Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. The Lounge
  3. Case insensitive passwords

Case insensitive passwords

Scheduled Pinned Locked Moved The Lounge
question
20 Posts 13 Posters 0 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • T tgrt

    Would anyone else feel uncomfortable if their bank, a major bank, used case insensitive passwords?

    P Offline
    P Offline
    PIEBALDconsult
    wrote on last edited by
    #5

    Nothing in a user interface should be case sensitive. Usernames and passwords on OpenVMS are not case sensitive.

    1 Reply Last reply
    0
    • T tgrt

      Would anyone else feel uncomfortable if their bank, a major bank, used case insensitive passwords?

      C Offline
      C Offline
      Clifford Nelson
      wrote on last edited by
      #6

      Better than just numbers, which is what a pin is. More concerned about my debit card than most things I do on the internet. From what I understand, passwords are weak in general. It somebody has the no how, they will get through.

      1 Reply Last reply
      0
      • T tgrt

        Would anyone else feel uncomfortable if their bank, a major bank, used case insensitive passwords?

        W Offline
        W Offline
        wizardzz
        wrote on last edited by
        #7

        I imagine it went something like this: Richie McRich, the owner of Bank of The World: "Damnit, I can't login!." Minion 1: "Sir, it appears your caps lock is on." Richie McRich: "Why should that matter?! I want to count my money now!" Minion 1: "Well, it provides 26 more possible characters per-" Richie McRick: "Come here!" Richie takes off his glove slowly, then slaps Minion 1. Minion 1: "But sir, the general public might feel more secure if we only accept their exact-" Richie McRich: "Eliminate case sensitivity! Minion #2 execute Minion #1 and take his job! And bring in more babies, I'm hungry for dessert!" [Lights fade]

        P 1 Reply Last reply
        0
        • T tgrt

          Would anyone else feel uncomfortable if their bank, a major bank, used case insensitive passwords?

          P Offline
          P Offline
          Pualee
          wrote on last edited by
          #8

          No reason for alarm... your a programmer... did you have a CS background? The size of the alphabet alone does not make the password safe or not. You can just come up with your own encoding for the password you want and as long as the string is sufficiently long, your covered. camelCasePassword --> camelucaseupassword :suss: Edit: I bet an individual encoding would be harder to break using known hashes... think... if everyone has their own encodings... then the passwords become much more random (in the eyes of the attacker) and harder to break.

          T 1 Reply Last reply
          0
          • W wizardzz

            I imagine it went something like this: Richie McRich, the owner of Bank of The World: "Damnit, I can't login!." Minion 1: "Sir, it appears your caps lock is on." Richie McRich: "Why should that matter?! I want to count my money now!" Minion 1: "Well, it provides 26 more possible characters per-" Richie McRick: "Come here!" Richie takes off his glove slowly, then slaps Minion 1. Minion 1: "But sir, the general public might feel more secure if we only accept their exact-" Richie McRich: "Eliminate case sensitivity! Minion #2 execute Minion #1 and take his job! And bring in more babies, I'm hungry for dessert!" [Lights fade]

            P Offline
            P Offline
            Pualee
            wrote on last edited by
            #9

            :-D Made my day... been slow at work.

            1 Reply Last reply
            0
            • R Rama Krishna Vavilala

              No. Passwords can still be strong without being case sensitive - assuming they allow numbers and special characters.

              N Offline
              N Offline
              Nish Nishant
              wrote on last edited by
              #10

              How about banks that only allow a max of 8 characters :-)

              Regards, Nish


              My technology blog: voidnish.wordpress.com

              L 1 Reply Last reply
              0
              • P Pualee

                No reason for alarm... your a programmer... did you have a CS background? The size of the alphabet alone does not make the password safe or not. You can just come up with your own encoding for the password you want and as long as the string is sufficiently long, your covered. camelCasePassword --> camelucaseupassword :suss: Edit: I bet an individual encoding would be harder to break using known hashes... think... if everyone has their own encodings... then the passwords become much more random (in the eyes of the attacker) and harder to break.

                T Offline
                T Offline
                tgrt
                wrote on last edited by
                #11

                But it should make it safer. So if I generate a password 14 characters long than the password is 62 bits if it's case insensitive or 81 bits if it's case sensitive. The bank in question limits the length of the password to 14 characters. (It's 29 and 36 bits for a six character password.) The site is a little better than this, because it does allow a handful of special characters. Where am I wrong? Edit: by the way I used the Keepass password generator to give me quick and dirty relative bit strength for a sample password

                P 1 Reply Last reply
                0
                • T tgrt

                  Would anyone else feel uncomfortable if their bank, a major bank, used case insensitive passwords?

                  R Offline
                  R Offline
                  Roger Wright
                  wrote on last edited by
                  #12

                  Nope. Heck, until a couple of years ago, my bank still used a 4-digit PIN for online banking. Any letters is a big improvement! :-D

                  Will Rogers never met me.

