04-11-2018, 01:26 PM
(This post was last modified: 04-11-2018, 01:27 PM by ppppenguin.)
Of course there's a need for decent passwords but many organisations don't exactly help you do this. Things I've seen include:
Paaswords emailed back to you in open email. This happens with some forums when you become a new user.
Maximum PW lengths, sometimes as short as 8 characters
Requirement to include a number/capital letter/special character. This can actually reduce entropy
Not allowing special characters
Not allowing PW to start with other than a letter
Some of these are from financial institutions where if your PW was hacked you'd lose money.
Also even with good PWs and good PW policies, it only prevents brute force attacks. There are side channels, inculding human engineering, that can offfer much easier routes. For example the replacement SIM fraud: https://www.theguardian.com/money/2018/f...d-security
This is an example of a fraud over which we have little or no control as end users.
Paaswords emailed back to you in open email. This happens with some forums when you become a new user.
Maximum PW lengths, sometimes as short as 8 characters
Requirement to include a number/capital letter/special character. This can actually reduce entropy
Not allowing special characters
Not allowing PW to start with other than a letter
Some of these are from financial institutions where if your PW was hacked you'd lose money.
Also even with good PWs and good PW policies, it only prevents brute force attacks. There are side channels, inculding human engineering, that can offfer much easier routes. For example the replacement SIM fraud: https://www.theguardian.com/money/2018/f...d-security
This is an example of a fraud over which we have little or no control as end users.
www.borinsky.co.uk Jeffrey Borinsky www.becg.tv







