Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


mover85

29 posts

Geek
+1 received by user: 8


#272091 9-Jun-2020 11:06
Send private message

Hi Everyone

 

I was trying to login to my Xtra webmail account and noticed the password field is not case sensitive.

 

Is this intentional or a bug?


Create new topic
Jase2985
13732 posts

Uber Geek
+1 received by user: 6205

ID Verified
Lifetime subscriber

  #2501291 9-Jun-2020 11:26
Send private message

Just tried with mine

 

not good

 

@hio77 this needs looked at ASAP




SirHumphreyAppleby
2939 posts

Uber Geek
+1 received by user: 1860


  #2501302 9-Jun-2020 11:42
Send private message

While perhaps not best practice, I wouldn't consider this a security flaw per se. I'm sure there is a good reason why it is configured this way.


hio77
'That VDSL Cat'
13036 posts

Uber Geek
+1 received by user: 3896

ID Verified
Trusted
Lizard Networks
Subscriber

  #2501331 9-Jun-2020 12:17
Send private message

Jase2985:

 

hio77 this needs looked at ASAP

 

 

Heya,

 

 

 

I've passed this onto the relevant team to investigate.





#include <std_disclaimer>

 

Any comments made are personal opinion and do not reflect directly on the position my current or past employers may have. 




boosacnoodle
1274 posts

Uber Geek
+1 received by user: 858


  #2501451 9-Jun-2020 12:32
Send private message

This presumably means that they are not hashing passwords which is not a good sign.


SirHumphreyAppleby
2939 posts

Uber Geek
+1 received by user: 1860


  #2501459 9-Jun-2020 12:48
Send private message

boosacnoodle:

 

This presumably means that they are not hashing passwords which is not a good sign.

 

 

Normalisation may be occurring before hashing.


yitz
2239 posts

Uber Geek
+1 received by user: 594


  #2501484 9-Jun-2020 13:24
Send private message

It's not case sensitive on Yahoo either.


 
 
 

Shop on-line at New World now for your groceries (affiliate link).
igiveup
24 posts

Geek
+1 received by user: 3


  #2506692 17-Jun-2020 14:42

Yesterday I checked and sure enough my xtra mail will log in using 

 

my password in just lower case. Sooo I contacted spark by typing

 

to the robot and after about 15 minutes playing ring a ring a rosie

 

I was typing to a human and 3o  minutes later and much hair pulling

 

the penny dropped and I was told it should not do that and that the

 

problem would be escalated to the great unwashed.

 

I wait with no expectation of an outcome as it would appear that such

 

a security flaw is nothing to really worry about


hio77
'That VDSL Cat'
13036 posts

Uber Geek
+1 received by user: 3896

ID Verified
Trusted
Lizard Networks
Subscriber

  #2506717 17-Jun-2020 14:56
Send private message

Since this thread came across my desk, this has been actively been worked on.

 

 

 

I don't have an update i can provide here at this stage, but I'll simply confirm Yes it has already been esclated and is with the right folk.





#include <std_disclaimer>

 

Any comments made are personal opinion and do not reflect directly on the position my current or past employers may have. 


TheMaskedOnion
51 posts

Master Geek
+1 received by user: 4


  #2506769 17-Jun-2020 15:49
Send private message

The ASB fastnet classic login webpage has the same issue.


dfnt
1553 posts

Uber Geek
+1 received by user: 1036

Trusted
Lifetime subscriber

  #2506860 17-Jun-2020 17:09
Send private message

TheMaskedOnion:

 

The ASB fastnet classic login webpage has the same issue.

 

 

Had, don't you mean?

Pretty sure they changed that a few years ago when it was last bought up here in GZ.

 

I just tried with an old login, and changed one character from upper to lower case and the login failed as expected. Worked fine with the proper case.


TheMaskedOnion
51 posts

Master Geek
+1 received by user: 4


  #2506865 17-Jun-2020 17:19
Send private message

Mine isn't case sensitive, maybe i just need to change it.

 

 

 

EDIT: yup, just needed to change my password and now it's case sensitive.


 
 
 
 

Shop now for Lego sets and other gifts (affiliate link).
MickeyD
97 posts

Master Geek
+1 received by user: 29

Lifetime subscriber

  #2506868 17-Jun-2020 17:23
Send private message

On its own, is this actually much of an issue?

 

While case insensitive passwords certainly aren't best practice, if other techniques are used such as salting, hashing, and stretching, and forced password resets following multiple incorrect attempts within a given timeframe, then the increased risk by having case-insensitive passwords probably isn't that great.

 

What I'd be more concerned about is given that they use case insensitive passwords, what's the likelihood they also don't implement the other techniques for keeping my password safe, or that it's stored in plain text? That we will likely never know.

 

I would have thought that there's a better return on effort spent encouraging friends and family to use a password of sufficient length that includes special characters; ideally using a password manager to generate a random password, and not reusing your email password anywhere else than there is worrying about case sensitivity.

 

 

 

 


dfnt
1553 posts

Uber Geek
+1 received by user: 1036

Trusted
Lifetime subscriber

  #2506886 17-Jun-2020 18:04
Send private message

TheMaskedOnion:

 

Mine isn't case sensitive, maybe i just need to change it.

 

 

 

EDIT: yup, just needed to change my password and now it's case sensitive.

 

 

Ah yep, I did change my password when it was announced they were now case sensitive and longer than whatever the old limit was

 

Was awhile ago, I'm with a different bank now


Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.