                  1 Reply Last reply
                  0
                  • T tgrt

                    But it should make it safer. So if I generate a password 14 characters long than the password is 62 bits if it's case insensitive or 81 bits if it's case sensitive. The bank in question limits the length of the password to 14 characters. (It's 29 and 36 bits for a six character password.) The site is a little better than this, because it does allow a handful of special characters. Where am I wrong? Edit: by the way I used the Keepass password generator to give me quick and dirty relative bit strength for a sample password

                    P Offline
                    P Offline
                    Pualee
                    wrote on last edited by
                    #13

                    tgrt wrote:

                    The bank in question limits the length of the password to 14 characters

                    It's all 1's and 0's in the end. However, the limitation in length does break down my argument, now you don't necessarily have the ability of encoding .

                    1 Reply Last reply
                    0
                    • T tgrt

                      Would anyone else feel uncomfortable if their bank, a major bank, used case insensitive passwords?

                      L Offline
                      L Offline
                      Lost User
                      wrote on last edited by
                      #14

                      Yes. It reduces the amount of possible combinations. Would you boast over a vault with a bad lock?

                      Bastard Programmer from Hell :suss: If you can't read my code, try converting it here[^] They hate us for our freedom![^]

                      1 Reply Last reply
                      0
                      • T tgrt

                        Would anyone else feel uncomfortable if their bank, a major bank, used case insensitive passwords?

                        T Offline
                        T Offline
                        TheGreatAndPowerfulOz
                        wrote on last edited by
                        #15

                        yep

                        If your actions inspire others to dream more, learn more, do more and become more, you are a leader.-John Q. Adams
                        You must accept one of two basic premises: Either we are alone in the universe, or we are not alone in the universe. And either way, the implications are staggering.-Wernher von Braun
                        Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.-Albert Einstein

                        1 Reply Last reply
                        0
                        • T tgrt

                          Would anyone else feel uncomfortable if their bank, a major bank, used case insensitive passwords?

                          P Offline
                          P Offline
                          PIEBALDconsult
                          wrote on last edited by
                          #16

                          Wait a minute... how would you know?

                          1 Reply Last reply
                          0
                          • N Nish Nishant

                            How about banks that only allow a max of 8 characters :-)

                            Regards, Nish


                            My technology blog: voidnish.wordpress.com

                            L Offline
                            L Offline
                            Lost User
                            wrote on last edited by
                            #17

                            Nish Sivakumar wrote:

                            How about banks that only allow a max of 8 characters :)

                            It depends if they are using rather large values of 8 or not.

                            Michael Martin Australia "I controlled my laughter and simple said "No,I am very busy,so I can't write any code for you". The moment they heard this all the smiling face turned into a sad looking face and one of them farted. So I had to leave the place as soon as possible." - Mr.Prakash One Fine Saturday. 24/04/2004

                            B 1 Reply Last reply
                            0
                            • L Lost User

                              Nish Sivakumar wrote:

                              How about banks that only allow a max of 8 characters :)

                              It depends if they are using rather large values of 8 or not.

                              Michael Martin Australia "I controlled my laughter and simple said "No,I am very busy,so I can't write any code for you". The moment they heard this all the smiling face turned into a sad looking face and one of them farted. So I had to leave the place as soon as possible." - Mr.Prakash One Fine Saturday. 24/04/2004

                              B Offline
                              B Offline
                              Brisingr Aerowing
                              wrote on last edited by
                              #18

                              Website written in FORTRAN?

                              Bob Dole

                              The internet is a great way to get on the net.

                              :doh: 2.0.82.7292 SP6a

                              1 Reply Last reply
                              0
                              • T tgrt

                                Would anyone else feel uncomfortable if their bank, a major bank, used case insensitive passwords?

                                B Offline
                                B Offline
                                Brisingr Aerowing
                                wrote on last edited by
                                #19

                                My bank is the exact opposite. The password AND the username are case sensitive. And they don't allow any special characters, just letters and numbers.

                                Bob Dole

                                The internet is a great way to get on the net.

                                :doh: 2.0.82.7292 SP6a

                                1 Reply Last reply
                                0
                                • T tgrt

                                  Would anyone else feel uncomfortable if their bank, a major bank, used case insensitive passwords?

                                  C Offline
                                  C Offline
                                  Chris Berger
                                  wrote on last edited by
                                  #20

                                  Absolutely I would feel uncomfortable. But not for the reason that some people seem to be imagining. It's because it makes me think that they're storing my password in plaintext. Basically, I can think of two ways that my password would be case insensitive. a) is deliberate - they uppercase (or lowercase) it before hashing it. It seems pointless and silly to do this, but it causes no great loss of security. b) is accidental - they're storing my password in plaintext, and SQL string comparisons are case insensitive by default. The tendency to believe b) is what makes me uncomfortable.

                                  1 Reply Last reply
                                  0
                                  Reply
                                  • Reply as topic
                                  Log in to reply
                                  • Oldest to Newest
                                  • Newest to Oldest
                                  • Most Votes


                                  • Login

                                  • Don't have an account? Register

                                  • Login or register to search.
                                  • First post
                                    Last post
                                  0
                                  • Categories
                                  • Recent
                                  • Tags
                                  • Popular
                                  • World
                                  • Users
                                  • Groups