3 ms·
This justification actually makes some sense to me (Software engineer familiar with crypto.) If an attacker already has access to the password hashes, then yes
by darken 12y ago
This justification actually makes some sense to me (Software engineer familiar with crypto.)
If an attacker already has access to the password hashes, then yes, they can brute force any 8 character case-insensitive password easily.
However, a brute force "try to login to their site" attack isn't feasible without hitting a rate limit or alarm: (26+10)^8 = 2.8*10^12 is still a lot of attempts to login to an account.
The weakness to this model is the password. It is easiest to guess your password if it was the same one on your Sony account (i.e. leaked). However, if you're forced to pick a unique password just for Schwab, it's immune from the most common [citation needed] attack on passwords. Also, it makes the Schwab password useless for hacking other databases, making user passwords a less valuable target for hackers.
If the tradeoffs are worth it: I have no idea, but it's not without merits. I personally like using a password manager with 2-factor authentication and generating all new random PWs for my accounts. I generally don't use more than 8-character passwords, since they're isolated from each other anyways. I would be negligibly less secure using this with Schwabs constraints than other sites, as the security lies in isolating passwords. (I use https://lastpass.com/ https://lastpass.com/)
- newman314 12y agoWhy 8? IIRC it is now recommended to do 10-12 (at a minimum) and since it's autogenerated, might as well make it 20+chars if the site will accept it. Also, you are assuming that Schwab rate-limits login attempts. Given their dismal password policy, do you think that's a safe/reasonable assumption?
- bdhe 12y agoHowever, if you're forced to pick a unique password just for Schwab, it's immune from the most common [citation needed] attack on passwords. Also, it makes the Schwab password useless for hacking other databases, making user passwords a less valuable target for hackers. I'll give you points for honesty on the [citation needed], but your entire argument hinges on this point and there's no a priori reason to follow your assumption. Moreover, your idea of each website having a unique set of constraints to force unique passwords scales horribly from a user perspective. 10/10 for a devil's advocate answer.
- ossreality 12y agoYou have to be kidding me. Too bad you used a throwaway so we can't look out for you to avoid hiring you.
- CamperBob2 12y agoRate-limiting is important, and almost universally practiced, but it doesn't have anything to do with the problem with short passwords. When the password database inevitably gets hacked and uploaded to Pastebin, it's too late for rate limiting.