8 ms·
T-mobile password reset does not allow you to type the letter "V"
- seanieb 14y agoWait till this guy figures out that T-Mobile also stores his password in plain text.
- antimatter15 14y agoI wonder if it's a bad idea to disclaim that you store passwords in plain text (when you actually use PBKDF2 or something) to trick users into making more secure passwords.
- jonursenbach 14y agoPersonally, that'd steer me away.
- charliesome 14y agoIt'd be terrible PR though
- milesokeefe 14y agoThe type of users that use insecure passwords probably don't care about or understand the implications of plain text passwords.
- duaneb 14y agoI would just switch carriers.
- shawabawa3 14y agoWhy would I bother making a secure password if it's stored in plaintext anyway?
- Steko 14y agoAnyone know if this is just the US T-Mobile site or do all the Deutsche Telekom properties do this?
- MichaelGG 14y agoApparently to prevent paste. Their CheckEnter.js file has: function keyDown(a) { if (a.keyCode == 86) { a.preventDefault() } } And that's assigned to onkeydown... Funny enough, elsewhere in their code, they do explicitly check for Ctrl & V/C.
- ams6110 14y agoAnd why prevent paste? Just ran into this recently on paypal when I wanted to change my password. I generated one in passpack and tried to paste it in, no can do. Ridiculous.
- machrider 14y agoApple does this, too. Not just on password change forms, but on login forms. Drives me nuts, as I use a password manager and my passwords are 24 characters of garbage. Edit: Apparently I can't reply to the next comment, but keepassx also has the feature that passwords are cleared from the clipboard after 30 seconds.
- Foy 14y agoClearly, having your password on the clipboard is a security issue. Storing your password in plain text, however, isn't. Gotta love half-assed security measures. :)
- SquareWheel 14y agoI ran into this same problem. Had to use the Chrome Web Inspector to get around it. I believe it's a part of PCI compliance, but plenty of sites accept credit cards without that nonsense so I'm not sure. GetGamesGo.com does the same thing.
- tedunangst 14y agoPlease, in the future, whenever talking about PCI compliance, cite chapter and verse. There's more than enough wild speculation running around about it, all sorts of myths are repeated and propagated.
- andrewcooke 14y agowhy would you want to stop paste? don't mobile devices have things like keypass? (i don't own a smartphone, but paste all passwords on my computers).
- jschmitz28 14y agoIt makes sense to paste your password when logging into an account, but from what I read this is just on the password reset. They probably want people to actually type their new password twice instead of typing it once and then copy/pasting for the second field.
- LoganCale 14y agoWhat about people who use password managers to generate random passwords and paste them into the fields?
- tedunangst 14y ago0.0001% of the people get 0.0001% of the love.
- jfb 14y agoIt's not insane, but it does increase the burden on those of us who use password generators. There is NO excuse for the sloppiness of the implementation, however.
- scjody 14y agoPayPal does this too. I don't get it. (Other than PayPal are jerks anyway so this fits.)
- untog 14y agoTheir entire site is a really bad example of ASP.NET development. As someone who knows the technology well, it can make great sites. It just rarely does. I like my T Mobile service but there's something odd with their backend systems and/or customer service. I logged in to disable their "WebGuard" service that seemed to be blocking pages at random. It required address and social security verification, but I couldn't get it to verify my details. I called, and the customer service agent hopefully told me that my address didn't exist. I live in the middle of New York, and I've never had this issue before. I can't help but wonder what crazy verification system they're using.
- heretohelp 14y ago>As someone who knows the technology well, it can make great sites Example?
- joshu 14y agoOrkut!
- glassx 14y agoOnly up to 2006, at least according to this link: http://www.quora.com/Orkut/Why-was-Googles-Orkut-built-on-ASP-NET http://www.quora.com/Orkut/Why-was-Googles-Orkut-built-on-AS...
- untog 14y agoStack Overflow, for one.
- nopal 14y agoSO is built with MVC, which encourages good development practices. T-Mobile looks to be using Web Forms. I'm sure there are good sites out there that use Web Forms, although as a .NET developer, I've found a that Web Forms encourages practices that I consider bad.
