3 ms·
Let me guess... is it a bank? One of mine's does it (expires session after a few minutes, even actively using it). I find that bank websites usually follow com
by nidble 3y ago
Let me guess... is it a bank? One of mine's does it (expires session after a few minutes, even actively using it).
I find that bank websites usually follow completely opposite ways regarding to security than any other industry: very short passwords, only digits, not encrypted in db (some sites ask for single positions), mandatory password input by virtual keyboard, cannot use password managers, not using 2FA or only allowing SMS instead of TOTP or other methods, etc...
- rrrpfb11 3y agoRe single positions, my bank requires a password (which one hopes is appropriately hashed and so forth) plus a challenge to supply requested offsets into a secret phrase. That mitigates I suppose against over the shoulder attack. And they have fewer requirements of the phrase so maybe it’s less likely to be written down? I’m curious whether there’s a technical means to allow the challenge by offset without storing the phrase plain text. I’m challenged for four positions - in theory it could store hashes of all possible four offsets, but is there a better way?
- GoblinSlayer 3y agoSplit the secret into characters then compute verifier bytes for each character: verifier[i]=hash(pepper,salt,i,secret[i])[0]