4 ms·
It's not that they don't care, they are managing support headaches, and balancing risk to reward. 6 Character AlphaNumeric for Schwab is because they use the s
by brandon_wirtz 13y ago
It's not that they don't care, they are managing support headaches, and balancing risk to reward.
6 Character AlphaNumeric for Schwab is because they use the same password for phone, and this is a throwback to a "Pin". They could at least be honest that this is why it is what it is. The Fobs they send that generate a random number to go with your login make this not a deal breaker for me.
Microsoft is balancing support with security. If you can have a 32 character password it is more likely to be forgotten. But that isn't the real "Support" cost it is DDOS attacks. Computing a hash of a 128 character password is more expensive than doing a 16 character password. This makes it possible to bombard their servers with a Hotmail address you know to be real, and an imaginary password which they have to compute and check the hash for.
- shawabawa3 13y agoBut that isn't the real "Support" cost it is DDOS attacks. Computing a hash of a 128 character password is more expensive than doing a 16 character password. I'm sorry but this is bullshit for so many reasons. 1. There is no way hashing 128 characters instead of 16 is so much more expensive that it enables an otherwise infeasible DDOS 2. Passwords should be salted before hashing, so you're adding (hopefully) at least 30 characters of salt to the password anyway. 3. Hashing should be expensive. You should be using bcrypt or some other algorithm with a work factor to protect against brute forcing if your database is compromised. The real reason is likely a mix of legacy code and extra support from people forgetting passwords, and just plain ignorance from the developers
- Evbn 13y agoHashing passwords intentionally slow for security. The solution to a DOS like this is to ignored all password attempts after N per M time.
- samegreatsleeve 13y agoThat's like saying to get someone to stop punching you, just punch yourself. DOSing yourself to stop a DOS :/
- harshreality 13y agoNope, what typically happens is the account gets locked out and requires a confirmation sent to the account's email address to unlock it.
- samegreatsleeve 13y agoSo a soft DOS then. Not much of a solution, still fully exploitable.
- rcxdude 13y agohow so? cutting off an IP after many failed passwords is good security anyway. Only side affect may be if someone's machine is infected and taking part in the attack they get locked out while it goes on.
- samegreatsleeve 13y agoHe didn't say cut off an IP address.
- happimess 13y ago> If you can have a 32 character password it is more likely to be forgotten. I disagree. There are many long passwords that are easier to remember than a short password. Just to make up an example, I might use "WakeGrindTampInfusePourSip" as a password--it's the sequence of actions that lead to my morning caffeine fix. Compare that to a password that must be between 6 and 12 characters, with one lowercase letter, one capital letter, one numeral, and no special characters. Nothing in my life maps readily onto that schema except for my AOL password from 1996, so I'm going to make something up on the spot, forget it immediately, and rely on the password reset functionality every time I want to log in.
- DanBC 13y agoMicrosoft needs to buyout and then supply a stupidly simple, easy to use, password manager. They need to test is against hoardes of naive users. They need to encourage those users to have one long strong password to unlock the safe, and then to have strong random passwords for everything else. Having seen how some computer users operate I guess any OS supplier has a hard job here. See, for example, the 'power users' who turned off UAC.