Long Passwords Could Have Crashed Security Website

Status
Not open for further replies.

anti-painkilla

Distinguished
Mar 29, 2011
116
0
18,640
I cannot understand why someone would even need a 4000 character password for these websites let alone a 100 character. I would bet that the majority of the passwords are the minimum length allowed.
 

palladin9479

Distinguished
Jul 26, 2008
193
0
18,640
"Long passwords are great: As a user, the longer your passwords are (while still being memorable and usable), the more secure you are."

This is very false. Longer passwords only protect against brute force attacks but not social engineering. If anything they make the user more prone to side-band attacks as humans can't easily remember such long *random* passwords and expect to change them every 90 days. Instead they write them down or store them in a text file on their desktop. That in turn makes them vulnerable to social engineering or other non-brute force attacks that focus on revealing the password or hints at the password instead of trying all random values until you hit on a match.
 

jtd871

Distinguished
Jan 26, 2012
7
0
18,510
I would imagine that long passwords stored as a cryptographic hash would also be vulnerable to a birthday attack.
 

leo2kp

Distinguished
Oct 9, 2006
126
0
18,640
This has been an issue for web security for quite a while. Not sure why they didn't start out with a password length limit. Nub mistake.
 
Status
Not open for further replies.