Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


mover85

29 posts

Geek


#272091 9-Jun-2020 11:06
Send private message

Hi Everyone

 

I was trying to login to my Xtra webmail account and noticed the password field is not case sensitive.

 

Is this intentional or a bug?


Create new topic
  #2501291 9-Jun-2020 11:26
Send private message

Just tried with mine

 

not good

 

@hio77 this needs looked at ASAP




SirHumphreyAppleby
2847 posts

Uber Geek


  #2501302 9-Jun-2020 11:42
Send private message

While perhaps not best practice, I wouldn't consider this a security flaw per se. I'm sure there is a good reason why it is configured this way.


hio77
12999 posts

Uber Geek

ID Verified
Trusted
Lizard Networks

  #2501331 9-Jun-2020 12:17
Send private message

Jase2985:

 

hio77 this needs looked at ASAP

 

 

Heya,

 

 

 

I've passed this onto the relevant team to investigate.





#include <std_disclaimer>

 

Any comments made are personal opinion and do not reflect directly on the position my current or past employers may have.

 

 




boosacnoodle
963 posts

Ultimate Geek


  #2501451 9-Jun-2020 12:32
Send private message

This presumably means that they are not hashing passwords which is not a good sign.


SirHumphreyAppleby
2847 posts

Uber Geek


  #2501459 9-Jun-2020 12:48
Send private message

boosacnoodle:

 

This presumably means that they are not hashing passwords which is not a good sign.

 

 

Normalisation may be occurring before hashing.


yitz
2080 posts

Uber Geek


  #2501484 9-Jun-2020 13:24
Send private message

It's not case sensitive on Yahoo either.


igiveup
24 posts

Geek


  #2506692 17-Jun-2020 14:42

Yesterday I checked and sure enough my xtra mail will log in using 

 

my password in just lower case. Sooo I contacted spark by typing

 

to the robot and after about 15 minutes playing ring a ring a rosie

 

I was typing to a human and 3o  minutes later and much hair pulling

 

the penny dropped and I was told it should not do that and that the

 

problem would be escalated to the great unwashed.

 

I wait with no expectation of an outcome as it would appear that such

 

a security flaw is nothing to really worry about


 
 
 

Move to New Zealand's best fibre broadband service (affiliate link). Free setup code: R587125ERQ6VE. Note that to use Quic Broadband you must be comfortable with configuring your own router.
hio77
12999 posts

Uber Geek

ID Verified
Trusted
Lizard Networks

  #2506717 17-Jun-2020 14:56
Send private message

Since this thread came across my desk, this has been actively been worked on.

 

 

 

I don't have an update i can provide here at this stage, but I'll simply confirm Yes it has already been esclated and is with the right folk.





#include <std_disclaimer>

 

Any comments made are personal opinion and do not reflect directly on the position my current or past employers may have.

 

 


TheMaskedOnion
51 posts

Master Geek


  #2506769 17-Jun-2020 15:49
Send private message

The ASB fastnet classic login webpage has the same issue.


dfnt
1512 posts

Uber Geek

Lifetime subscriber

  #2506860 17-Jun-2020 17:09
Send private message

TheMaskedOnion:

 

The ASB fastnet classic login webpage has the same issue.

 

 

Had, don't you mean?

Pretty sure they changed that a few years ago when it was last bought up here in GZ.

 

I just tried with an old login, and changed one character from upper to lower case and the login failed as expected. Worked fine with the proper case.


TheMaskedOnion
51 posts

Master Geek


  #2506865 17-Jun-2020 17:19
Send private message

Mine isn't case sensitive, maybe i just need to change it.

 

 

 

EDIT: yup, just needed to change my password and now it's case sensitive.


MickeyD
97 posts

Master Geek

Lifetime subscriber

  #2506868 17-Jun-2020 17:23
Send private message

On its own, is this actually much of an issue?

 

While case insensitive passwords certainly aren't best practice, if other techniques are used such as salting, hashing, and stretching, and forced password resets following multiple incorrect attempts within a given timeframe, then the increased risk by having case-insensitive passwords probably isn't that great.

 

What I'd be more concerned about is given that they use case insensitive passwords, what's the likelihood they also don't implement the other techniques for keeping my password safe, or that it's stored in plain text? That we will likely never know.

 

I would have thought that there's a better return on effort spent encouraging friends and family to use a password of sufficient length that includes special characters; ideally using a password manager to generate a random password, and not reusing your email password anywhere else than there is worrying about case sensitivity.

 

 

 

 


dfnt
1512 posts

Uber Geek

Lifetime subscriber

  #2506886 17-Jun-2020 18:04
Send private message

TheMaskedOnion:

 

Mine isn't case sensitive, maybe i just need to change it.

 

 

 

EDIT: yup, just needed to change my password and now it's case sensitive.

 

 

Ah yep, I did change my password when it was announced they were now case sensitive and longer than whatever the old limit was

 

Was awhile ago, I'm with a different bank now


Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.