5 ms·
I'm not sure if accepting unicode characters is a good idea. It would make it more secure but you can very easily get locked out of your own account if you try
by peterjlee 10y ago
I'm not sure if accepting unicode characters is a good idea. It would make it more secure but you can very easily get locked out of your own account if you try to login from another device without the correct input method.
Here's one extreme example of it:
"I included emoji in my password and now I can't log in to my Account on Yosemite"(https://news.ycombinator.com/item?id=10742351 https://news.ycombinator.com/item?id=10742351)
- tuwtuwtuw 10y agoA somewhat similar issue appears with Bitlocker in Windows. When you set your password you are using your custom Windows keyboard layout, such as sv-SE (Swedish). But then when you are prompted to enter your password during boot to decrypt your computer the keyboard is always en-US. It's fun figuring out how to type Swedish and special characters on a foreign keyboard layout. Of course no part of the UI indicates this layout issue. I think Unicode is good. I think companies should fix their broken input instead.
- loup-vaillant 10y agoShame on Microsoft, then. My Ubuntu Linux laptop was installed with the default settings for full disk encryption, and it uses my favourite layout right there at boot time.
- nikcub 10y agoA BIOS is 7bit ASCII - if you want anything more than that you need to load a ramdisk with drivers. If you're loading a ramdisk with drivers then you may as well also load a keylogger. You'd also need to recreate that ramdisk if your hardware fails, and good luck booting from non-root encrypted volumes. Using EN-US for boot disk volumes is pretty good advice. Microsoft have thought this through - their recovery keys are ASCII numerals only and are entered using function keys since they're the only universal keys. edit: relevent Technet: https://technet.microsoft.com/en-us/library/ee449438(v=ws.10).aspx#BKMK_Key https://technet.microsoft.com/en-us/library/ee449438(v=ws.10...
- loup-vaillant 10y agoAnd where exactly the keylogger is supposed to come from? Has your laptop been tampered with during lunch? Then I'm afraid bitlocker is just as screwed as my Ubuntu. Or has the laptop been owned during use (remote vulnerability, double click on a malware…)? Same thing. I'm not sure I see the point of this limitation. At a first glance, it seems using the BIOS only doesn't buy us much.
- user5994461 10y agoMay I suggest a hardware keylogger? Noone will ever figure out that the fat plug at the end of the USB cable is a keylogger =)
- DanielLee5 10y agoAny recommendations on a good keylogger software please? Have anybody tried this one https://www.refog.com/ https://www.refog.com/ , I read only positive reviews on it. Thanks in advance.
- MarcScott 10y agoIt may not even remotely be the user's fault as well, if generated passwords can have unicode characters.
- witty_username 10y agoBut, not everyone uses Roman script languages. I think the best solution is displaying a warning when using non-US keyboard characters.
- pokemon-trainer 10y agoMy Unicode password: ( ͡° ͜ʖ ͡°)
- paulddraper 10y agoI think that tends closer to a user problem. If they don't have input mechanisms for white corner bracket, don't use white corner bracket.