Canada's Only Integrated Social Media News Network©
Username:  Password: Lost Password? Sign Up
Welcome, Guest Please, login above or Signup

Password length and Hotmail
(1 viewing) (1) Guest
Issues: Anti-virus, Firewall/UTM, Privacy
Go to bottomPage: 1
TOPIC: Password length and Hotmail
#3492
Password length and Hotmail 8 Months ago Karma: 2
Interesting post by Kaspersky's Costin Raiu on the disconnect between best practice in passwords and current practice for at least one prominent destination.

Raiu advises users to build passwords that:
* include both uppercase and lowercase chars
* include at least one space character
* include numbers
* include several symbols such as !@#
* are not based on a known word
* are at least 12 chars in size, but the longer the better

He then goes on to talk about getting a message from Hotmail, telling him that his password is too long - that Hotmail limits passwords to 16 characters. After discussing the implications of this message, Raiu concludes that "since its inception, Hotmail was silently using only the first 16 chars of the password." A link from one of the comments to Microsoft.com shows that this is indeed the case.

As intrusions become more common, the authors of these intrusions become better-armed and more skilled, and (as a result of both points) security becomes more complex, it will be important for all sites to keep pace with best practices. Clearly, this is more of a challenge for sites with millions of users than for start-ups - but it's not less important!

Tip of the cap to Kaspersky's Nicole Capulla for the link to the Raiu post.
Michael_ONeil
Admin
Posts: 709
graph
User Offline Click here to see the profile of this user
The administrator has disabled public write access.
 
Go to topPage: 1