5 ms·
Your email may be less secure in the hands of a local sysadmin than with a company like Google, which has a valuable reputation to defend and sophisticated syst
by va_coder 16y ago
Your email may be less secure in the hands of a local sysadmin than with a company like Google, which has a valuable reputation to defend and sophisticated systems in place to guard your data.
A legitimate reason to not use Google is their history of less than perfect customer service; they excel in technology, not in customer service.
- credo 16y agoAs per the article, it appears that privacy concerns played a bigger role (than security concerns) in the UC decision. Your comment solely addresses security, but privacy concerns are not necessarily the same as security concerns
- fname 16y agoYes, but at least they can audit and track those accesses with a local sysadmin and ask questions when appropriate.
- deleted 16y ago[deleted]
- zerokyuu 16y agoI completely agree. My university required you to change your password every 90 days. Not such a bad idea, however, they compare your new password against all previous passwords to make sure they are significantly different (e.g. you can't change your password from abcdefg to abcdeff). I'm assuming this means they save your passwords in clear text somewhere. Not exactly the type of people I'd trust with sensitive information. EDIT: meastham makes a good point and he/she could definitely be right about generating hashes of all slight variations of each password. In response to what fname said, I'm wondering if there are any security concerns about being able to find similarities in hashes for similar passwords.
- fname 16y agoIn the Windows/AD world, this is not true. AD will never store a current or previous password in clear-text. AD will, however, compare the password hashes before it will accept the new password when this type of setting is enabled. EDITed to add: There's some logic to detect how close a new password is to an old one. Mainly, it's looking for consistencies between the 2.
- p858snake 16y agoYou can easily tell AD (at least in 03) to store passwords in plain text (for backwards compatibility).
- meastham 16y agoThat doesn't mean that they're storing your passwords in the clear. They could simply be keeping hashes of your old passwords around and checking simple variations of the new password you're trying to use.
- deleted 16y ago[deleted]
- Locke1689 16y agoIf I understand what you're suggesting, it is that they generate a list of slight variations to the new password, has it, then compare it to the old password, right? I think many people are misunderstanding what you're saying i.e., they think you're saying that similarities between hashes correspond to similarities between passwords.
- nopassrecover 16y agoWhy are you assuming that? You can compare hashes ("does the encrypted version of what they entered as a new password equal any of the encrypted previous passwords").
- deleted 16y ago[deleted]
- lftl 16y agoIf by hash you mean a one-way hashing system, then he did say significantly different and not just different. You couldn't do that with any common one-way hash.
- nopassrecover 16y agoYou're correct, I didn't understand what he meant by significantly different until you pointed out because I have never encountered a system that didn't allow me to have a "similar password". However, I have encountered ones where my new password could not contain previous passwords, so unless they are hashing each component of my password and comparing this probably does indicate clear-text storage.
- deleted 16y ago[deleted]
- fnid2 16y agoI've never bought this argument. It is mathematically unsound. Systems behind my firewall, touched by one or two people, and with fewer hackers trying to break in are exposed to fewer threats. Many people want to break into gmail, because it's gmail. Many fewer people care about breaking into one university. There's no wire over which to transmit information. The more access points there are and the more hackers there are who can reach the systems, the greater the probability that one of those hackers will succeed. Google's sophisticated systems have already been compromised by unsophisticated hackers in China. A house with 5 doors is less secure than a house with 1 door. A house with no windows is more secure than a house with windows.
- csytan 16y agoBut then again, there's safety in numbers. There may be more hackers, but there's a significantly larger number of accounts.