View Single Post
04-01-11, 10:55 AM   #36
Doskious
A Deviate Faerie Dragon
AddOn Author - Click to view addons
Join Date: Mar 2009
Posts: 14
Downloading needs Authentication???

Originally Posted by fixitman333 View Post
I understand how requiring an authenticator for uploading anything (files, posts, etc) can improve security. I even understand how it would help protect the repository. I can't understand how requiring one for downloading does anything for security though. We'll be able to browse the site without one (which requires downloading data), so why require one for simply downloading updated addons?

Edit: I have no issue with the price, this just seems like too much hassle for my needs. I already deal with an authenticator for my WoW accounts. It can be really aggravating to have to wait for a new code to pop up for each account when I multibox. I just have to remember that having all three accounts stolen would be worse. I can't see a security downside to my not having an authenticator for wowinterface though.
I have to confess, requiring an authenticator for *file downloads* seems unjustifiable to me - both for the "site navigation" reason that fixitman333 identified and also because the process of downloading a file is an output from, rather than an input to, the WoWInterface system. In order to ensure system security, inputs need to be carefully managed/watched/regulated, but outputs need not be so limited, inasmuch as the system itself controls the outputs.

In short, until now I have enjoyed the environment of WoWInterface substantially over the environment of other WoW Addon sites. I have not created any addons, and have only replied infrequently in addon-based threads, but I have downloaded almost all of my addons from here - this site has been my first stop before loading WoW almost every day to check for updated mods that I use, and come April 11, I'll be denied that option.

While I don't object to the notion of authenticators costing $5, I do strenuously object to the imposition of totally unnecessary "security" measures that are designed to chisel any amount of money out of me so that I can continue to download files. I don't object to requiring an authenticator to post, I certainly don't object to requiring an authenticator to author files - these are legitimate sources of system input that the authenticator system will protect. I don't even object to the notion of requiring an authenticator to maintain a list of favorite addons (though it seems to me that this feature could be segregated from sensitive regions of the system in a way to preclude needing to require an authenticator). Downloading is not a system input (if it is presently designed to allow system input, then somebody seriously messed up that design), and as such, as I understand it, should be able to be executed in the absence of an authenticator without any security risks.

I would greatly appreciate an explanation of why downloads are included in the authenticator blanket, including what security risks unauthenticated downloads pose.

~Doskious

Edit: Well played. I cannot read backwards, nor can I properly make sense of a calendar.

Last edited by Doskious : 04-01-11 at 05:00 PM. Reason: A-hah!
  Reply With Quote