3 ms·
> In fact the only real possibility that leaves any credibility whatsoever is that the stored password is being decrypted then compared to the password provided
by codeka 14y ago
> In fact the only real possibility that leaves any credibility whatsoever is that the stored password is being decrypted then compared to the password provided at logon using a non-case sensitive comparer.
You can do case-insensitive passwords with hashing/salting. It's just a matter of lower-casing the password before hashing it. (Edit: I'm not saying this is a good idea, of course!!)
I remember reading once that Facebook actually hashes multiple versions of your password (eg with the first letter upper-cased to handle the case where a phone auto-corrects it, and also with all character cases toggled to handle the case when you left caps lock on). I wonder if there's any statistics about how often this kind of thing actually helps?
Of course, it seems pretty clear in this particular case that Troy is right and they're just storing your password in a case-insensitive database column.
- gizmo686 14y agoIf you want hash based passwords to be case insensitive (or have case insensitive characters) You should convert the case before you hash on login. Saving every hash makes it easier for an attacker to find a collision.
- tbrownaw 14y agoDoes it really? What matters is NUM_POSSIBLE_KEYS / NUM_SAVED_HASHES, saving hashes for multiple casings of the password can't possibly increase the number of hashes by more than lowercasing the password would decrease the keyspace by.
- gizmo686 14y agoYou're right, I was thinking that the attacker didn't know the publicly available information that passwords were case insensitive. However, I would still be concerned that it unnecessarily increases the chances to exploit some weakness in the hash algorithm.
- polshaw 14y ago>Facebook actually hashes multiple versions of your password (eg ... when you left caps lock on). Detecting if capslock is on with javascript (in a round about way) would seem to be a much better solution for this case.