- skanuj 14y agoTry using special characters - It will just omit some special characters and save the password with that character omitted. And yes, T-mobile sent back my password in clear-text, and that's how i know.
- agildehaus 14y agoI learned this too recently when my password, which starts with a special character, suddenly was being rejected. Turns out they use a Javascript validator on passwords, not only at creation, but also when you're logging in (beats me as to why). I found a page on their site that doesn't do the check and I can login fine there. Storing the password in plain text is absolutely inexcusable. I'm an idiot and my passwords are stored PBKDF2/SHA512 - not like it's difficult.
- madmaze 14y agoalso interesting is that t-mo will truncate any password at 15 characters without warning and then only accept 15 upon login.. At least that was the state of things about 2 weeks ago
- troels 14y agoMy guess - varchar(15) Adobe does the same thing with the horrible license-management selfcare site. Which, as far as I can tell, is some kind of SAP frontend.
- machrider 14y agoT-Mobile also capitalized my password on me, once. It was fine for a couple years and then one day it stopped working. I got the site to text it to me (why do they even have it in plain text?) and all the letters had been capitalized somehow. (Previously was mixed-case.)
- deleted 14y ago[deleted]
- BryanB55 14y agoI hate when people disable pasting in password fields. Some of my passwords are 50 character random strings stored in 1password and sometimes I need to copy/paste and can not do it (ahem, icloud). I usually end up disabling javascript if the page still renders without javascript.
- jrockway 14y agoAssuming you're on Linux, you can just pipe the input into "xargs xdotool type". Thanks to the keyboard abstraction in X, no program will ever be able to tell that you didn't just type that on a keyboard.
- jedbrown 14y agoUnfortunately, xdotool type is schizophrenic with multiple keyboard layouts http://code.google.com/p/semicomplete/issues/detail?id=13 http://code.google.com/p/semicomplete/issues/detail?id=13
- jrockway 14y agoAn admittedly obscure corner case. (Though I'm not defending the X keyboard API. Linux input is a nightmare. I especially like the hard-coded list of keys in the kernel, limiting the number of unique keys that any userspace application can address, even though it's perfectly possible to plug in 128 keyboards each with several hundred keys.)
- jlgreco 14y agoIf you are on linux, chances are you can just middle-click.
- yaix 14y agoOr just click the password field -> Menu [Edit] -> [Paste]
- rat87 14y agoThis might be a good place to complain about -ed out passwords on mobile phones. It makes it next to impossible to enter a password(yes the last letter not -ed out for a few seconds only helps a tiny bit). If I'm not copy-pasting from keepass I'm entering the password in the login field then cut/paste it.
- deleted 14y ago[deleted]
- deleted 14y ago[deleted]
- rat87 14y agostarred out. markup ate starts.
- morsch 14y agoI think having the last letter visible for a very short time is a good balance. I certainly do not want the password to be visible in clear text. Shoulder surfing is an even bigger issue for mobile devices like phones or tablets -- which you routinely use in public and around strangers -- than it is for laptops or desktops.
- drzaiusapelord 14y agoI like to end my passwords with non-alphas like "!" Neither tmobile or at&t let me do this for whatever reason. Its incredible how telcos get away with everything from high pricing to shit web code. These are the mistakes of self-taught amateurs, not professionals.
- pyre 14y agoSometimes the restrictions are due to interfacing with legacy back-ends. No a great excuse, but at least more understandable.
- gnu8 14y agoWhy are web pages still allowed to interfere with keyboard input like this?
- mryan 14y agoBecause the ability for JS to 'interfere' with the keyboard input enables some very useful features. e.g. using keyboard navigation in web apps.
- greesil 14y agoBecause V is for vendetta?
- scorcher 14y agoI'm not surprised. I got the expiry date of my credit card wrong. It stores it and will not let you change overwrite or delete it. In the end I just had to top up offline till I could move carrier.
- samuel55 14y agothat is great send me another one in my acount
- samuel55 14y agowow
- samuel55 14y agowow
- samuel55 14y agowow
- samuel55 14y agowow
- samuel55 14y agowow
- samuel55 14y agothats enough mate
- samuel55 14y agothats it i have had enough these emails are stupid dum as