4 ms·
It is so unlikely that they would throw away half of the key space if they were really committed to doing things the right way (hashing/salting). It is more li
by slumdev 7y ago
It is so unlikely that they would throw away half of the key space if they were really committed to doing things the right way (hashing/salting).
It is more likely that they are storing everything in upper case plain text or in a DBMS that ignores case.
- kedean 7y agoThere's a middle ground where part of the bank wants to do things right, and the other half wants customers happy now. As a pure hypothetical situation, if the old system was terrible and, say, stored things in plaintext and did case-insensitive password lookups, then the new system needs to emulate that if they don't want to piss off existing customers by making their old password suddenly not work. The security side is going say "just have customers make new passwords", the business side will say "we won't budge, this has to be seamless", and the developers will settle with the crappy middleground of uppercasing everything before hashing to emulate the old system. Maybe they even maintain naive hope of improving the system down the road and convincing the next set of execs that its ok to revoke everyones password to allow them to better the system.