6 ms·
Actually, I don't see that as a big deal. Maybe it could be tweaked to have only the first one sensitive or try the all-caps/no-caps. But still, it's all in the
by g0su 14y ago
Actually, I don't see that as a big deal. Maybe it could be tweaked to have only the first one sensitive or try the all-caps/no-caps. But still, it's all in the length of the password. I prefer to have that rather than someone forcing me to use a 6-8 characters password with at least one cap, one special or any of this bullshit.
- frio 14y agoI would be very interested, however, to know what this implies about the way they store their passwords. If, on submission, they normalise the case it and then hash it (and then for all checks, normalise the supplied pw)... then, it's still not really acceptable, but at least the password I've given them is encrypted.
- ubercore 14y agoPedant alert! Hashing is not encryption.
- SquareWheel 14y agoHashing is one way, and encryption is two way -- correct? edit: Might as well look it up. The user "bestsss" at Stack overflow confirms this is the case. http://stackoverflow.com/questions/4948322/fundamental-difference-between-hashing-and-encryption-algorithms http://stackoverflow.com/questions/4948322/fundamental-diffe...
- lawnchair_larry 14y agoPedant alert, hashing is still a form of encryption. Take a look at what crypt(3) used to do ;)
- deleted 14y ago[deleted]
- GuiA 14y agoWhy isn't it acceptable to normalise the password and then hash it, compared to just hashing it?
- deleted 14y ago[deleted]
- frio 14y agoBecause the search space for brute-forcing a password is massively reduced :). Suddenly, instead of having 62 possibilities per password character (assuming alphanumeric + no specials), there's only 36. Whereas a password like "PassWord123" might have gotten past a wordlist (well, that's unlikely, but...), "password123" certainly wouldn't.
- GuiA 14y agoThanks!
- baddox 14y agoWhy isn't that technique (normalizing then hashing) acceptable? There is always a compromise between user experience and security. Why allow three character passwords, or passwords of "password", but not case insensitive passwords?
- Zimahl 14y agoYou are correct, this is less than a big deal. In fact it's pretty irrelevant. Third parties hacking battle.net accounts aren't doing so through brute force, they are doing it through phishing and viruses with keyloggers.
- lawnchair_larry 14y agoThis is kind of important. I will reserve "big deal" for other infractions, but it's far from harmless. It's important to protect your users passwords regardless of whether phishing them directly is the more popular attack. If you don't know why, just ask Sony and Valve.