<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: The List Of Shame: Websites That Don&#8217;t Allow Special Characters In Their Passwords</title>
	<atom:link href="http://danielmiessler.com/blog/the-list-of-shame-websites-that-dont-allow-special-characters-in-their-passwords/feed" rel="self" type="application/rss+xml" />
	<link>http://danielmiessler.com/blog/the-list-of-shame-websites-that-dont-allow-special-characters-in-their-passwords</link>
	<description>grep understanding</description>
	<lastBuildDate>Fri, 19 Mar 2010 22:30:03 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Jared</title>
		<link>http://danielmiessler.com/blog/the-list-of-shame-websites-that-dont-allow-special-characters-in-their-passwords/comment-page-1#comment-49106</link>
		<dc:creator>Jared</dc:creator>
		<pubDate>Sat, 21 Apr 2007 16:28:40 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1289#comment-49106</guid>
		<description>&lt;p&gt;Matt you&#039;re right I haven&#039;t actually tried the feature since they changed it but the wording on the front page implies that it&#039;s still stored plain text. My bad.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Matt you&#8217;re right I haven&#8217;t actually tried the feature since they changed it but the wording on the front page implies that it&#8217;s still stored plain text. My bad.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://danielmiessler.com/blog/the-list-of-shame-websites-that-dont-allow-special-characters-in-their-passwords/comment-page-1#comment-48947</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Fri, 20 Apr 2007 20:10:32 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1289#comment-48947</guid>
		<description>&lt;p&gt;&quot;Becareful of taking a holier than thou attitude, while you can use special characters in reddit, they are stored plain text in their database despite the fact that their backups containing the passwords were stolen from the back of a van a few months ago.&quot;&lt;/p&gt;

&lt;p&gt;I believe you are mistaken. After they lost the backups and everyone yelled at them they implemented password hashing.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>&#8220;Becareful of taking a holier than thou attitude, while you can use special characters in reddit, they are stored plain text in their database despite the fact that their backups containing the passwords were stolen from the back of a van a few months ago.&#8221;</p>

<p>I believe you are mistaken. After they lost the backups and everyone yelled at them they implemented password hashing.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://danielmiessler.com/blog/the-list-of-shame-websites-that-dont-allow-special-characters-in-their-passwords/comment-page-1#comment-48946</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Fri, 20 Apr 2007 20:07:11 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1289#comment-48946</guid>
		<description>&lt;p&gt;This annoys me also.  I get angry when sites don&#039;t even allow spaces or punctuation.  I use phrases (around 3 or 4 words) for my passwords since they are easy to remember. The length also makes dictionary attacks infeasible, so I can use regular words.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>This annoys me also.  I get angry when sites don&#8217;t even allow spaces or punctuation.  I use phrases (around 3 or 4 words) for my passwords since they are easy to remember. The length also makes dictionary attacks infeasible, so I can use regular words.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: chris</title>
		<link>http://danielmiessler.com/blog/the-list-of-shame-websites-that-dont-allow-special-characters-in-their-passwords/comment-page-1#comment-48910</link>
		<dc:creator>chris</dc:creator>
		<pubDate>Fri, 20 Apr 2007 15:05:49 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1289#comment-48910</guid>
		<description>&lt;p&gt;Your post reminds me of this blog entry here:
http://blogs.ittoolbox.com/security/investigator/archives/look-at-all-of-these-passwords-11240&lt;/p&gt;

&lt;p&gt;It&#039;s just as important, if not more, to allow your visitors to login securely.  Even if your password was 27 characters and completely random, a sniffer will log it just as easily as a short, easy password.&lt;/p&gt;

&lt;p&gt;@Jared&lt;/p&gt;

&lt;p&gt;Bloglines stores their passwords in clear text, also.  I&#039;ve had to have them send it to me a couple of times and instead of sending me some random garbage, they send my real password to me.  Good security, indeed.&lt;/p&gt;

&lt;p&gt;That&#039;s why it&#039;s important to use different passwords.  If someone compromises one, they just have access to that one resource.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Your post reminds me of this blog entry here:
<a href="http://blogs.ittoolbox.com/security/investigator/archives/look-at-all-of-these-passwords-11240" rel="nofollow">http://blogs.ittoolbox.com/security/investigator/archives/look-at-all-of-these-passwords-11240</a></p>

<p>It&#8217;s just as important, if not more, to allow your visitors to login securely.  Even if your password was 27 characters and completely random, a sniffer will log it just as easily as a short, easy password.</p>

<p>@Jared</p>

<p>Bloglines stores their passwords in clear text, also.  I&#8217;ve had to have them send it to me a couple of times and instead of sending me some random garbage, they send my real password to me.  Good security, indeed.</p>

<p>That&#8217;s why it&#8217;s important to use different passwords.  If someone compromises one, they just have access to that one resource.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: yoshi</title>
		<link>http://danielmiessler.com/blog/the-list-of-shame-websites-that-dont-allow-special-characters-in-their-passwords/comment-page-1#comment-48902</link>
		<dc:creator>yoshi</dc:creator>
		<pubDate>Fri, 20 Apr 2007 14:15:36 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1289#comment-48902</guid>
		<description>&lt;p&gt;@E&lt;/p&gt;

