Stop restricting my password - Help these sites get better security.
weakpasswords.org
weakpasswords.org
Would be cool if that was added as a column here. I'd submit some sites.
That will tell you whether they send the password in clear, not whether they encrypt it. The only information you'll have is:
IF (they send you the password in clear) THEN (they don't use a one-way hash)
There is no other information to be derived from this method of checking.
(? as my knowledge on security is somewhat limited)
> But if they use a two way cipher and the server is compromised one would presume the mechanism for un-encrypting [decrypting] the passwords would also be compromised meaning it is almost as bad?
It might be. It is conceivable that a site may use public key cryptography and store encrypted passwords, but have password recovery done on an independent system which has the decryption key.
(For our purposes, a "reset question" might also be considered a password because it is still something "you know" and to be differentiated from an email address which would be something "you have")
Nevertheless, the idea of a password question is so useful that I still support it on my sites. But our implementation is open-ended: you define your own question as well as its answer. I think this is better for anyone who is security conscious, but unfortunately it still allows the lazy or ignorant to be insecure.
However, a mechanism for sites that use the standard questions is to manufacture a set of fictitious names and use those everywhere. e.g. Father's name - "Keyser Soze". First car make and model, "Millennium Falcon", etc.
There is the overhead of remembering these but that is not too hard with some thought and repeated use.
Personally, I think it's overkill, but I'll admit that I wouldn't envy anybody tasked with getting someone's account.
First you enter a password, and you get a challenge code back. You insert your card into a device they send you, then enter the pin and the code. The device displays a response code that you enter into the website.
If I want to use my card at an ATM say, they require me to use a different PIN.
It's really just laziness and incomptence on the part of the programmers.
I agree, the only rationale I can think of for this is that these institutions don't want people to forget their passwords, but even then I don't understand why they would want that at the expense of security.
You could use "thecatsatonmybluesuedeshoes", but that may be harder to type accurately.
So let's cap the length at 100k characters and call it a day.
(Length also has almost nothing to do with SQL Injection, and you're plugging a raw password into an SQL query you're doing something very wrong anyways).
No, they should be using bcrypt. You didn't think you'd get away with this by posting after tptacek's bedtime, did you?
Google, MSN, Facebook, Twitter - They all already allow
you to use anything you want for your password.
This is not strictly true - while Google et al might have a large set of permitted characters, there are nearly always restrictions on length. Google, for example, requires that their passwords be at least 8 characters long. While a long password does reduce brute-force attacks and shoulder-surfing, it nevertheless is a restriction.The site for my credit card requires a password that is no more than 6 characters -- talk about insecure.
Not necessarily. Oftentimes banks will set a hard limit on the number of unsuccessful attempts you can make before they lock you out entirely. Then you have to phone them and jump through a number of hoops to prove you are who you say you are, and then reset the password. If they do a really good job preventing brute-forcing, then having an un-brute-forceable password is not necessary any more.
The easiest example of this is debit card PINs. They are usually only 4 numeric digits, and yet are trusted by banks for direct access to accounts. This is because a) banks have sophisticated systems to track brute-forcing and other kinds of abuse, b) longer pins are more prone to being written down, forgotten, and mistyped, and c) there are limits on how much you can purchase / take out per day, limiting the potential damage.
PIN requires you to possess a card with the account details and relevant security data. Yes they're clonable but you can't do a distributed attack on thousands of accounts that way.
Online, as many banks have leaked customer data, one can use a botnet to try common passwords against thousands of customer accounts (you may need to get account data elsewhere to do this or customer numbers may be guessable). 6 chars severely limits the passwords to try.
Though to be fair, they ask additional security questions if you haven't previously logged in from that browser.
Account creation at ING is also awful. I created my account, but did not yet "activate" it. Keep in mind that it did not tell me in any obvious way that I needed to take extra steps to activate the account. Once I tried to log in it started asking me questions like "What is your father's father's name?" and my answer was: you cannot possibly know that yet since I haven't told you. Eventually I figured that out.
Next comes the verification of my checking account. This was fun because I have a joint checking account and a joint ING account. Guess what: it made me AND my wife verify the same exact transactions. Seriously? It's just bad UX all around. Now that I've got it set up I am fine with using it, just the initial process was awful.</megarant>
He couldn't care less. So I asked him to file a formal complaint about this point. I doubt he did.
For those that want to know more about InSecureCode: http://www.mastercard.com/us/personal/en/cardholderservices/...
It is actually kind of secure because the card processor never gets or knows your extra code, but the implementation is atrocious since it requires the website wanting your money to display a webpage from your bank. The odds of that page integrating nicely with the website's payment flow is kinda non-existant, and always sets my fraud alert spinning.
They require you to enter a SkyMiles number and a PIN, along with your last name... all of which is certainly not very secure information. But ultimately, all that gives you access to is viewing a person's SkyMiles account. It hardly seems to make sense alongside banking sites.
Voted for Amex (twice). I'm always annoyed that the 8-character limit prevents me from using my normal password + PwdHash.