Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Sites That Don't Allow Special Characters In Passwords !?!
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Analysis of the Gozi Trojan - leads to Russian data horde »
« Free antivirus for non-profit organization?  
AuthorAll Replies


nwrickert
sand groper
Premium,MVM
join:2004-09-04
Geneva, IL
·AT&T U-Verse
·AT&T Midwest

reply to Daniel
Re: Big Sites That Don't Allow Complex Passwords !?!

It's a problem because humans are better at remembering shorter passwords, ...
The idea of remembering passwords went out the window once web sites started wanting passwords. It is unmanageable.

I keep only a very few remembered passwords. One of those is the passphrase I need to access my encrypted password database. And once one starts storing passwords in a database, there is no longer a need to keep them short.
--
AT&T dsl; Westell 2200 modem/router; SuSE 10.1; firefox 1.5.0.10


Daniel
Premium,MVM
join:2000-06-26
Pleasanton, CA
clubs:


2 edits
said by nwrickert See Profile :

It's a problem because humans are better at remembering shorter passwords, ...
The idea of remembering passwords went out the window once web sites started wanting passwords. It is unmanageable.
Your argument is invalid simply because over 95% of users still do manage their own passwords. That's a guess, but it's actually probably closer to 99%. We have to solve the problems we have, not the problems we should have or wish we had.
--
dmiessler.com -- grep understanding knowledge


nwrickert
sand groper
Premium,MVM
join:2004-09-04
Geneva, IL
·AT&T U-Verse
·AT&T Midwest

Your argument is invalid simply because over 95% of users still do manage their own passwords.
I manage my own passwords. Storing them in a file, and encrypting that file is part of how I manage them.

I just checked. I have 55 entries in that file, and I shun most web sites that require passwords. Nobody can remember that many.

If they actually are trying to remember 55 passwords, then they are probably using very weak passwords and re-using the same password for many sites. And if they are doing that, they have a more serious problem than the one you suggested in your OP.
--
AT&T dsl; Westell 2200 modem/router; SuSE 10.1; firefox 1.5.0.10


Daniel
Premium,MVM
join:2000-06-26
Pleasanton, CA
clubs:

said by nwrickert See Profile :

Your argument is invalid simply because over 95% of users still do manage their own passwords.
If they actually are trying to remember 55 passwords, then they are probably using very weak passwords and re-using the same password for many sites. And if they are doing that, they have a more serious problem than the one you suggested in your OP.
Well, that is the reality we're facing. The question is, how do we mitigate some of this risk? It's a lot harder to get users to change their habits than it is to get a single site that handles millions of accounts to change theirs.

I agree it's not a real solution, but nothing in security ever is. It's about reducing risk, and if we can add ANY significant amount of complexity to the incredibly weak passwords that most people use, we'll have accomplished something. Hence my OP.
--
dmiessler.com -- grep understanding knowledge
Forums » Up and Running » Security » SecurityAnalysis of the Gozi Trojan - leads to Russian data horde »
« Free antivirus for non-profit organization?  


Wednesday, 02-Dec 01:05:20 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [139] Comcast Releasing Promised Usage Meter
· [68] Baltimore To Ban Lazy Cable Installs
· [56] Broadband Killed The Game Console
· [51] Latest Consumer Reports Survey Not Kind To AT&T
· [50] Rogers Unveils The ISP Dream Model
· [40] Rural Carriers Quickly Embracing Fiber
· [37] ACTA: Global Three Strikes
· [35] Charter Exits Chapter 11
· [33] AT&T Top Lobbyist Cicconi Has His Feelings Hurt
· [25] Vivendi Agrees, Comcast/NBC Deal Soon
Most people now reading
· Download speeds very slow. [AT&T West]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· 16% packet loss. damn dsl. los angeles [AT&T West]
· Windows 7 boot manager editing questions [Microsoft Help]
· [Newsgroups] Newzleech down? [Filesharing Software]
· Considering Leaving Vonage, who should I Consider? [VOIP Tech Chat]
· [Snow Leopard] NFS Mounts - no more Directory Utility [All Things Macintosh]
· Data Usage Meter Launched [Comcast HSI]
· netTalk tk6000 [VOIP Tech Chat]
· [Phish] email from CDC "personal vaccination profile" [Spam, Scam and Phishbusters]