Passwords For Your Facebook Account
labnol.org
labnol.org
Now, the question is, just how much security are you losing by allowing this? Assuming the passwords are stored correctly my guess would be that passwords that are considered secure already would only be marginally less secure because of this, however non secure passwords (common ones) are a hell of a lot less secure but only in a relative context, they're still just as insecure as the original insecure password.
I'm not sure I articulated this properly so if I didn't let me know.
And I agree it's a great UX enhancement. I've been frustrated many times entering usernames and passwords with my phone defaulting to capitalising the first letter.
Now if only they'd strip # from the end of posts again (on UK keyboards at least it's right next to the return key, so many posts end up looking like this#
So, slightly more than one bit of entropy lost?
In fact in terms of relative impact, this has a much greater impact on "secure" passwords (in this case, I mean ones that are a random jumbled set of mixed case letters and numbers). That's only really because it significantly reduces the range of the first character.
Of course, if they implemented this, it would turn it into a case insensitive password with much bigger security implications. So, this isn't a criticism of their decision. Only an observation.
Have they always done this, or is this new?
For those of us who haven't changed our Facebook password in years, does this mean that we don't get this option, or do we? And if we do, is Facebook storing our passwords in plaintext?
I think it would be worrisome if there weren't protective measures already in place, such as limited login attempts, two-factor auth, and so on.
The other weakness would be the repetition of that password on sites that place a low priority on, or are ignorant about, security. At which point, it doesn't even matter.
I was confused until I realized the caps lock case only applies to Windows users.
hash(password)
hash(password-inverted)
hash(password-first-upper-case)
This way it'll work with an inverted password even on the first attempt (after this feature was implemented)Edit: Going by my gut feeling only, this feels slightly more secure too... If the hashed password database is ever leaked, it feels like it would be easier to crack a password given the three related hashes, compared to just the one.
I think that first step (un-hashing) is impossible for a cryptographically secure hashing algorithm.
Edit: archivator explained it me :)
Also, inverting a hash function is impossible (the size of the range is less than the size of the domain). Finding a collision, on the other hand, is not.
Even if that tale is apocryphal, the underlying moral is true - your security is greatly undermined if you reuse your password (or key) across sites - any malicious site operator (or even an honest one that has their security broken) will expose you.
hash(password)
hash(password-inverted)
hash(password-first-lower-case)
The first character upper case-case only matters if the first character of the entered password actually is received in upper case, in which case, you'd want to flip it to lower before doing the hash, right?Does anyone know the behavior of other operating systems? Or is it an Apple-specific behavior?
Accepting the entirely uppercased password would significantly reduce the number of unique passwords needed to guess a user's password.
If you want the caps-lock-gives-numerics behavior you need to set your layout to "French — numerical" — its icon is a french flag with 123 at the bottom — instead of simply "French".
Your browser doesn't do any hashing, it doesn't (and shouldn't) know about whatever password hashing scheme is happening on the server.
This is how sites can (but shouldn't) store passwords in clear text, because that's how they get them in the first place.
[1] http://blog.agilebits.com/2011/09/13/facebook-and-caps-lock-...
The slight benefit of this being that if your database is leaked, then the attacker won't have his/her brute forcing job made easier by knowing that the password3 hash only contains lowercase alphanumeric characters.
Edit: Apparently I suck at reading, it's not upper() and lower(). Woops :). Well, if any other sites do store upper() and lower() variations, I wonder if they use this idea?
(To get inverse password you simply reverse the case on all letters.)
It's just a dumb philosophical thought I had.
On a Mac, shift with caps-lock on doesn't toggle to lower-case, so they would need to store a fourth version for this to work.
OPERATI@NGERONIMO
Overall it's a clever UX hack, though I worry they came to it by observing invalid password attempts which seems slightly outside of appropriate, although it doesn't particularly bother me in this case.