5 ms·
My favorite bit: "Passwords may contain no more than two identical consecutive characters in any position from the previous password". How would they know that
by billybob 14y ago
My favorite bit: "Passwords may contain no more than two identical consecutive characters in any position from the previous password".
How would they know that unless they have your previous password in plaintext?
Security Fail
- chris_wot 14y agoNot to mention they know the names of your pets :-)
- NLips 14y agoThey could store a hash of your old password, along with 40 hashes, one for each character, hashed against the hash of the old password. e.g. 'this_is_my_password" => hash1 'hash1_t' => hash2 'hash1_h' => hash3 etc This way, when you enter the first character of a new password, they can hash it against your old password, see if it creates hash2 and refuse permission to use the new password. Hopefully this is the same way as websites can ask for only selected characters from a password when you log in.
- teraflop 14y agoThat's functionally equivalent to storing the password in plaintext. The individual letter hashes would be trivial to reverse.
- NLips 14y agoIt would be _easier_ - you still need to know the hashing algorithm and salt. I suppose since it's the TSA, they may use encryption and an HSM instead of hashes.
- Robin_Message 14y agoKerckhoffs's principle: A cryptosystem should be secure even if everything about the system, except the key, is public knowledge. So you can assume the algo is public and the salt too (assume someone has a dump of your source code and your database - how do you keep the salt secret? You can't. This is the case where all the effort to protect passwords and use strong hashes is aimed at.) The solution of "enter your old password" when you enter the new one is simple and doesn't compromise security.
- NLips 14y agoI agree, but "password is not secure if everything about the system, except the key, is public knowledge" is better than "password is saved in plain text".
- kristianc 14y agoShould we also be worried then about Facebook, which also stores previous passwords?
- statictype 14y agoIf your Facebook password and banking passwords are the same, or you believe your Facebook password is actually protecting anything you do there, then yes, you should be worried.
- mkjones 14y agoI'm curious what you mean by that. I work on security at Facebook (and actually help with the system that detects malicious logins), and think we have a pretty good / secure login system, even compared to a lot of banks. The odds of a phisher who knows a bunch of valid Facebook credentials getting into any significant percent of the corresponding accounts are pretty low. EDIT: If you want more protection than this, you can also turn on 2-factor authentication for your account, with "Login Approvals:" https://www.facebook.com/settings?tab=security§ion=approvals&view https://www.facebook.com/settings?tab=security§ion=a.... I don't think I have the ability to do this at login time with my bank (though they do offer / require it when taking high-risk actions like initiating transfers). All that being said, you're absolutely right that sharing passwords across sites is a bad idea.
- tnorthcutt 14y agoThanks for the two factor info and link. I wasn't aware that was available.
- mkjones 14y agoGlad it's helpful! If that's too hardcore for you, check out "Login Notifications" as well (on the same page). This sends you a text whenever someone logs in from an unrecognized browser (but allows the login).
- jsight 14y agoThat requirement actually isn't as rigorous (or as difficult to implement) as it sounds. The keyword there is "password" instead of passwords. Based upon similar systems, I feel comfortable that this is not a typo. Whenever the user changes a password, the user has to provide a (single) previous password. This password is hash-checked against the current user password. Then the password duplication rules are applied. (Note, none of the above should be construed as an indication that I agree with this approach to password policy :) )
- billybob 14y agoVery good point. If they make you enter your previous password as you change it, my criticism is invalid.
- Androsynth 14y agoWhenever the user changes a password, the user has to provide a (single) previous password. What about if you forgot your password? (which I feel is the scenario I usually change a password in) Do they just ignore that rule in that case? If so, whats the point of having the rule?
- Ideka 14y agoThe fact that you know your password is what identifies you as the legitimate owner of your account. If you forget your password, you can't identify yourself as the legitimate owner of your account and thus, to the eyes of the system, you aren't. And about the only person who should be able to change the password of an account is its legitimate owner. So, to answer your question: Do they just ignore that rule in that case? That case should not even happen in the first place.
- chris_wot 14y agoThat's ridiculous. It is extremely easy to forget your password, that situation does happen and resetting passwords should be catered for in the system. Your premise is basically false. A system administrator should be able to reset a password.
- kahawe 14y agoDon't be so quick to judge. Believe it or not, it is not so uncommon for LargeCorps to store passwords in a way they can be retrieved again at least in one place - which is usually their central identity management system. This helps them enforce password policies and expirations across a wide range of systems and gives them better control and overview of all the many user accounts lurking around on all their systems. And obviously being able to make sure all accounts of a user are properly locked or deleted is more important to them than giggling at centrally storing potentially tens of thousands of passwords. The system I know and maintain stores your current password and history in an encrypted form and protects them through various means, so if you got a full DB dump you would still have to brute-force. Works pretty well for us and the advantages seem to greatly outweigh this downside of having passwords stored somewhere in a retrievable form. Plus in typical LargeCorp you have (more or less) sophisticated logging and monitoring tools on top of that so a lot of suspicious activities are detected pretty well. And there are a LOT of other LargeCorps I know of which are using that same product and on a global scale. So, such a system is definitely overkill in ye-old startup webshop, if only for the insane bucks it costs, but for LargeCorps with way too many systems piling up it can be very valuable.