23 ms·
Passwords for JetBlue accounts cannot contain a Q or a Z
- guelo 12y agoMy guess, some kind of harebrained master password scheme for support.
- amichal 12y agoguessing... Touch tone phone keypads dont always show q and z. I suspect that some older JetBlue system allows you to use your password via a touch tone system (with a vastly reduced keyspace)
- elsporko 12y agoThat would also explain the last rule: Cannot contain special characters or symbols (such as !#$@*, etc). It seems to be geared toward those with cell phones but not necessarily 'smart' phones (with full keyboards).
- jamieomatthews 12y agoCan anyone explain why this is? I've never heard a security reason for this.
- eudox 12y agoGuess 1: They append either one of those characters to the password to store some form of information. Guess 2: The characters are column separators in some form of data store.
- ShaneWilton 12y agoOn some older keypad layouts, Q and Z aren't associated with a number. It could be some misguided attempt at backwards compatibility.
- cgtyoder 12y agoShit poor security? It almost sounds like they end up converting the stored password to digits, based on letters associated with numbers on a standard phone (originally 'Q' and 'Z' were omitted). I wonder if they consider 'ad4jmp' and '2ehkn7' different passwords. That would be an interesting test.
- 30thElement 12y agoWhile the other answers about Sabre are probably right, I've heard that banks intentionally have stupid password policies to prevent password reuse. If one bank says "no special characters but most contain a number", another says "must contain a special character, but no numbers", and a 3rd says "must contain a number and special character", they can guarantee that if one of the 3 is hacked into it doesn't compromise people with accounts at all 3 (of course ignoring people using "password" with a 1 or ! on the end).
- frogpelt 12y agoThis would require cooperation.
- jdonahue 12y agoMarketing? A sane password policy doesn't get you to #2 on HN.
- codezero 12y agoMy guess is that this is just a rule to force people to read the rules.
- gedrap 12y agoIt's not an Odesk job post where "please include <some word> in your application" ;)
- seanmccann 12y agoThey use Sabre (like others), and it's an archaic holdover from when phones didn't have Qs or Zs.
- drdeadringer 12y agoToday, I learned that phones didn't have Qs or Zs. Things you don't notice on that one rotary phone your parents used to have when you were 5.
- seandougall 12y agoWell, they had to make room for that tetragraph that has since sadly fallen so out of favor, "OPER".
- michaelmior 12y agoOr the rotary phone your parents still have right now in my case.
- dasil003 12y agoOr the antique Bell candlestick rotary phone that my mom has, still hard-wired into a phone nook inset into the plaster walls during construction nearly 100 years ago. And that bad boy still works flawlessly.
- drdeadringer 12y agoDo they still rent it?
- ryanburk 12y agoI then wonder if these passwords are even less secure since the backend system would have mapped {A,B,C}=1 at some point for the dialer system to work. so my password "CaB" would be the same as "cab" and "CAB" and "ABC" and "111", etc.
- rosser 12y ago
- lvs 12y agoLooks like it has to do with the venerable Sabre system (scroll to bottom): http://kottke.org/12/06/the-worlds-worst-password-requirements-list http://kottke.org/12/06/the-worlds-worst-password-requiremen...
- mikeash 12y agoIt's worth noting that when you say "venerable" you mean it. Basic research for what would become Sabre first started in 1953, development started in earnest in 1957, and it was online in 1960. It's also interesting that the project got its start because an IBM salesman just happened to be sitting next to the president of American Airlines on a flight, and that salesman happened to be working on a massive air defense computer system for the Air Force. Goes to show the power of knowing the right people, or in this case, coincidentally meeting them on a plane.
- fiatmoney 12y agoLess of a coincidence when flying was expensive enough to be reserved for the "jet set".
