7 ms·
When passwords are case insensitive I'm always skeptical that they are storing passwords in plain text. Ofcourse they could be using a function to change the c
by mataug 10y ago
When passwords are case insensitive I'm always skeptical that they are storing passwords in plain text.
Ofcourse they could be using a function to change the case before putting it through a oneway function but it just adds to the suspicion.
The other horrid offence that I see banks make is preventing users from pasting / autofilling their passwords. This just asks for people to use common easy to guess passwords instead of a password manager.
- ntumlin 10y agoDisallowing autofill I could understand to prevent people from accidentally saving credentials on public devices. Maybe disallowing pasting is a (bad) attempt to disallow automated password guessing.
- Cthulhu_ 10y agoBetter safe than sorry right? I mean I can imagine pasting stuff into forms via some JS is how script kiddies start out.
- Already__Taken 10y agoIf you don't let keepass paste into your form I'm just not going to use you.
- hvidgaard 10y agoA password should be hashed client side, and lowercasing (or upper casing) before hashing would be trivial and just as secure if you accept that the searchspace is reduced.
- throwawaysbdi 10y agoEh, if you're using TLS it really doesn't matter where you hash. There's a lot of arguments for not doing secure hashing and encryption in JavaScript
- hvidgaard 10y agoIf I hash client side the server will never know my password. If the server hashes the password, that is effectively the same as storing the password in cleartext. /edit: Security wise sending the password, means you trust the server to handle the password correctly. For all we know it stores the plaintext password. If we send the hash, we KNOW that it does not store the password. It's an important distinction to make in real world systems. No matter how much best practices dictates to not reuse passwords, it happens as long as humans are involved.
- justinjlynn 10y agoAnd yet the server sends you the code to hash your password. Either way, if the server compromised, all bets are off. That said, there are architectures where this may make a difference, but they certainly aren't the usual case.
- hvidgaard 10y agoThe difference is that I can verify the code, and the data send. If I send the password to serverside hashing, I can only trust the server to handle it correctly. Security wise that is a fairly important difference.
- temprature 10y agoAre you saying you not only know of some website that does password hashing client-side but that you also inspect the javascript that site serves you every time you login?
- hvidgaard 10y agoSecurity wise there is a difference. This difference don't matter to the average person. I don't reuse passwords, so I don't need this protection.
- Freak_NL 10y ago
- thegreatpl 10y agoActually, Passwords should never be hashed client side. Otherwise, a man in a middle attack could intercept the hash and get your password, allowing them to log in. Instead, the password should be encrypted to the server, and hashed there.
- iopq 10y ago> When passwords are case insensitive I'm always skeptical that they are storing passwords in plain text. or maybe they always to_lowercase all the passwords before hashing them
- detaro 10y agoThat's exactly what the next line in the parent comment says.
- iopq 10y agoBut it makes the whole comment pointless, how does it add to the suspicion?
- eximius 10y agoNo it doesn't, case insensitive passwords have nearly half of the entropy. It's less bad than plaintext password storage but only barely.
- iopq 10y agoMost passwords don't have capital letters unless forced by stupid password rules. This only makes it so accidental capital letters don't prevent you from logging in.
- mark-r 10y agoMaking a case-insensitive password checker is trivial if the passwords are being compared in plain text, but requires a bit of forethought if you do it with hashed passwords. In particular it's impossible to add this feature after the fact if you already have hashed mixed case passwords in your database. So the likelihood that passwords are unhashed goes way up.