6 ms·
Looks like some good suggestions: - Glad they're recommending a stop to the pointless "password must be no longer than (16, 20, ...) characters". Aren't you st
by mylesm 10y ago
Looks like some good suggestions:
- Glad they're recommending a stop to the pointless "password must be no longer than (16, 20, ...) characters". Aren't you storing a constant-length hash anyway?
- Why do some logins restrict which ASCII characters can be used? When I see that I can use any symbol from '%!#&' or whatever list they provide, I can only imagine it's a really naive SQL-injection defense. Is there any valid reason for this?
- And glad to see they're recommending against "security challenges". Half the time I'm forced to pick a security question, either none of them apply, a bunch of them are ambiguous ("what's your favorite movie?" - uhh, I'll give you a different answer depending on my mood, etc.), or they're easily searchable ("where did you go to high school?")
Unfortunately I doubt the bad actors will pay too much attention to this. I know Google is planning on dinging sites that don't use HTTPS, is it possible they could ding sites for poor password policies?
- derefr 10y ago> Is there any valid reason for this? If they know that at some point they'll have to ask you to enter your password over a restricted input-method (e.g. on a DTMF keypad.)
- Molomby 10y agoReal world example of this "limited input" problem: http://apple.stackexchange.com/questions/202143/i-included-emoji-in-my-password-and-now-i-cant-log-in-to-my-account-on-yosemite http://apple.stackexchange.com/questions/202143/i-included-e... Pre-Touch Bar, of course...
- colanderman 10y agoYep. FastMail restricts spaces in passwords due to mail clients that do not allow them.
- kibwen 10y agoWhich clients specifically?
- nmjenkins 10y ago(FastMail developer here) The issue was actually that we support many different protocols (not just mail) and some combinations of clients/protocols have had issues in the past (it might have been some FTP clients I think, but can't remember right now.) Anyway, this restriction no longer applies as we now require server-generated app passwords for 3rd party apps: https://www.fastmail.com/help/clients/apppassword.html https://www.fastmail.com/help/clients/apppassword.html. So feel free to use as many spaces as you like in your password!
- colanderman 10y agoI didn't know that, thanks, and thanks for providing a product I can rely on!
- rdiddly 10y agoI just use the security questions as another password, like my favorite color is JyQ|l[Duc-I6KrU-0k and I went to elementary school at ?YfBW+Yurh@m$lml":.
- zwily 10y agoThose are rough when a customer service rep asks you for one of those over the phone... :)
- Nadya 10y agoI was literally just about to post this. I refuse to make my password less secure though - and security questions really are just "alternate passwords". I've never had a problem but I have had a few reps who are trying to not act really surprised. I've had one instance of someone trying to stifle laughter (of the "You can't be serious") kind. Taking security seriously is a rare thing. :( They usually stop me after the 8th or so character. I'd be concerned but if any potential social engineer has the first 8 characters they likely have the full string anyways so stopping early makes both our jobs easier.
- ryanlol 10y agoOn several social engineering calls I've had reps who were happy with just "it's just a bunch of random characters, would be a little silly if I tried to read it out"
- _kst_ 10y agoWow, that's disturbing. Perhaps I should say that my first pet's name was "mellower retry audited grieves" rather than "esrhciaiyzhkj". (Both are random, and both have very close to the same information content given the dictionary I used.)
- josephg 10y agoI do this. I told the CS rep that my password hint was "just random characters mashed on the keyboard" and she accepted this and moved on. I'm not sure what to think of the security implications.
- 1_2__3 10y agoMy suggestion: use a nonsense answer and use it for all of them. I don't reuse passwords but for exactly the reasons you state the answer to all my security challenges is something like "Because a kipper doesn't red the blue." Alternately have a few nonsense phrases for stock challenge questions (first car, first pet, favorite <thing>, etc.) It's better than using the real (googleable) answer. Finally, as Dale Carnegie would have loved: the more absurd it is the easier it is to remember. So while you won't remember if your favorite movie is the matrix or titanic, but you WOULD remember "I clocked blithely cookie everywhere." as the answer when you see that question.
- hexane360 10y agoPafwert [1] creates the absurd really well. [1] https://github.com/m8urnett/pafwert https://github.com/m8urnett/pafwert
- koolba 10y agoHere's what I use to generate answers to secret questions: < /dev/urandom tr -dc a-z0-9 | head -c 16 This leads to things like: > "What is your first pet's name?" "q1ry9nftmxb1gmag" I haven't had it happen yet, but I wonder what a customer service rep's response will be when I spell out "yrlmduihhyju5il0" when asked what my favorite color is.
- OptimalRoasted 10y agoThe guy on the phone laughed. I've moved to providing a few random words, easier to say over the phone than capital y lowercase r number 1.... etc.
- estefan 10y agoThe woman on the phone at the utility company that was messing me around didn't laugh when I said the answer to my security question "what do you think of customer service" was "f*cking retards" :-D
- 10y ago
- callmeal 10y agoI usually have fun with security challenges. And get annoyed at ones with multiple choice answers. What's your favorite movie? -> a sexual position Where did you go to high school? -> another sexual position City of birth? -> something else from the kamasutra Of course, that makes phone conversations where they ask you those security questions very fun.
- oneeyedpigeon 10y agoApparently, sexually explicit concepts (maybe all 'shocking' concepts?) are very highly memorable, so that's probably a good approach!
- ams6110 10y ago> When I see that I can use any symbol from '%!#&' or whatever list they provide, I can only imagine it's a really naive SQL-injection defense. Is there any valid reason for this? One reason I've seen for this is that the website is just a front-end for some older mainframe system that has password rules from 1987. Banks and insurance companies are frequently culprits here.
- kbart 10y ago" I know Google is planning on dinging sites that don't use HTTPS, is it possible they could ding sites for poor password policies?" How they gonna do that? Do you expect Google to audit every site in their search ranks?
- Qantourisc 10y agoThe same way to index websites: with web-spiders. They would need to write new code for this though. Also for HTTPS they also had to write new code.
- kbart 10y agoHow do you check if password is salted and hashed correctly afterwards? There's not much use of strong passwords if they are stored in plaintext anyway.
- oneeyedpigeon 10y agoCouldn't Google just auto-register an account with a known good password, and penalise the account if it fails? Someone else mentioned improving the http authentication 'api', which would definitely help in this regard; until then there are drawbacks to the auto-register approach including things like captchas. Sites would have to explicitly allow the Google bot to bypass them.
- hollander 10y agoThey should have required proper guiding when creating a new password. I normally use passwords that are like 80 characters long, generated in a password manager. If I paste one of these in a password field, then submit, I get the warning that it's too long. Why didn't it say so when I pasted it? Why put a limit on it below 256 characters? Does that really matter nowadays? It's not a 5MB selfie I'm uploading. The limitions of the password should be built in the HTML of the form like a regex or something easier.