- mikeash 12y agoNo doubt. Interestingly, this meeting didn't happen on a jet and probably predates the term "jet set", as the first jet airliner had only entered service the year before. The IBM salesman thinks it might have been a DC-6: http://conservancy.umn.edu/bitstream/11299/107637/1/oh034rbs.pdf http://conservancy.umn.edu/bitstream/11299/107637/1/oh034rbs... Interesting little note from that: "I learned later that he would be sitting in his office in New York and he'd suddenly wonder how things were getting along in L.A. He would tell his secretary, "I'm going to L.A." He would go to the airport, just walk on a plane, and fly out without a shaving kit, pajamas or anything. Then he would take a look around and catch another plane back." I doubt many company presidents are taking that sort of approach anymore.
- gress 12y ago
- dragonwriter 12y agoThey also can't contain symbols (so apparently just digits and letters except Q and Z). The combination suggests to me the horrible possibility that they actually reduce the password to just digits for storage, and to support entry on devices that look like old touchtone phones [1] (I say "old" because newer ones usually have "PQRS" instead of "PRS" and "WXYZ" instead of "WXY"): [1] Like: http://www.cs.utexas.edu/users/scottm/cs307/utx/assignment5.html http://www.cs.utexas.edu/users/scottm/cs307/utx/assignment5....
- theboss 12y agoThat's nothing.... A friend of mine forwarded some emails shes gotten from jet blue. First this screenshot: http://i.imgur.com/oKKpFM1.png http://i.imgur.com/oKKpFM1.png Followed by the money screenshot: http://i.imgur.com/DlAlQPt.png http://i.imgur.com/DlAlQPt.png She redacted some of the information before she sent it (obviously). This is from Jan 21 of this year. It's just so sad.... It's incredible people still have plaintext passwords serverside....
- xanderstrike 12y agoDid you tell her to make sure that password isn't used anywhere else?
- theboss 12y agoShe's a computer person too so she knows all this jazz.
- iopq 12y agooh come on, man everyone's sent those emails before you try to do some smart templating, but your designer changes the template and never actually remembers that those were FILLER VALUES
- theboss 12y agoI actually have no idea what you're talking about. All I know is they sent her plaintext passwords to her, which she redacted before sending to me....
- slaundy 12y agoI just changed my Jetblue password to contain both a Q and a Z. Seems the support documentation is out of date.
- eli 12y agoI'd caution against making assumptions about the competence of the developers based only what you can see from the outside. More likely than not there are good reasons to maintain interoperability with legacy systems. This may well be the most elegant way to solve a complex problem. I've certainly written my share of code that would look weird to an outsider who didn't know the backstory and the constraints and the evolution.
- mikeash 12y agoIn this case, a legacy system (Sabre) whose origins predate the integrated circuit. I'm sure a lot has changed since then, but it's a bit scary to wonder what hasn't.
- eli 12y agoI don't find that scary. I think it's a testament to the original architects and to the people who maintain it.
- SnakeDoc 12y agoIt's engineering thoughts like this that continue the proliferation of terrible, and insecure login systems.
- eddieroger 12y agoI'm not sure about that. Sabre is an extremely (assumption) functional tool in an extremely niche market. That makes the barrier to enter it very high, and the barrier to rewrite equally so. Underneath the covers it could be a real piece hung together by duct tape and vacuum tubes, but why rewrite it if it's working and keeping planes in the air?
- fennecfoxen 12y agoBecause OMG HACKERS. Seriously, why do we have any security on anything?
- 12y ago
- jrockway 12y agoShouldn't this mean that the OUTPUT FROM THE HASH FUNCTION can't contain Q or Z!? Certainly no system other than the web frontend would be looking at the password itself...
- maxmem 12y agoAlso no special characters.
- gt21 12y agoHere's a pic of when phone keypads don't have Q and Z: http://www.dialabc.com/words/history.html http://www.dialabc.com/words/history.html
- bluedino 12y agoI feel so old.
- GrinningFool 12y agoThat's ok, here's a better one. etrade - yeah, THAT etrade? Yeah. They make your passwords case-insensitive.
