Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Sites That Don't Allow Special Characters In Passwords !?!
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Analysis of the Gozi Trojan - leads to Russian data horde »
« Free antivirus for non-profit organization?  
AuthorAll Replies


BlitzenZeus
Burnt Out Cynic
Premium,MVM
join:2000-01-13
Beaverton, OR
reply to Daniel
Re: Big Sites That Don't Allow Complex Passwords !?!

If your just setting up complex passwords in some password program, its not helping you at all. Using some master password to as part of a password storage then your only fooling yourself when it comes to security.

dave
Premium,MVM
join:2000-05-04
not in ohio
·Verizon Online DSL
·Verizon FIOS


1 edit
said by BlitzenZeus See Profile :

If your just setting up complex passwords in some password program, its not helping you at all. Using some master password to as part of a password storage then your only fooling yourself when it comes to security.
Assume an attacker has no access to your PC; he's merely attacking the web site (and it's not tricky to guess, for example, that there might be a user called 'dave'). There is no 'master password' involved. It's simply a matter of how hard it is to brute-force the password space.

If the password space is restricted to [A-Za-z0-9] then there are far fewer possible passwords than if passwords could use any characters. Thus, the password is easier to guess. Simple arithmetic.

This is just sloppy programming, about as sloppy as the idiots who insist you type credit card numbers without spaces, despite that fact that the numbers on the cards are grouped in fours for a very good reason.

I suppose the point of your comemnt may be that people who use 'complex passwords' must be keeping them in software-managed keyrings. That doesn't seem to follow at all. A few non-alphameric characters dropped into a password doesn't suddenly make it impossible to remember; even a scheme as silly as replacing an 's' with '$' adds a small amount of strength, withut making the password harder to remember.

--
Microsoft Security MVP, 2005-2007.
Forums » Up and Running » Security » SecurityAnalysis of the Gozi Trojan - leads to Russian data horde »
« Free antivirus for non-profit organization?  


Tuesday, 10-Nov 22:10:23 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [121] Moto Sold About 100,000 Droids
· [93] Verizon Keeps Swinging At AT&T
· [86] VoIP Over 3G Still Not Working For iPhone
· [67] Government Will Release Some Telco Wiretap Lobbying Documents
· [60] Verizon's Hanging Up On Rural America
· [46] Verizon's Higher ETFs Annoy Senator
· [34] Bill Would Force ISPs To Block Financial Scams
· [29] Sprint Announces Job Cuts
· [24] Mediacom Hints At 50, 100 Mbps Speeds
· [21] Google Offers Free Holiday Airport Wi-Fi
Most people now reading
· [Rant] windows 7 is the most retarded os ever and its broke to [Rants, Raves, and Praise]
· I miss trash... [World of Warcraft]
· Holy work line speeds!! [TekSavvy]
· Water heater pilot light won't light [Home Repair & Improvement]
· Windows 7 boot manager editing questions [Microsoft Help]
· House inspector failed to find major gas leak [Home Repair & Improvement]
· RG Firmware update to VDSL2 this morning [AT&T U-verse]
· New low end ip phone Polycom IP335 [VOIP Tech Chat]
· [ Classes] Druid tanking: rotation and glyphs [World of Warcraft]
· Cellulose v Fiberglass for the attic [Home Repair & Improvement]