password is already in use

No way that’s an actual security threat, right?

@pazukaza@lemmy.ml
link
fedilink
0
edit-2
1Y

The only security threat would be the site itself. How do they know other users have the same password?

Options:

  • They have your password in plain text in their DB. CHEFF KISS

  • They aren’t using salts.

  • They are using the same salt for everyone.

All of them concerning.

“Password is already used by user potatoeater420, please choose a different password.”

Knowing that it’s already in use is.

Basically all of these constraints are bad practice, though. It’s obviously better to have a long, complex password, and not to reuse passwords between sites, but if you make shit impossible for people to remember they’re going to write it down, and a lot of people don’t use password managers (or use shared devices where they aren’t possible).

Length limits (that aren’t like 1000 characters) are unconditionally terrible practice. It means your password is probably plain text, because hashes don’t really care or take meaningfully longer based on the length of the input.

A string of (random) words is a perfectly fine password. There’s an xkcd I’m too lazy to get demonstrating it, but it genuinely does add enough randomness to break brute force.

HeavyRust
link
fedilink
91Y

A string of (random) words is a perfectly fine password. There’s an xkcd I’m too lazy to get demonstrating it, but it genuinely does add enough randomness to break brute force.

Here’s the xkcd.

Create a post

Post funny things about programming here! (Or just rant about your favourite programming language.)

Rules:

  • Posts must be relevant to programming, programmers, or computer science.
  • No NSFW content.
  • Jokes must be in good taste. No hate speech, bigotry, etc.
  • 1 user online
  • 61 users / day
  • 247 users / week
  • 417 users / month
  • 2.88K users / 6 months
  • 1 subscriber
  • 1.53K Posts
  • 33.9K Comments
  • Modlog