4 ms·
So you're still storing part of the plaintext... That's still insecure Plus, the keylogger could just collect a few logins and it completely defeats the whole
by IAmLiterallyAB 8y ago
So you're still storing part of the plaintext... That's still insecure
Plus, the keylogger could just collect a few logins and it completely defeats the whole thing, so it doesn't help anyway. It's just terrible, it makes everything worse
- ajuc 8y ago25% of the password. Shouldn't matter that much. And you can change the percentages to for example 10% (asking for 90% of the password each time). Demand slightly longer passwords if that's a big problem. Hm, actually instead of masking the password to defeat keyloggers they could also just permutate the characters. So that you have to enter password in different order each time. But usability would suck so much :) I prefer the masking. Also - universal keylogger wouldn't know which characters of the passwords you were asked for. They would need to make a keylogger designed for this bank website so it can understand which characters you provide. And they would need to update the keylogger with updates on the login website (which preasumably would be written in a way that makes it hard to know which characters these are - for example with randomly generated ids of the input fields and provided in random order then positioned with javascript). I know - security by obscurity. But it does help.
- rhinoceraptor 8y agoI'm sure it will help the bank's helpdesk job security, but not much else. Remembering a specific character of a password is not easy to do, so people will probably type it into notepad and then count to get the right one anyways. TOTP is much more usable, and probably more secure than inventing your own ridiculous partial password scheme.
- ajuc 8y agoYou just spell your password in your mind and when the character is needed you press the key, when it's not needed you don't. The login site looks like this: [x] [ ] [x] [ ] [ ] [ ] [ ] [x] [ ] [ ] [ ] [x] [ ] And when you press a key it jumps to the next empty field.
- gbear605 8y agoI don’t spell passwords in my mind; I have muscle memory for the password.
- ajuc 8y agoWell, yes, it's slower. But not by much. A few seconds.
- gbear605 8y agoSome of my passwords I have memorized only as muscle memory. Without going into too much detail, if I didn’t have a qwerty keyboard, I wouldn’t be able to enter it without a couple minutes of thinking “okay, this key is there on a qwerty keyboard...”
- cbsks 8y agoI have exactly the same issue with my passwords. I can remember what the letters, numbers, and symbols are, but I can only remember which letters are uppercase by typing it out on a keyboard.
- ajuc 8y agoI create my passwords from long, easy-to-remember sentences that I sample to be like 15-25 characters long with capitalization and special characters added in a pattern. Makes it easy to remember the password without muscle memory.
- dpark 8y agoThis means you're re-using passwords. There is zero chance that you remember hundreds of unique passwords for all the different sites you need access to. Good money says that your pattern is extremely predictable and anyone who sees one or two of your passwords has enough context to know the pattern for all other passwords.
- dpark 8y ago