>I misunderstood you and i apologize for that!

I don't think they want to confuse hackers but instead make their lives less easy. The error message doesn't tell the whole truth.

Check this error message from (mt):

It appears that either your domain, email address, or password is incorrect. Please try logging in again, or consider using the Lost Password Recovery Page. If you still have problems, please contact the customer support department at 877-578-4000.

TIP: Your domain should not include the "http://" prefix nor should it include the "www" prefix.</description>
		<content:encoded><![CDATA[<p>I misunderstood you and i apologize for that!</p>
<p>I don&#8217;t think they want to confuse hackers but instead make their lives less easy. The error message doesn&#8217;t tell the whole truth.</p>
<p>Check this error message from (mt):</p>
<p>It appears that either your domain, email address, or password is incorrect. Please try logging in again, or consider using the Lost Password Recovery Page. If you still have problems, please contact the customer support department at 877-578-4000.</p>
<p>TIP: Your domain should not include the &#8220;http://&#8221; prefix nor should it include the &#8220;www&#8221; prefix.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sugar</title>
		<link>http://blog.sugarenia.com/archives/rantings/get-your-error-messages-right-people#comment-22423</link>
		<dc:creator>Sugar</dc:creator>
		<pubDate>Tue, 02 Jan 2007 14:35:30 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sugarenia.com/archives/rantings/get-your-error-messages-right-people#comment-22423</guid>
		<description>Please Titanas, don't distort my sayings.

I didn't mention that coComment is a nuisance. I just say that, in usability terms and in my humble opinion, their login system has a flaw in error messages.

I really can't believe that the obvious solution for web application developers is to provide an ambiguous error message to "confuse" potential hackers. 

Let's be realistic here.</description>
		<content:encoded><![CDATA[<p>Please Titanas, don&#8217;t distort my sayings.</p>
<p>I didn&#8217;t mention that coComment is a nuisance. I just say that, in usability terms and in my humble opinion, their login system has a flaw in error messages.</p>
<p>I really can&#8217;t believe that the obvious solution for web application developers is to provide an ambiguous error message to &#8220;confuse&#8221; potential hackers. </p>
<p>Let&#8217;s be realistic here.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Titanas</title>
		<link>http://blog.sugarenia.com/archives/rantings/get-your-error-messages-right-people#comment-22417</link>
		<dc:creator>Titanas</dc:creator>
		<pubDate>Tue, 02 Jan 2007 12:01:11 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sugarenia.com/archives/rantings/get-your-error-messages-right-people#comment-22417</guid>
		<description>@Sugar: coComment is a nuisance for you, Gmail is a nuisance for someone else, phpBB is a nuisance for me etc.

Developers are called to protect their service and what Tsevdos John says is right.</description>
		<content:encoded><![CDATA[<p>@Sugar: coComment is a nuisance for you, Gmail is a nuisance for someone else, phpBB is a nuisance for me etc.</p>
<p>Developers are called to protect their service and what Tsevdos John says is right.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sugar</title>
		<link>http://blog.sugarenia.com/archives/rantings/get-your-error-messages-right-people#comment-22399</link>
		<dc:creator>Sugar</dc:creator>
		<pubDate>Mon, 01 Jan 2007 21:17:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sugarenia.com/archives/rantings/get-your-error-messages-right-people#comment-22399</guid>
		<description>Aren't there any &lt;em&gt;other&lt;/em&gt; safety locks about this? Like, set the account pending when someone tries more than 5 times to login unsuccessfully?

And to be frank, who's gonna hack into my coComment account, really!

I could understand (maybe) if this was coming from an e-shop, or anything that needs to be more secure than conventional sites. But in this case, it's just a nuisance.</description>
		<content:encoded><![CDATA[<p>Aren&#8217;t there any <em>other</em> safety locks about this? Like, set the account pending when someone tries more than 5 times to login unsuccessfully?</p>
<p>And to be frank, who&#8217;s gonna hack into my coComment account, really!</p>
<p>I could understand (maybe) if this was coming from an e-shop, or anything that needs to be more secure than conventional sites. But in this case, it&#8217;s just a nuisance.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tsevdos John</title>
		<link>http://blog.sugarenia.com/archives/rantings/get-your-error-messages-right-people#comment-22354</link>
		<dc:creator>Tsevdos John</dc:creator>
		<pubDate>Sun, 31 Dec 2006 17:00:21 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sugarenia.com/archives/rantings/get-your-error-messages-right-people#comment-22354</guid>
		<description>Well Sugar it has to do with safety procedures. If a login system reveal which of the username or password is wrong (which simply means that the other is right), it is very easy for a hacker to find out more information about the specific account... That's why all the login systems never generated the two above error messages you suggesting...</description>
		<content:encoded><![CDATA[<p>Well Sugar it has to do with safety procedures. If a login system reveal which of the username or password is wrong (which simply means that the other is right), it is very easy for a hacker to find out more information about the specific account&#8230; That&#8217;s why all the login systems never generated the two above error messages you suggesting&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Titanas</title>
		<link>http://blog.sugarenia.com/archives/rantings/get-your-error-messages-right-people#comment-22342</link>
		<dc:creator>Titanas</dc:creator>
		<pubDate>Sun, 31 Dec 2006 12:33:26 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sugarenia.com/archives/rantings/get-your-error-messages-right-people#comment-22342</guid>
		<description>It's one of those stupid things someone forgot to do.. or maybe it's the implementation of the query that doesn't make life easy enough for such error messages.

You love me, I love you: let's make love :)</description>
		<content:encoded><![CDATA[<p>It&#8217;s one of those stupid things someone forgot to do.. or maybe it&#8217;s the implementation of the query that doesn&#8217;t make life easy enough for such error messages.</p>
<p>You love me, I love you: let&#8217;s make love <img src='http://blog.sugarenia.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sugar</title>
		<link>http://blog.sugarenia.com/archives/rantings/get-your-error-messages-right-people#comment-22341</link>
		<dc:creator>Sugar</dc:creator>
		<pubDate>Sun, 31 Dec 2006 11:39:29 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sugarenia.com/archives/rantings/get-your-error-messages-right-people#comment-22341</guid>
		<description>Har har har.

Why should I do that, since with just one right error message, they'd put me in the right track and make me understand what's wrong at a glance?

I love you too! :P</description>
		<content:encoded><![CDATA[<p>Har har har.</p>
<p>Why should I do that, since with just one right error message, they&#8217;d put me in the right track and make me understand what&#8217;s wrong at a glance?</p>
<p>I love you too! <img src='http://blog.sugarenia.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
</channel>
</rss>
