3 ms·
This is a terrible idea - incredibly easy to bruteforce, among other things. You now have effectively a two-character password, and even though those character
by Firehed 14y ago
This is a terrible idea - incredibly easy to bruteforce, among other things. You now have effectively a two-character password, and even though those characters rotate based on a different set of criteria, the number of valid possibilities is still limited by the length of the full password.
Yes, it also means they're storing your full password in some sort of reversible format. We can't be sure it's plaintext, but given their roll-your-own approach to security that's probably the case. I understand that they're trying to cut back on the damage a keylogger can do and I commend them for that, but they've lowered the overall security of the site in attempt to increase the security in a corner case. More to the point, if a keylogger is installed, the whole system is compromised which means they'll eventually get the entire password even if it's only a couple of letters at a time.
The only effective solution to this problem is real two-factor authentication. Not this password plus "is this your image?" or "security question" crap that a lot of banks employ: that's two-step, one-factor authentication (both are things you know), but a real second factor based on something you have (RSA token, etc.) or something you are (eg. biometrics, which is obviously impractical on the web)