Live data from Hacker News

Air France requires account password to be between 4 and 6 characters

twitter.com

1–10 of 11 posts

Re: Air France requires account password to be between 4 and 6 characters

#5
post #3

between 4 and 6 is characters is pretty bad, but only numbers as well? Thats begging to be brute force.

Well even 4 numbers of 10,000 combinations. Say they lock the account out after 100 wrong attempts (hopefully), then assuming you don't choose 1234 or 0000 then you're pretty safe from a brute force attack.

I'm guessing they require this so you can type it in over the phone, that's the only sensible reason I can think of.

Re: Air France requires account password to be between 4 and 6 characters

#8
post #5
post #3

between 4 and 6 is characters is pretty bad, but only numbers as well? Thats begging to be brute force.

Well even 4 numbers of 10,000 combinations. Say they lock the account out after 100 wrong attempts (hopefully), then assuming you don't choose 1234 or 0000 then you're pretty safe from a brute force attack. I'm guessing they require this so you can type it in over the phone, that's the only sensible reason I can think of.

This is not safe at all. If you do this with a hundred accounts, you're likely to hack at least one.

Re: Air France requires account password to be between 4 and 6 characters

#9
post #8
post #5

Earlier quoted context omitted.

Well even 4 numbers of 10,000 combinations. Say they lock the account out after 100 wrong attempts (hopefully), then assuming you don't choose 1234 or 0000 then you're pretty safe from a brute force attack. I'm guessing they require this so you can type it in over the phone, that's the only sensible reason I can think of.

This is not safe at all. If you do this with a hundred accounts, you're likely to hack at least one.

It is safe for the individual accounts. Like a zebra in a zeal.
Post reply on HN