5 ms·
I did report this a while ago to Schwab both over the phone and on Twitter and I have been equally ignores. Thanks for writing a blog post about it. Edit: forg
by spac 12y ago
I did report this a while ago to Schwab both over the phone and on Twitter and I have been equally ignores. Thanks for writing a blog post about it.
Edit: forgot to mention that the passwords are case insensitive!!!!!!
- spac 12y agoHere's the tweet https://twitter.com/stefpac/status/455132477724852224 https://twitter.com/stefpac/status/455132477724852224
- cdolan 12y agoYou are factually incorrect that the passwords are case insensitive.
- spac 12y agoFair enough: Schwab's login mechanism ignores the case of the passwords.
- AjithAntony 12y agoVerified, mine is case-insensitive. If phone-keypad-password-entry is a requirement, then that makes sense.
- cdolan 12y agoIm confused, are you verifying that the passwords are or are not case sensitive? Mine is certainly case sensitive (watch me get hacked now, 8 characers, one is capital!)
- AjithAntony 12y agomine is case-insensitive It is possible there are more than one schwab interfaces that behave differently. I have two entry points. One for just 401k (https://www.schwabplan.com https://www.schwabplan.com). That one has long case-sensitive passwords. The brokerage account(https://client.schwab.com https://client.schwab.com) is short and case-insentive
- gknoy 12y ago"Case sensitive" means that it matters whether you keep characters matching the same case. So, let's imagine a hypothetical service: # This should work for any such service: Service.set_password('MyPassword') Service.verify('MyPassword') Logging in with the mixed-case password (which should, of course, work) does not tell us anything about whether it's case sensitive. However, if alternate-case verisons of your passwords work, your service has case insensitive password: # These fail if a case-sensitive service Service.verify('mypassword') Service.verify('MYPASSWORD') If we can give it either too many or too few characters, then they are likely truncating your password before storing/testing it: # They drop characters if these work: Service.verify('My') Service.verify('MyVoice') Edit: And, in case they are trying to be nice and allow you to log in with your phone, they might do something lame like store your password as the numbers-you-would-type, rather than the actual characters, in which case this might work: # I hope not: 'mypassword' phone pad digits Service.verify(6972779673) # Even worse, if they might store only the first digits: Service.verify(6972) Apologies if I've made any typos, but I hope that clarifies how one might verify that passwords are treated as case sensitive or not.