Just throwing a thought out there: What about an option that allows people to use etacts without storing their password. So every time a user wants to "refresh" their data, they would have to re-enter their password.
The security advantages are limited– the password has to go through you guys either way– but there may be a difference psychologically.
I don't think mail2web would be as widely-used if they didn't have a policy against storing passwords.
You can't convince people like me to give you a gmail password. It's simply not going to happen.
Meanwhile, you could convince my mom to give up her gmail password with an animated GIF of a cartoon padlock.
What we can help you with here is how to communicate about security without setting off alarm bells. Your security page isn't awful; "bank security" is a security idiom, it's fine that you use it. But we can help you make it better. Make it clear that you're storing passwords so nobody can say they're surprised about, and make sure security researchers know how to contact you.
Comments
Just throwing a thought out there: What about an option that allows people to use etacts without storing their password. So every time a user wants to "refresh" their data, they would have to re-enter their password.
The security advantages are limited– the password has to go through you guys either way– but there may be a difference psychologically.
I don't think mail2web would be as widely-used if they didn't have a policy against storing passwords.
this is a good idea, we'll talk to our users and see if this is a wanted feature.
It won't be. Don't bother.
You can't convince people like me to give you a gmail password. It's simply not going to happen.
Meanwhile, you could convince my mom to give up her gmail password with an animated GIF of a cartoon padlock.
What we can help you with here is how to communicate about security without setting off alarm bells. Your security page isn't awful; "bank security" is a security idiom, it's fine that you use it. But we can help you make it better. Make it clear that you're storing passwords so nobody can say they're surprised about, and make sure security researchers know how to contact you.