- honoredb 12y agoAs does Citibank. I imagine it's for telling-support-over-the-phone purposes, which isn't great.
- tokenizerrr 12y ago...why would you have to tell them your password in the first place?
- SeanLuke 12y agoUNIX historically truncated passwords to eight characters.
- hamiltonkibbe 12y agoCharles Schwab silently truncates passwords to 8 characters. Always a fun surprise to accidentally enter a password you use somewhere else and get logged in anyways.
- grmarcil 12y agoI complained to them a while ago about the fact that they limit passwords to 8 characters. Must have been two years ago and I got a very generic "sorry, we know this could be better and our engineers are working on it. In the mean time, we'll send you an RSA security token fob for two factor authentication if you'd like". Thanks but no thanks, I'd rather not add another item to my keychain to make up for your website's lackluster password requirements. I never knew that their website would truncate passwords at 8 characters, but just checked and sure enough it works. This is indicative of the ridiculousness of the 8 char limit, but given the 8 char limit, I don't think it weakens their system at all.
- 12y ago
- stephengillie 12y agoWhen I saw the Sabre password requirements, I couldn't help but imagine that passwords are stored entirely numerically - "badpass" would be entered (hashed?) as "2237277", as in dialing a phone. So the password "abesass" would collide with "badpass" and grant access. Has Sabre at least upgraded their storage mechanism, or do (did?) they reduce entropy on passwords?
- 8_hours_ago 12y agoI was also curious about this and decided to test it. I created a new account with the password "badpassbadpass" (minimum password length of 8!), but I was unable to log in with "abesassabesass". There was also no error when I tried to put a 'q' and a 'z' in my password, so I'm guessing that they've updated their system since the documentation was written.
- squeaky-clean 12y agoI just tried it with 'abcabcabc' as my password. It claims passwords are case sensitive, but both 'abcabcabc' and 'ABCABCABC' work and any variation ('ABCabcaBc' works). Variations based on a phone pad don't seem to work. '123123123' or 'bacbacbac' don't work. I also tried only changing one letter. >Must contain one letter and one number Also not true. >Cannot contain three repeating character Also not true. I changed my password to 'qqq123123' and could login just fine. Something like 'zzz123123' does not work. I put way too much effort into this.
- mentat 12y agoSo for all those saying that we should just "trust the engineers know what they're doing" this is a pretty damning refutation as far as I'm concerned.
- taejo 12y agoIt's possible they store both the original password, for use on the web, and the numeric version, for phones.
- coherentpony 12y agohttp://xkcd.com/936/ http://xkcd.com/936/
- jfoster 12y agoIf they were OK with applying more duct tape, why not map Q and Z to characters (eg. A and B) that can be part of passwords? (eg. a password of "quiz" would become "auib") It would make their password system slightly weaker perhaps, since freq(a) then becomes more like freq(a)+freq(q) and freq(b) more like freq(b)+freq(z). I'm not sure that's much weaker than just excluding Q and Z, though. The user experience is improved. The major downside would be in technical debt.
- elwell 12y agoOr you map them to something like: Q = ABDHCJSKJDHSSS Z = YYYDUHUHUHSSYS ... to avoid weakening the password.
- napoleond 12y agoI can't tell if you're joking or not, but for the benefit of people who don't know any better: such a scheme would not meaningfully impact the strength of the password storage scheme at all. (To prove it to yourself, think about how rainbow tables work. Then consider how little additional work would be required to replace all Q's and Z's with the appropriate string before making the table. It's not much different from having a "salt" that's the same for every user in your application, which also doesn't meaningfully impact the strength of the password storage scheme.)
- jpatokal 12y agoActually, it's a classic case of security through obscurity. If the attacker doesn't know about it and are using a standard rainbow table, then no, it's not going to have "ABDHCJSKJDHSSS" in there and it will make their life harder. Once they do find out, though, it's useless.
