Have they always done this, or is this new?
For those of us who haven't changed our Facebook password in years, does this mean that we don't get this option, or do we? And if we do, is Facebook storing our passwords in plaintext?
Have they always done this, or is this new?
For those of us who haven't changed our Facebook password in years, does this mean that we don't get this option, or do we? And if we do, is Facebook storing our passwords in plaintext?
hash(password)
hash(password-inverted)
hash(password-first-upper-case)
This way it'll work with an inverted password even on the first attempt (after this feature was implemented)Edit: Going by my gut feeling only, this feels slightly more secure too... If the hashed password database is ever leaked, it feels like it would be easier to crack a password given the three related hashes, compared to just the one.
Accepting the entirely uppercased password would significantly reduce the number of unique passwords needed to guess a user's password.
If you want the caps-lock-gives-numerics behavior you need to set your layout to "French — numerical" — its icon is a french flag with 123 at the bottom — instead of simply "French".
Does anyone know the behavior of other operating systems? Or is it an Apple-specific behavior?
hash(password)
hash(password-inverted)
hash(password-first-lower-case)
The first character upper case-case only matters if the first character of the entered password actually is received in upper case, in which case, you'd want to flip it to lower before doing the hash, right?I think that first step (un-hashing) is impossible for a cryptographically secure hashing algorithm.
Edit: archivator explained it me :)
Also, inverting a hash function is impossible (the size of the range is less than the size of the domain). Finding a collision, on the other hand, is not.
Even if that tale is apocryphal, the underlying moral is true - your security is greatly undermined if you reuse your password (or key) across sites - any malicious site operator (or even an honest one that has their security broken) will expose you.
Your browser doesn't do any hashing, it doesn't (and shouldn't) know about whatever password hashing scheme is happening on the server.
This is how sites can (but shouldn't) store passwords in clear text, because that's how they get them in the first place.
I think it would be worrisome if there weren't protective measures already in place, such as limited login attempts, two-factor auth, and so on.
The other weakness would be the repetition of that password on sites that place a low priority on, or are ignorant about, security. At which point, it doesn't even matter.
I was confused until I realized the caps lock case only applies to Windows users.