h3h.net provides mostly valuable and insightful commentary on a wide range of contemporary subjects, including business, philosophy, software, and responsibility.

written by brad fults

Archives

Admin

Bank of America’s Retarded Password Policy

Tuesday, September 18, 2007

Bank of America requires that your password be only alphanumeric.

Wait. Let me get this straight. You want me to supply a password that consists of only letters and numbers, thereby increasing the likelihood of simple dictionary attacks? And this is “to make sure [my] passcode is sufficiently secure”? Apparently there are “invalid symbols” that I [...]

written by Brad Fults

You Need to Use Better Passwords

Sunday, February 25, 2007

What is your online banking password? I have 10 to 1 odds that say it sucks. You should probably do something about that. If you like money, that is.

Alex King wrote a couple of posts [1, 2] on using password hashing software to abstract your passwords out of your head, ostensibly increasing the level of security involved with the web sites you entrust your information to.

written by Brad Fults