4 ms·
> While lowercasing the passwords increases the guess-ability of the password when attempting to log in to this site it actually reduces the value of the passw
by rms_returns 10y ago
> While lowercasing the passwords increases the guess-ability of the password when attempting to log in to this site it actually reduces the value of the password in a breach of this sort
But why don't they use the proven common-sense strategy of not storing the passwords at all, but store the hashes instead? They can validate by converting user-input to a hash and then there is no harm even if the user auth table is stolen.
- gruturo 10y agoAccording to the article they were indeed hashes, but they were converted to lowercase _before_ hashing. This effectively makes your password case insensitive and probably reduces the % of support tickets (some people might not just click a reset password link and will insist they were typing it right, so they will open a ticket - all because they forgot capslock). It reduces operating costs at the expense of lower security and somebody must have considered it to be worth it.
- lloeki 10y agoRead that again, slower. > "the hashed passwords seem to have been changed to all lowercase before storage"