<?xml version="1.0"?>
<rss version="2.0">
   <channel>
      <title>Systems Security Project  by Durgashini</title>
      <link>https://padlet.com/durgashini7/njzeka3d4xakbb2a</link>
      <description>Group Members: Keng Tiong (191404X), Durgashini (192159E), Narmatha (193081T)</description>
      <language>en-us</language>
      <pubDate>2020-04-21 02:29:32 UTC</pubDate>
      <lastBuildDate>2024-10-15 10:04:46 UTC</lastBuildDate>
      <webMaster>hello@padlet.com</webMaster>
      <image>
         <url>https://padlet.net/icons/png/1f913.png</url>
      </image>
      <item>
         <title>FaceBook(Keng Tiong)</title>
         <author>ahtiongtkt37</author>
         <link>https://padlet.com/durgashini7/njzeka3d4xakbb2a/wish/541188901</link>
         <description><![CDATA[<div>-pros</div><div>-Don’t allow user to forget or change his/her password for more then 5 times in a day</div><div>-When account is created, a code will be sent to the user’s email account to verify whether the created is the legit owner of the email account set</div><div>-Prompt user when email user to inform password have been set and device and IP address used.</div><div>-con</div><div>-Allow user to set the same password over and over again, which will result in account being bruteforce by hackers.</div><div>-no 2FA<br>-Password requirement of at least 6 characters long and suggestion to user to create a strong password by having a combination of letters, digits and punctuation marks. This allow user's password to be not easily bruteforce by hackers<br><br></div>]]></description>
         <enclosure url="" />
         <pubDate>2020-04-30 08:01:09 UTC</pubDate>
         <guid>https://padlet.com/durgashini7/njzeka3d4xakbb2a/wish/541188901</guid>
      </item>
      <item>
         <title>Investing.com(Keng Tiong)</title>
         <author>ahtiongtkt37</author>
         <link>https://padlet.com/durgashini7/njzeka3d4xakbb2a/wish/541193920</link>
         <description><![CDATA[<div>-Investing .com</div><div>-cons- allow user to set a password that is used before when resetting the account                      password hence will allow hackers to bruteforce to the account</div><div>          -  No 2FA</div><div>-Pros <br>– Verify user is legit by having a image verification “ I’m not the robot prompt”</div><div> - Verify user own the email account entered to create an account by issuing a code to be sent in the email account when creating the account.</div><div>  -reset password link is sent to the email account<br>-Password requirement of  using 4-15 characters with minimum of 2 letters and digit in order to create a more secure password and not being bruteforce easily by hackers.</div>]]></description>
         <enclosure url="" />
         <pubDate>2020-04-30 08:03:17 UTC</pubDate>
         <guid>https://padlet.com/durgashini7/njzeka3d4xakbb2a/wish/541193920</guid>
      </item>
      <item>
         <title>Gmail (Keng Tiong</title>
         <author>ahtiongtkt37</author>
         <link>https://padlet.com/durgashini7/njzeka3d4xakbb2a/wish/541195654</link>
         <description><![CDATA[<div>Gmail password recovery</div><div>-Don’t allow the user to choose password that have been used before</div><div>-Verify user with sms or email codes sent</div><div>-Prompt message is sent to owner when password is successfully sent</div><div>-2FA log in options are available for user who wanted their account to be much more secure</div><div>-Allow user to enter their phone number to their gmail account, code will be sent to their mobile number via sms <br>-Password requirement of use 8 or more characters with a mix of letters, numbers &amp; symbols in order to create a more secure password and not being bruteforce easily by hackers.</div>]]></description>
         <enclosure url="" />
         <pubDate>2020-04-30 08:04:05 UTC</pubDate>
         <guid>https://padlet.com/durgashini7/njzeka3d4xakbb2a/wish/541195654</guid>
      </item>
      <item>
         <title>Carousell.com (Durgashini)</title>
         <author>durgashini7</author>
         <link>https://padlet.com/durgashini7/njzeka3d4xakbb2a/wish/544213425</link>
         <description><![CDATA[<div><em><mark>Carousell.com</mark></em></div><div><strong><em>Advantages:</em></strong></div><ul><li>User is asked to type their mobile number and an account registration confirmation prompt notice sms is sent immediately</li><li>Already used usernames are not allowed</li><li>Already used mobile numbers are not allowed</li><li>Invalid email addresses are not allowed</li><li>User has to use the verification code sent in that sms to proceed</li><li>No common passwords (1234, abcd, birth date) are allowed</li><li>User is asked to click the ‘I’m not a robot’ checkbox</li><li>User is asked to do an image verification </li><li>When user clicks ‘forgot password’, an email / sms is sent to the user for him to use the verification code, in order to get access to the resetting of the password</li><li>User is not allowed to use passwords that were previously used, so it is more secure</li><li>Once password is successfully reset, a prompt email / sms is sent immediately<br><br></li></ul><div><strong> </strong></div><div><strong><em>Disadvantages:</em></strong></div><ul><li>No 2-step verification</li><li>No 2FA options, so it is less secure</li><li>No strict password requirement (eg. alphanumeric, mix of symbols, mix of lower and uppercase, minimum no. of characters)</li></ul>]]></description>