- georgemcbay 12y agoOr just map them to asterisks, and call it a hunter2 transform... "Cannot contain special characters or symbols (such as !#$@*, etc)" Well, damn! Guess that won't work.
- skizm 12y agoActually this kind of gives me an idea: what if modern systems decided to just tell people they can't use "p" so that people stop using the word "password" or variants as their password. Hell, for that matter, tell users they can't use vowels so they can't make words. They might do leet speak, or whatever which is pretty easy to crack given time, but it stops things like password re-use attacks (people less likely to have the same password as their other apps) and simple guessing attacks (try top 3 most popular passwords on all known emails/accounts). For such a simple rule set (no vowels) it forces a decent level of password complexity.
- daviding 12y agopsswrd123
- stephengillie 12y agoassword123
- vacri 12y agoLooking through old scripts, you'll sometimes see a matching query for "sername", so you get both Username and username (pseudo case-insensitive) and there's usually a second matching query for... "ssword", because removing "P" gives you "assword", which clearly is improper to put in a script! Harrumph!
- DonHopkins 12y agoSounds like that script has a back door.
- barsonme 12y agoOne issue for IT is having employees write down their passwords. I can imagine something like this would have the same effect and probably decrease security somewhat. Although, take what I say with a grain of salt. I'm not sure how prevalent having your passwords physically stolen outside of a closed environment like a workplace is. There are a lot more variables at a job than at my house in my locked drawer.
- bgia 12y agoWhy didn't phone have Q and Z? Everyone is mentioning that they did not have them, but I can't find a reason for that.
- ryanburk 12y agoit was the simplest way to map 3 letters to each number 1-9 on the keypad.[1] that way you didn't have a few numbers with 4 letters and had a consistent model. [1] my grandfather explained it this way back in the early '80s. I couldn't find a good link to a more official source.
- nkurz 12y agoExcept that 3 * 9 = 27, and there are only 26 letters in the English alphabet. They are actually mapped to the numbers 2-9, which leaves the question of why they didn't use 1.
- btgeekboy 12y agoThe local prefixes of phone numbers don't/couldn't start with 1. If you map ABC to 1, you can't use those letters as the start of a word. (Your number could be GET-SOME but not AND-MORE.) This is because when you dial without an area code, your leading 1 would be interpreted as a long distance call. This is the same reason they didn't use 0, as that's the start of an international call (011).
- ryanburk 12y agough, typo. good catch, and good explanation below re: starting a number with an A.
- codexon 12y agowhy not hash the the password and encode it in base34? (36-2)
- manojit 12y agoWhy people are still restricting password complexity. As long as passwords are carefully & cryptographically processed (read hashed with individual salt). I recently designed a system where the only password policy is the length (8 char minimum) and they are stored hashed with salt being a specially encoded user id (thus unique for each user). I also like to contradict myself. Password complexity and and all the policy are needed to make the social engineering not feasible. I mean a strong and secure system and with that people are using 'password1234' is a very bad practice.
- Sami_Lehtinen 12y agoI consider passwords as random blobs of bytes. Everyone says that hashing is important but I don't see any real benefit of it. If I hash random 128 bits result is random 128 bits.
- SoftwareMaven 12y agoIt's important because if somebody gets your database, if you haven't hashed, they have everybody's passwords, and those passwords are often reused many times at many sites. Hashing at least puts a step between stealing your table and knowing everybody's passwords (a mathematically hard step for good passwords). Also, please let me know what sites you manage so I know where my data is not valued.
- Sami_Lehtinen 12y agoMy bank allows only passwords which are six digits like 123456. No longer or other characters or symbols.
- Iterated 12y agoQuestion to all those saying this is because of Sabre: How? Does the TrueBlue password somehow go through Sabre's systems? The truly old business unit of Sabre that everyone is referencing is Travel Network. I'm not sure why an airline's loyalty program would intersect with Travel Network other than through the back end of a booking tool.