&lt;p&gt;If is so trivial to implement than why -not- do it?&lt;/p&gt;

&lt;p&gt;Allowing a wider character set for the password allows the user to choose a complex passphrase that they are more likely to remember or more familiar with.  I&#039;ll bring up the example of the so called &quot;security questions&quot; (used by ING, BoA and half the world).  If asked for the &quot;City of your Birth&quot; and you can&#039;t enter in &quot;St. Louis&quot; because the tool won&#039;t allow the &quot;.&quot; (period) than I&#039;ve just created an exception to something I know and can remember.  The next time I&#039;m asked that question I&#039;ll screw it up.  This is basic usability.&lt;/p&gt;

&lt;p&gt;I find it interesting that we continue to argue about this topic.  Just the other day I attempted to log into an application and it wouldn&#039;t allow me in.  My first theory (and the correct one it turned out) was the back end system was an older Oracle system.  My password just happened to have an &#039;@&#039; sign in it.  Its 2007 and we can&#039;t even get escaping the password correct.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>@E</p>

<p>If is so trivial to implement than why -not- do it?</p>

<p>Allowing a wider character set for the password allows the user to choose a complex passphrase that they are more likely to remember or more familiar with.  I&#8217;ll bring up the example of the so called &#8220;security questions&#8221; (used by ING, BoA and half the world).  If asked for the &#8220;City of your Birth&#8221; and you can&#8217;t enter in &#8220;St. Louis&#8221; because the tool won&#8217;t allow the &#8220;.&#8221; (period) than I&#8217;ve just created an exception to something I know and can remember.  The next time I&#8217;m asked that question I&#8217;ll screw it up.  This is basic usability.</p>

<p>I find it interesting that we continue to argue about this topic.  Just the other day I attempted to log into an application and it wouldn&#8217;t allow me in.  My first theory (and the correct one it turned out) was the back end system was an older Oracle system.  My password just happened to have an &#8216;@&#8217; sign in it.  Its 2007 and we can&#8217;t even get escaping the password correct.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Jared</title>
		<link>http://danielmiessler.com/blog/the-list-of-shame-websites-that-dont-allow-special-characters-in-their-passwords/comment-page-1#comment-48899</link>
		<dc:creator>Jared</dc:creator>
		<pubDate>Fri, 20 Apr 2007 13:43:35 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1289#comment-48899</guid>
		<description>&lt;p&gt;&quot;The ones that stand out are the financially-oriented sites, obviously, but the fact that Digg doesn’t allow special characters just blows my mind (Reddit does). &quot;&lt;/p&gt;

&lt;p&gt;Becareful of taking a holier than thou attitude, while you can use special characters in reddit, they are stored plain text in their database despite the fact that their backups containing the passwords were stolen from the back of a van a few months ago.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>&#8220;The ones that stand out are the financially-oriented sites, obviously, but the fact that Digg doesn’t allow special characters just blows my mind (Reddit does). &#8220;</p>

<p>Becareful of taking a holier than thou attitude, while you can use special characters in reddit, they are stored plain text in their database despite the fact that their backups containing the passwords were stolen from the back of a van a few months ago.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Tim</title>
		<link>http://danielmiessler.com/blog/the-list-of-shame-websites-that-dont-allow-special-characters-in-their-passwords/comment-page-1#comment-48888</link>
		<dc:creator>Tim</dc:creator>
		<pubDate>Fri, 20 Apr 2007 12:55:59 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1289#comment-48888</guid>
		<description>&lt;p&gt;I remember once (a long long time ago) I was installing some version of linux, and when I put in my password for the root account it told me the password was too long and I had to pick another one.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>I remember once (a long long time ago) I was installing some version of linux, and when I put in my password for the root account it told me the password was too long and I had to pick another one.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: E</title>
		<link>http://danielmiessler.com/blog/the-list-of-shame-websites-that-dont-allow-special-characters-in-their-passwords/comment-page-1#comment-48859</link>
		<dc:creator>E</dc:creator>
		<pubDate>Fri, 20 Apr 2007 05:23:28 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1289#comment-48859</guid>
		<description>&lt;p&gt;Ok, maybe it&#039;s trivial to implement, but I don&#039;t think the benefits are much, for the reasons you mentioned. Plus, you are using a bad password generator if it doesn&#039;t allow you to change its settings to, e.g., not use special characters.&lt;/p&gt;

&lt;p&gt;What&#039;s much more shameful, imo, are corporations, etc. that make users change their passwords every month. That&#039;s absolutely terrible.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Ok, maybe it&#8217;s trivial to implement, but I don&#8217;t think the benefits are much, for the reasons you mentioned. Plus, you are using a bad password generator if it doesn&#8217;t allow you to change its settings to, e.g., not use special characters.</p>

<p>What&#8217;s much more shameful, imo, are corporations, etc. that make users change their passwords every month. That&#8217;s absolutely terrible.</p>]]></content:encoded>
	</item>
</channel>
</rss>
