Live data from Hacker News

Stop restricting my password - Help these sites get better security.

weakpasswords.org

11–20 of 61 posts

Re: Stop restricting my password - Help these sites get better security.

#11
I like the idea. I think it would be nice to also include sites that store passwords in plain text. I always email sites if they send me my password in plain text. Half the time they reply and say it's not really so bad. Half the time they reply and clearly don't understand why I would even care. I've yet to see anyone admit that it's a problem. If we get could get that solved, that would really be nice.

Re: Stop restricting my password - Help these sites get better security.

#12
post #8

ING's isn't a password it's a PIN number. That's why you can't use any letters or special characters.

That is kind of true - ING do call it a PIN. The thing is that all I can do with the PIN is to log on to their online banking site. That makes it a password in my opinion.

If I want to use my card at an ATM say, they require me to use a different PIN.

Re: Stop restricting my password - Help these sites get better security.

#13
post #3

I believe that the logic behind ING direct is that by requiring you to use a mouse to click out your password it prevents key sniffers. And they show you a keypad being a bank.

There are banks that do this, but provide you with the full alphabet, as well as the numbers. The other banks that I've come across with this style also don't have a maximum password length. I believe that doing this would be an improvement - it gives you far more combinations.

Re: Stop restricting my password - Help these sites get better security.

#15
I was thinking of creating a list like this of all the sites that (most likely) store passwords as plain text. I'd get the list by doing a password reminder and seeing if they email me my password.

Would be cool if that was added as a column here. I'd submit some sites.

Re: Stop restricting my password - Help these sites get better security.

#16
post #5

Erm, Delta sure seems like an odd member of the list, doesn't it? They require you to enter a SkyMiles number and a PIN, along with your last name... all of which is certainly not very secure information. But ultimately, all that gives you access to is viewing a person's SkyMiles account. It hardly seems to make sense alongside banking sites.

Access to a Skymiles account allows booking award tickets - in any name, as well as using any stored credit card to pay for part of the cost. I think it also allows redirecting email notifications to another address. I think the chances of catching the person responsible for a fraudulent use of such an account are higher than for a bank account, but the potential harm is pretty high.

Re: Stop restricting my password - Help these sites get better security.

#17
post #9

There's really no point in restricting length or non-alphanumeric characters. They should be storing a salted hash, not the actual passwords, so the content of the password shouldn't matter. It's really just laziness and incomptence on the part of the programmers.

> There's really no point in restricting length or non-alphanumeric characters. I agree, the only rationale I can think of for this is that these institutions don't want people to forget their passwords, but even then I don't understand why they would want that at the expense of security.

The irritating thing is that forbidding spaces discourages pass phrases. You can't use "the cat sat on my blue suede shoes", which is pretty secure yet easy to remember.

You could use "thecatsatonmybluesuedeshoes", but that may be harder to type accurately.

Re: Stop restricting my password - Help these sites get better security.

#20
post #18

I can upvote one item as much as I want if I clear my cookies. Voted for Amex (twice). I'm always annoyed that the 8-character limit prevents me from using my normal password + PwdHash.

He probably should use IP logging too, but beyond that and cookies what can you really do?
Post reply on HN