- coldcode 12y agoNo, there is no way their loyalty program has anything to do with SABRE, any more than Expedia's passwords are stored in SABRE.
- cosmotron 12y agoI'm guessing that JetBlue allows people to log into their account via telephone. They could map your alphanumeric password to the series of numbers you'd punch in on a phone. Example: the password 'foobar9' could be mapped to 3662279
- deleted 12y ago[deleted]
- dredmorbius 12y agoAs several people have noted, the Q/Z restriction likely arises from inputting passwords from a telephone keypad. What I haven't seen is a statement as to why this would have been a problem. The reason is that Q and Z were mapped inconsistently across various phone keypads. The present convention of PQRS on 7 and WXYZ on 9 wasn't settled on until fairly late in the game, and as noted, the airline reservation system, SABRE, is one of the oldest widely-used public-facing computer systems still in existence, dating to the 1950s. https://en.wikipedia.org/wiki/Sabre_(computer_system) https://en.wikipedia.org/wiki/Sabre_(computer_system) The 7/9 standard, by the way comes from the international standard ITU E 1.161, also known as ANSI T1.703-1995/1999 and ISO/IEC 9995-8:1994). http://www.dialabc.com/words/history.html http://www.dialabc.com/words/history.html Other keypads may not assign Q or Z at all, or assign it to various other numbers, 1 for Australian Classic, 0 for UK Classic and Mobile 1. http://www.dialabc.com/motion/keypads.html http://www.dialabc.com/motion/keypads.html Similarly, special characters can be entered via numerous mechanisms on phone keyboards. My suspicion is that there's a contractual requirement somewhere to retain compatibility with an existing infrastructure somewhere.
- gcb0 12y agoso, they have a requirement to maintain compatibility with telephone password input, but require an uppercase character as well? it does not make any sense. this is incompetent developers in a dysfunctional environment. there is no good light anyone can throw at it. and no, having the system live since the 50s is not a good excuse. it is certainly not the same system, for obvious reason.
- acdha 12y agoConsider how important air travel is and the wide range of situations people use to book or change travel plans. It's completely unsurprising that someone would be reluctant to say that no device or system in use anywhere in the world would have a problem with this.
- colanderman 12y agoThat makes perfect sense. 'A' and 'a' are both on the 2 key, along with 'b', 'c', 'B', and 'C'.
- jedberg 12y agoOne of my bank accounts has the same restriction, so that you can enter you password through the phone system. It's stupid, but at least it has a reason.
- phlo 12y agoAs many sources have pointed, out, this is very likely related to Sabre. Interestingly, there is another reason why such a restriction might be useful: There are three popular key arrangements. English/US QWERTY, French AZERTY, and German QWERTZ. Apart from switching around A, W, Y, Z, and most special characters, they are mostly identical. If your goal is to ensure successful password entry even if a user is unexpectedly using an unfamiliar keyboard scheme, all you need to do is replace all instances of A or Q by one value; and all instances of W, Y, Z by another. Or you could, of course, disallow these characters. I hear Facebook had a similar approach to coping with input problems in the early days of mobile access: for each passWord1, three hashes were stored: "PassWord1" (uppercase first letter), "PASSwORD1" (caps lock) and "passWord1" (unchanged). As far as I remember, they didn't deal with i18n issues -- or publish the results of their approach. Edit: This would, of course, weaken password security significantly. If my very rough back-of-the-envelope calculation is correct, by a bit less than 50%.
- mhandley 12y agoSeems more likely that Sabre's restriction was because old phone dials (and the keypads that replaced them) didn't have Q or Z: http://payphonepictures.com/44631-4/IMG_4953.jpg http://payphonepictures.com/44631-4/IMG_4953.jpg http://www.dreamstime.com/royalty-free-stock-photography-pay-phone-keypad-image1938827 http://www.dreamstime.com/royalty-free-stock-photography-pay...