         <enclosure url="https://padlet-uploads.storage.googleapis.com/538714330/44034091ecc6594a2741215d7f4e4579/Screenshot__187_.png" />
         <pubDate>2020-05-01 14:59:55 UTC</pubDate>
         <guid>https://padlet.com/durgashini7/njzeka3d4xakbb2a/wish/544213425</guid>
      </item>
      <item>
         <title>Amazon.com (Durgashini)</title>
         <author>durgashini7</author>
         <link>https://padlet.com/durgashini7/njzeka3d4xakbb2a/wish/544219045</link>
         <description><![CDATA[<div><em><mark>Amazon.com</mark></em></div><div><strong><em>Advantages:</em></strong></div><ul><li>User is asked to type their email address and an account registration confirmation prompt notice email is sent immediately</li><li>User has to click on the link sent in that email to proceed</li><li>Strict password requirement (eg. alphanumeric, mix of symbols, mix of lower and uppercase, minimum length)</li><li>Already used usernames are not allowed</li><li>Already used mobile numbers are not allowed</li><li>Invalid email addresses are not allowed</li><li>No common passwords (1234, abcd, birth date) are allowed</li><li>User is asked to click the ‘I’m not a robot’ checkbox</li><li>User is asked to do a 2-step verification procedure: an audio verification and jumbled up characters verification</li><li>When user clicks ‘forgot password’, an email / sms is sent to the user for him to use the verification code, in order to get access to the resetting of the password</li><li>User is not allowed to use passwords that were previously used, so it is more secure</li><li>Once password is successfully reset, a prompt email / sms is sent immediately</li><li>That prompt email  / sms has an option ‘No, it wasn’t me who reset the password’, so that users can take action if their account was hacked<br><br></li></ul><div> </div><div><strong><em>Disadvantages:</em></strong></div><ul><li>No 2FA options, so it is less secure </li></ul>]]></description>
         <enclosure url="https://padlet-uploads.storage.googleapis.com/538714330/67f801da6aefdf9f46e348641587c2b5/Amazon_Page_4.png" />
         <pubDate>2020-05-01 15:02:10 UTC</pubDate>
         <guid>https://padlet.com/durgashini7/njzeka3d4xakbb2a/wish/544219045</guid>
      </item>
      <item>
         <title>Shoppee.com (Durgashini)</title>
         <author>durgashini7</author>
         <link>https://padlet.com/durgashini7/njzeka3d4xakbb2a/wish/544221112</link>
         <description><![CDATA[<div><em><mark>Shoppee.com</mark></em></div><div><strong><em>Advantages:</em></strong></div><ul><li>User is asked to click the ‘I’m not a robot’ checkbox</li><li>Already used usernames are not allowed</li><li>Invalid email addresses are not allowed</li><li>When user clicks ‘forgot password’, an email / sms is sent to the user for him to use the verification code, in order to get access to the resetting of the password</li><li>Once password is reset, a prompt email / sms is sent immediately<br><br></li></ul><div> </div><div><strong><em>Disadvantages:</em></strong></div><ul><li>No password requirement </li><li>No image / audio / jumbled up characters verification</li><li>Already used mobile numbers are allowed, so people can create multiple fake accounts using one mobile number</li><li>Common passwords (1234, abcd, birth date) are allowed, so hackers can easily guess their passwords by doing a brute-force attack to hack into victims' accounts</li><li>No 'confirm password' option</li><li>User is allowed to use passwords that were previously used, so hackers can easily guess their victims’ passwords</li><li>Once password is successfully reset, a prompt email / sms is NOT sent</li><li>No 2FA options, so it is less secure </li><li>No 2-step verification</li></ul>]]></description>
         <enclosure url="https://padlet-uploads.storage.googleapis.com/538714330/b3104964bde0b69cc5ddfdc8b6df17d4/Screenshot__178_.png" />
         <pubDate>2020-05-01 15:03:06 UTC</pubDate>
         <guid>https://padlet.com/durgashini7/njzeka3d4xakbb2a/wish/544221112</guid>
      </item>
      <item>
         <title>SingPass (Narmatha)</title>
         <author>15narmatha2002</author>
         <link>https://padlet.com/durgashini7/njzeka3d4xakbb2a/wish/545491978</link>
