this post was submitted on 24 Mar 2024
384 points (96.2% liked)

Privacy

31892 readers
529 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 

VideoLAN @videolan App Stores were a mistake. Currently, we cannot update VLC on Windows Store, and we cannot update VLC on Android Play Store, without reducing security or dropping a lot of users... For now, iOS App Store still allows us to ship for iOS9, but until when?

you are viewing a single comment's thread
view the rest of the comments
[–] taladar@sh.itjust.works 91 points 7 months ago (32 children)

Banks are okay with it, but VLC feel more strongly than banks.

I mean banks are known for horrible security practices all around so that makes perfect sense.

[–] soloner@lemmy.world 3 points 7 months ago (31 children)
[–] Kindness@lemmy.ml 14 points 7 months ago (2 children)

Darren Kitchen from Hak5 has an amusing story about a bank teller who assured him email was entirely fine to send sPII through. "No sir, you just need to send it to us, and once we have your information then it'll be secure." No encryption. So, yes.

Also look into the Equifax security breach. Un-patched software for months.

It makes almost no sense to have a password length limit. 1_000_000, that's One Million, characters is equal to 1MiB. That's twice the length of the Lord of the Rings Trilogy and much less than most modern webpages. After hashing, which is how passwords should be stored, text length is irrelevant. All hashed inputs come out the exact same length. 65 characters for SHA256.

Very much known for their horrible security practices, yes. Absolutely.

[–] gartheom@lemmy.world 10 points 7 months ago* (last edited 7 months ago) (1 children)

Setting a max password length is sometimes done to prevent ddos attacks. Without it, attackers could just spam 1MB passwords constantly and force the login server to just spend all its cpu time hashing garbage.

That being said, a password limit of under 20 characters probably just means they are just storing passwords in plaintext.

[–] ICastFist@programming.dev 2 points 7 months ago

In Brazil, the govt owned lottery site, created around 2015, only accepts passwords with 6 numeric digits. Your password has to be a number between 000000 and 999999. Only somewhat recently (6 months ago or so) they've added a 2FA through an email link.

Oh, said lottery is run by the biggest govt owned bank. Chances of people reusing their bank password there are very fucking high.

load more comments (28 replies)
load more comments (28 replies)