- tn13 12y agoThere might be some very good reasons why such policy may exist. For example this system may involve telling the password to someone over the phone or using a TV remote to enter a password or some other keypad other than QWERTY.
- kirab 12y agoFor everyone who designs password rules: Please do not require the password to contain uppercase, lowercase letter, numbers and so on. Because this actually makes passwords statistically easier guessable. The only thing you should require is a minimum length, I recommend at least 10, better 12 characters. Even 12 digits are more secure than say "Apple1".
- sp332 12y agoHave you tried it? This person says it works just fine. https://twitter.com/__apf__/status/466327291027804160 https://twitter.com/__apf__/status/466327291027804160 And it doesn't make sense that it's a holdover from phones, because then it wouldn't be case-sensitive.
- eigenrick 12y agoEveryone in the conversation seems to be pointing out the fact that this is due to integration with legacy software. That's not an acceptable reason. In the broader sense, there is a great irony in making password "strength" restrictions, like "must include" and "must not include" because they often end up making passwords easier to brute force. If you start with the restriction that all passwords must have > 8 characters, you have basically an infinite number of possibilities, smart users will use a passPHRASE that is easy to remember. Dumb users will try to hit the bare minimum characters. When you put a restriction of 20 chars, it reduces the possibility that a persons favorite passphrase and guarantees that the set of all passwords is 8-20 characters, which means that the set of all passwords is smaller still. They disallow special chars, which probably includes space, which further reduces the likelihood that someone will pick a passphrase. Disallow repeating characters and you've further reduced the entropy. Disallow Q and Z and it's reduced it further still. I can't be arsed to do the math, so I'll reference XKCD http://xkcd.com/936/ http://xkcd.com/936/ But Sabre would do well to correct this, the optimal case is simply making a single requirement: passwords must be greater than 8 characters. The don't use your last N passwords requirement isn't bad, but people usually find hacky ways around this.
- rjacoby5 12y agoI think everyone is completely missing the reason behind the omission of Q and Z. Due to the database storage engine they chose, it was necessary to put a limitation on the number of Scrabble points that a password would award. Q and Z are both 10-pointers, so passwords with them frequently blew past the limit. You can use J and X, but that's really pushing it. And the "cannot contain three repeating character" rule is due to that being the trigger for the stored procedure that implements 'triple word score'.
- brianlweiner 12y agofor Bank of America customers, you might notice your mobile app requires you to use a password < 21 characters . There is no such restriction for desktop browsers. Attempting to login to my mobile app requires me to DELETE characters from my password until the overall length is less than 21. I'm then able to login. What does this tell us about BoA's password storage?
- DonHopkins 12y agoHow can people that stupid be allowed to operate airplanes?
- r0m4n0 12y agoLooks like they removed this requirement recently. We have JetBlue in our presence :O
- Iciloo 12y agoThe snow glows white on the mountain tonight, not a footprint to be seen. A kingdom of isolation and it looks like I'm the queen. The wind is howling like this swirling storm inside. Couldn't keep it in, Heaven knows I tried. Don't let them in, don't let them see. Be the good girl you always have to be. Conceal, don't feel, don't let them know. Well, now they know! Let it go, let it go! Can't hold it back any more. Let it go, let it go! Turn away and slam the door. I don't care what they're going to say. Let the storm rage on. The cold never bothered me anyway. It's funny how some distance, makes everything seem small. And the fears that once controlled me, can't get to me at all It's time to see what I can do, to test the limits and break through. No right, no wrong, no rules for me. I'm free! Let it go, let it go. I am one with the wind and sky. Let it go, let it go. You'll never see me cry. Here I'll stand, and here I'll stay. Let the storm rage on. My power flurries through the air into the ground. My soul is spiraling in frozen fractals all around And one thought crystallizes like an icy blast I'm never going back; the past is in the past! Let it go, let it go. And I'll rise like the break of dawn. Let it go, let it go That perfect girl is gone Here I stand, in the light of day. Let the storm rage on! The cold never bothered me anyway...