Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. The Lounge
  3. Case insensitive passwords

Case insensitive passwords

Scheduled Pinned Locked Moved The Lounge
question
20 Posts 13 Posters 0 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • R Rama Krishna Vavilala

    No. Passwords can still be strong without being case sensitive - assuming they allow numbers and special characters.

    N Offline
    N Offline
    Nish Nishant
    wrote on last edited by
    #10

    How about banks that only allow a max of 8 characters :-)

    Regards, Nish


    My technology blog: voidnish.wordpress.com

    L 1 Reply Last reply
    0
    • P Pualee

      No reason for alarm... your a programmer... did you have a CS background? The size of the alphabet alone does not make the password safe or not. You can just come up with your own encoding for the password you want and as long as the string is sufficiently long, your covered. camelCasePassword --> camelucaseupassword :suss: Edit: I bet an individual encoding would be harder to break using known hashes... think... if everyone has their own encodings... then the passwords become much more random (in the eyes of the attacker) and harder to break.

      T Offline
      T Offline
      tgrt
      wrote on last edited by
      #11

      But it should make it safer. So if I generate a password 14 characters long than the password is 62 bits if it's case insensitive or 81 bits if it's case sensitive. The bank in question limits the length of the password to 14 characters. (It's 29 and 36 bits for a six character password.) The site is a little better than this, because it does allow a handful of special characters. Where am I wrong? Edit: by the way I used the Keepass password generator to give me quick and dirty relative bit strength for a sample password

      P 1 Reply Last reply
      0
      • T tgrt

        Would anyone else feel uncomfortable if their bank, a major bank, used case insensitive passwords?

        R Offline
        R Offline
        Roger Wright
        wrote on last edited by
        #12

        Nope. Heck, until a couple of years ago, my bank still used a 4-digit PIN for online banking. Any letters is a big improvement! :-D

        Will Rogers never met me.

        1 Reply Last reply
        0
        • T tgrt

          But it should make it safer. So if I generate a password 14 characters long than the password is 62 bits if it's case insensitive or 81 bits if it's case sensitive. The bank in question limits the length of the password to 14 characters. (It's 29 and 36 bits for a six character password.) The site is a little better than this, because it does allow a handful of special characters. Where am I wrong? Edit: by the way I used the Keepass password generator to give me quick and dirty relative bit strength for a sample password

          P Offline
          P Offline
          Pualee
          wrote on last edited by
          #13

          tgrt wrote:

          The bank in question limits the length of the password to 14 characters

          It's all 1's and 0's in the end. However, the limitation in length does break down my argument, now you don't necessarily have the ability of encoding .

          1 Reply Last reply
          0
          • T tgrt

            Would anyone else feel uncomfortable if their bank, a major bank, used case insensitive passwords?

            L Offline
            L Offline
            Lost User
            wrote on last edited by
            #14

            Yes. It reduces the amount of possible combinations. Would you boast over a vault with a bad lock?

            Bastard Programmer from Hell :suss: If you can't read my code, try converting it here[^] They hate us for our freedom![^]

            1 Reply Last reply
            0
            • T tgrt

              Would anyone else feel uncomfortable if their bank, a major bank, used case insensitive passwords?

              T Offline
              T Offline
              TheGreatAndPowerfulOz
              wrote on last edited by
              #15

              yep

              If your actions inspire others to dream more, learn more, do more and become more, you are a leader.-John Q. Adams
              You must accept one of two basic premises: Either we are alone in the universe, or we are not alone in the universe. And either way, the implications are staggering.-Wernher von Braun
              Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.-Albert Einstein

              1 Reply Last reply
              0
              • T tgrt

                Would anyone else feel uncomfortable if their bank, a major bank, used case insensitive passwords?

                P Offline
                P Offline
                PIEBALDconsult
                wrote on last edited by
                #16

                Wait a minute... how would you know?

                1 Reply Last reply
                0
                • N Nish Nishant

                  How about banks that only allow a max of 8 characters :-)

                  Regards, Nish


                  My technology blog: voidnish.wordpress.com

                  L Offline
                  L Offline
                  Lost User
                  wrote on last edited by
                  #17

                  Nish Sivakumar wrote:

                  How about banks that only allow a max of 8 characters :)

                  It depends if they are using rather large values of 8 or not.

                  Michael Martin Australia "I controlled my laughter and simple said "No,I am very busy,so I can't write any code for you". The moment they heard this all the smiling face turned into a sad looking face and one of them farted. So I had to leave the place as soon as possible." - Mr.Prakash One Fine Saturday. 24/04/2004

                  B 1 Reply Last reply
                  0
                  • L Lost User

                    Nish Sivakumar wrote:

                    How about banks that only allow a max of 8 characters :)

                    It depends if they are using rather large values of 8 or not.

                    Michael Martin Australia "I controlled my laughter and simple said "No,I am very busy,so I can't write any code for you". The moment they heard this all the smiling face turned into a sad looking face and one of them farted. So I had to leave the place as soon as possible." - Mr.Prakash One Fine Saturday. 24/04/2004

                    B Offline
                    B Offline
                    Brisingr Aerowing
                    wrote on last edited by
                    #18

                    Website written in FORTRAN?

                    Bob Dole

                    The internet is a great way to get on the net.

                    :doh: 2.0.82.7292 SP6a

                    1 Reply Last reply
                    0
                    • T tgrt

                      Would anyone else feel uncomfortable if their bank, a major bank, used case insensitive passwords?

                      B Offline
                      B Offline
                      Brisingr Aerowing
                      wrote on last edited by
                      #19

                      My bank is the exact opposite. The password AND the username are case sensitive. And they don't allow any special characters, just letters and numbers.

                      Bob Dole

                      The internet is a great way to get on the net.

                      :doh: 2.0.82.7292 SP6a

                      1 Reply Last reply
                      0
                      • T tgrt

                        Would anyone else feel uncomfortable if their bank, a major bank, used case insensitive passwords?

                        C Offline
                        C Offline
                        Chris Berger
                        wrote on last edited by
                        #20

                        Absolutely I would feel uncomfortable. But not for the reason that some people seem to be imagining. It's because it makes me think that they're storing my password in plaintext. Basically, I can think of two ways that my password would be case insensitive. a) is deliberate - they uppercase (or lowercase) it before hashing it. It seems pointless and silly to do this, but it causes no great loss of security. b) is accidental - they're storing my password in plaintext, and SQL string comparisons are case insensitive by default. The tendency to believe b) is what makes me uncomfortable.

                        1 Reply Last reply
                        0
                        Reply
                        • Reply as topic
                        Log in to reply
                        • Oldest to Newest
                        • Newest to Oldest
                        • Most Votes


                        • Login

                        • Don't have an account? Register

                        • Login or register to search.
                        • First post
                          Last post
                        0
                        • Categories
                        • Recent
                        • Tags
                        • Popular
                        • World
                        • Users
                        • Groups