         <description><![CDATA[<div><strong>SingPass Login<br>More Secure</strong></div><div><strong><em>Advantages: </em></strong><br>- User can set up 2FA<br>- User can rest their password any time.</div><div>- Users can download the app in their mobile phone, they can register the mobile app; they can either set thumbprint to login or a 6-digit pin.</div><div>- Users can scan the code shown on their laptops, using their phone app. This makes it more user friendly easier to excess.<br>- Password cannot be the same as User ID</div><div>- Password to be between 8 – 24 alphanumeric characters, preferably containing upper case letters and symbols, with at least 1 letter and 1 number.<br>- Common passwords are disallowed, e.g., “password123”, “pwd12345”.</div><div>- Users new password cannot be the same as any of your previous five passwords.<br><br><strong><em>Disadvantages</em></strong>: <br>- Confidential information of users are stored.<br><br>- Elder users might not be able to use high tec features like scan QR code</div><div><br></div><div><br></div>]]></description>
         <enclosure url="https://padlet-uploads.storage.googleapis.com/538722943/fec6b4c3400918d00d509ddda4ce429f/Screenshot__183_.png" />
         <pubDate>2020-05-02 12:42:11 UTC</pubDate>
         <guid>https://padlet.com/durgashini7/njzeka3d4xakbb2a/wish/545491978</guid>
      </item>
      <item>
         <title>FastJob(Narmatha) </title>
         <author>15narmatha2002</author>
         <link>https://padlet.com/durgashini7/njzeka3d4xakbb2a/wish/546594507</link>
         <description><![CDATA[<div><strong>FastJobs.sg</strong><br><strong><em><br>Disadvantages:<br></em></strong>-When the user first enters their new password there is no confirm password option.<br>- Though they require phone number while signing up, the only way to retrieve back user's acc is the email they provided while signing up.<br>- If the user has no access to that email or forgot the password of that email the user will not be able to rest the password if they forget for FastJobs<br><br><strong><em>Advantages:<br></em></strong>- When the users first sign up, they are sent an email to verify their email.<strong><em><br>-</em></strong> Users can rest their password via email<strong><em><br></em></strong>- When forget password is clicked, user is redirected to this page which has I'm not a robot verification.<br>- Another email sent to the user to rest password.</div>]]></description>
         <enclosure url="https://padlet-uploads.storage.googleapis.com/538722943/d7f6a78e7efe3ea681743c1367330cd0/WhatsApp_Image_2020_05_03_at_7_17_34_PM.jpeg" />
         <pubDate>2020-05-03 10:33:09 UTC</pubDate>
         <guid>https://padlet.com/durgashini7/njzeka3d4xakbb2a/wish/546594507</guid>
      </item>
      <item>
         <title>Spotify(Narmatha)</title>
         <author>15narmatha2002</author>
         <link>https://padlet.com/durgashini7/njzeka3d4xakbb2a/wish/546736635</link>
         <description><![CDATA[<div><strong>Spotify.com<br><br>Disadvantages:<br></strong>- There isn't a confirm password option.<br>-  A default username is given; cant be changed on laptop.<br><strong><br>Advantages:<br></strong>- User can sign up either via email or Facebook.<strong><br></strong>- Doesn't allow an used password<br>- It uses I'm not a robot for verification<br>- Sends an email to verify account<br>- Reset can be done via email.<br>-  I'm not a robot verification is set for both signing up and while resetting. </div>]]></description>
         <enclosure url="https://padlet-uploads.storage.googleapis.com/538722943/50a419b61b9053577c0320f846950d31/Screenshot__186_.png" />
         <pubDate>2020-05-03 12:27:14 UTC</pubDate>
         <guid>https://padlet.com/durgashini7/njzeka3d4xakbb2a/wish/546736635</guid>
      </item>
      <item>
         <title></title>
         <author>15narmatha2002</author>
         <link>https://padlet.com/durgashini7/njzeka3d4xakbb2a/wish/553682614</link>
         <description><![CDATA[Amazon.com (Durgashini)
Amazon.com (Durgashini)
Amazon.com
Advantages:
User is asked to type their email address and an account registration confirmation prompt notice email is sent immediately
User has to click on the link sent in that email to proceed
Strict password requirement (eg. alphanumeric, mix of symbols, mix of lower and uppercase, minimum length)
Already used usernames are not allowed
Already used mobile numbers are not allowed
Invalid email addresses are not allowed
No common passwords (1234, abcd, birth date) are allowed
User is asked to click the ‘I’m not a robot’ checkbox
User is asked to do a 2-step verification procedure: an audio verification and jumbled up characters verification
When user clicks ‘forgot password’, an email / sms is sent to the user for him to use the verification code, in order to get access to the resetting of the password
User is not allowed to use passwords that were previously used, so it is more secure
Once password is successfully reset, a prompt email / sms is sent immediately
That prompt email  / sms has an option ‘No, it wasn’t me who reset the password’, so that users can take action if their account was hacked

