|
By (user no longer on site) OP
over a year ago
|
Hi everyone. I noticed today whilst logging in when I typed my password incorrectly this morning that you can login with your password every if you don't use the correct caps/small characters.
What I mean is you can set your password as - PaSsWoRd - and you can login with - password or PASSWORD.
Does anyone else see this as an issue or is it just me? |
Reply privately, Reply in forum +quote
or View forums list | |
|
By (user no longer on site)
over a year ago
|
It's all to do with the level of security a website database employs.
For example, a non-case sensitive alpha-numeric system is twice as likely to succumb to a brute force hacking attack than a case sensitive alpha-numeric system.
As a comparable, Diceware password systems are 125 less likely to succumb to a brute force hacking attack than a case sensitive system and 250 times less likely than a non-case sensitive system.
It all boils down to cost. If you can enter your password in lower or upper case the site is employing a cheaper database for it's security than if you had to input it in a mixture of upper/lower case symbols that also included numbers. |
Reply privately, Reply in forum +quote
or View forums list | |
» Add a new message to this topic