[Tutorial] How NOT To Store Your Users' Passwords
#16

Quote:
Originally Posted by Sasino97
Посмотреть сообщение
That is true, but if the user used words which are all related to each other, he made the attacker’s work easier.
Again, not really. Unless you know how the words are related. And it is still VASTLY better than normal passwords where people do use the same ones over and over, and those common passwords are very well known and documented. The theoretical difficulty in cracking normal passwords assumes that “Df3()AsЈ” is just as common as “p4ssw0RD”. Do you think that’s the case? You’re arguing that this method is less secure because it has a theoretical attack, while totally ignoring the fact that the current method has a known attack.

Edit:

Quote:
Originally Posted by Sasino97
Посмотреть сообщение
How can we programmatically ensure that the user did not use "My name is Carl" as a password?
Why? Yes, passwords with semantic meaning are slightly worse, but still vastly better than most normal passwords.

Again:

You’re arguing that this method is less secure because it has a theoretical attack, while totally ignoring the fact that the current method has a known attack. Is it perfect? No. Is it better than the alternative (when a password manager isn't available? Yes!
Reply


Messages In This Thread
How NOT To Store Your Users' Passwords - by Sasino97 - 27.06.2018, 13:11
Re: How NOT To Store Your Users' Passwords - by Robin96 - 27.06.2018, 13:28
Re: How NOT To Store Your Users' Passwords - by RogueDrifter - 27.06.2018, 13:33
Re: How NOT To Store Your Users' Passwords - by Sasino97 - 27.06.2018, 14:30
Re: How NOT To Store Your Users' Passwords - by Uproar - 27.06.2018, 14:42
Re: How NOT To Store Your Users' Passwords - by Sasino97 - 27.06.2018, 15:31
Re: How NOT To Store Your Users' Passwords - by jlalt - 27.06.2018, 15:39
Re: How NOT To Store Your Users' Passwords - by Sasino97 - 27.06.2018, 15:58
Re: How NOT To Store Your Users' Passwords - by Riddick94 - 27.06.2018, 17:22
Re: How NOT To Store Your Users' Passwords - by Freaksken - 27.06.2018, 17:55
Re: How NOT To Store Your Users' Passwords - by Mobtiesgangsa - 27.06.2018, 22:36
Re: How NOT To Store Your Users' Passwords - by Garr - 27.06.2018, 23:59
Re: How NOT To Store Your Users' Passwords - by Sasino97 - 28.06.2018, 07:27
Re: How NOT To Store Your Users' Passwords - by Sasino97 - 28.06.2018, 09:09
Re: How NOT To Store Your Users' Passwords - by Sasino97 - 28.06.2018, 09:24
Re: How NOT To Store Your Users' Passwords - by Y_Less - 28.06.2018, 09:27
Re: How NOT To Store Your Users' Passwords - by Sasino97 - 28.06.2018, 09:47
Re: How NOT To Store Your Users' Passwords - by Riddick94 - 28.06.2018, 10:07
Re: How NOT To Store Your Users' Passwords - by [HLF]Southclaw - 28.06.2018, 10:13
Re: How NOT To Store Your Users' Passwords - by Y_Less - 28.06.2018, 13:37

Forum Jump:


Users browsing this thread: 1 Guest(s)