 
Disadvantages:
No 2FA options, so it is less secure 
FastJob(Narmatha)
FastJob(Narmatha) 
FastJobs.sg

Disadvantages:
-When the user first enters their new password there is no confirm password option.
- Though they require phone number while signing up, the only way to retrieve back user's acc is the email they provided while signing up.
- If the user has no access to that email or forgot the password of that email the user will not be able to rest the password if they forget for FastJobs

Advantages:
- When the users first sign up, they are sent an email to verify their email.
- Users can rest their password via email
- When forget password is clicked, user is redirected to this page which has I'm not a robot verification.
- Another email sent to the user to rest password.
Spotify(Narmatha)
Spotify(Narmatha)
Spotify.com

Disadvantages:
- There isn't a confirm password option.
-  A default username is given; cant be changed on laptop.

Advantages:
- User can sign up either via email or Facebook.
- Doesn't allow an used password
- It uses I'm not a robot for verification
- Sends an email to verify account
- Reset can be done via email.
-  I'm not a robot verification is set for both signing up and while resetting. 
]]></description>
         <enclosure url="" />
         <pubDate>2020-05-06 03:28:03 UTC</pubDate>
         <guid>https://padlet.com/durgashini7/njzeka3d4xakbb2a/wish/553682614</guid>
      </item>
      <item>
         <title></title>
         <author>15narmatha2002</author>
         <link>https://padlet.com/durgashini7/njzeka3d4xakbb2a/wish/553682631</link>
         <description><![CDATA[Amazon.com (Durgashini)
Amazon.com (Durgashini)
Amazon.com
Advantages:
User is asked to type their email address and an account registration confirmation prompt notice email is sent immediately
User has to click on the link sent in that email to proceed
Strict password requirement (eg. alphanumeric, mix of symbols, mix of lower and uppercase, minimum length)
Already used usernames are not allowed
Already used mobile numbers are not allowed
Invalid email addresses are not allowed
No common passwords (1234, abcd, birth date) are allowed
User is asked to click the ‘I’m not a robot’ checkbox
User is asked to do a 2-step verification procedure: an audio verification and jumbled up characters verification
When user clicks ‘forgot password’, an email / sms is sent to the user for him to use the verification code, in order to get access to the resetting of the password
User is not allowed to use passwords that were previously used, so it is more secure
Once password is successfully reset, a prompt email / sms is sent immediately
That prompt email  / sms has an option ‘No, it wasn’t me who reset the password’, so that users can take action if their account was hacked

 
Disadvantages:
No 2FA options, so it is less secure 
FastJob(Narmatha)
FastJob(Narmatha) 
FastJobs.sg

Disadvantages:
-When the user first enters their new password there is no confirm password option.
- Though they require phone number while signing up, the only way to retrieve back user's acc is the email they provided while signing up.
- If the user has no access to that email or forgot the password of that email the user will not be able to rest the password if they forget for FastJobs

Advantages:
- When the users first sign up, they are sent an email to verify their email.
- Users can rest their password via email
- When forget password is clicked, user is redirected to this page which has I'm not a robot verification.
- Another email sent to the user to rest password.
Spotify(Narmatha)
Spotify(Narmatha)
Spotify.com

Disadvantages:
- There isn't a confirm password option.
-  A default username is given; cant be changed on laptop.

Advantages:
- User can sign up either via email or Facebook.
- Doesn't allow an used password
- It uses I'm not a robot for verification
- Sends an email to verify account
- Reset can be done via email.
-  I'm not a robot verification is set for both signing up and while resetting. 
]]></description>
         <enclosure url="" />
         <pubDate>2020-05-06 03:28:05 UTC</pubDate>
         <guid>https://padlet.com/durgashini7/njzeka3d4xakbb2a/wish/553682631</guid>
      </item>
   </channel>
</rss>
