<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>dmiessler.com | grep understanding - Latest Comments in The List Of Shame: Websites That Don&amp;#8217;t Allow Special Characters In Their Passwords</title><link>http://danielrm26.disqus.com/</link><description>dmiessler.com/about/</description><language>en</language><lastBuildDate>Sat, 21 Apr 2007 12:28:40 -0000</lastBuildDate><item><title>Re: The List Of Shame: Websites That Don&amp;#8217;t Allow Special Characters In Their Passwords</title><link>http://dmiessler.com/blog/the-list-of-shame-websites-that-dont-allow-special-characters-in-their-passwords#comment-4353841</link><description>Matt you're right I haven't actually tried the feature since they changed it but the wording on the front page implies that it's still stored plain text. My bad.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Jared</dc:creator><pubDate>Sat, 21 Apr 2007 12:28:40 -0000</pubDate></item><item><title>Re: The List Of Shame: Websites That Don&amp;#8217;t Allow Special Characters In Their Passwords</title><link>http://dmiessler.com/blog/the-list-of-shame-websites-that-dont-allow-special-characters-in-their-passwords#comment-4353843</link><description>"Becareful of taking a holier than thou attitude, while you can use special characters in reddit, they are stored plain text in their database despite the fact that their backups containing the passwords were stolen from the back of a van a few months ago."&lt;br&gt;&lt;br&gt;I believe you are mistaken. After they lost the backups and everyone yelled at them they implemented password hashing.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Matt</dc:creator><pubDate>Fri, 20 Apr 2007 16:10:32 -0000</pubDate></item><item><title>Re: The List Of Shame: Websites That Don&amp;#8217;t Allow Special Characters In Their Passwords</title><link>http://dmiessler.com/blog/the-list-of-shame-websites-that-dont-allow-special-characters-in-their-passwords#comment-4353842</link><description>This annoys me also.  I get angry when sites don't even allow spaces or punctuation.  I use phrases (around 3 or 4 words) for my passwords since they are easy to remember. The length also makes dictionary attacks infeasible, so I can use regular words.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Matt</dc:creator><pubDate>Fri, 20 Apr 2007 16:07:11 -0000</pubDate></item><item><title>Re: The List Of Shame: Websites That Don&amp;#8217;t Allow Special Characters In Their Passwords</title><link>http://dmiessler.com/blog/the-list-of-shame-websites-that-dont-allow-special-characters-in-their-passwords#comment-4353844</link><description>Your post reminds me of this blog entry here:&lt;br&gt;&lt;a href="http://blogs.ittoolbox.com/security/investigator/archives/look-at-all-of-these-passwords-11240" rel="nofollow"&gt;http://blogs.ittoolbox.com/security/investigato...&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;It's just as important, if not more, to allow your visitors to login securely.  Even if your password was 27 characters and completely random, a sniffer will log it just as easily as a short, easy password.&lt;br&gt;&lt;br&gt;&lt;br&gt;@Jared&lt;br&gt;&lt;br&gt;Bloglines stores their passwords in clear text, also.  I've had to have them send it to me a couple of times and instead of sending me some random garbage, they send my real password to me.  Good security, indeed.&lt;br&gt;&lt;br&gt;That's why it's important to use different passwords.  If someone compromises one, they just have access to that one resource.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">chris</dc:creator><pubDate>Fri, 20 Apr 2007 11:05:49 -0000</pubDate></item><item><title>Re: The List Of Shame: Websites That Don&amp;#8217;t Allow Special Characters In Their Passwords</title><link>http://dmiessler.com/blog/the-list-of-shame-websites-that-dont-allow-special-characters-in-their-passwords#comment-4353846</link><description>@E&lt;br&gt;&lt;br&gt;If is so trivial to implement than why -not- do it?&lt;br&gt;&lt;br&gt;Allowing a wider character set for the password allows the user to choose a complex passphrase that they are more likely to remember or more familiar with.  I'll bring up the example of the so called "security questions" (used by ING, BoA and half the world).  If asked for the "City of your Birth" and you can't enter in "St. Louis" because the tool won't allow the "." (period) than I've just created an exception to something I know and can remember.  The next time I'm asked that question I'll screw it up.  This is basic usability.&lt;br&gt;&lt;br&gt;I find it interesting that we continue to argue about this topic.  Just the other day I attempted to log into an application and it wouldn't allow me in.  My first theory (and the correct one it turned out) was the back end system was an older Oracle system.  My password just happened to have an '@' sign in it.  Its 2007 and we can't even get escaping the password correct.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">yoshi</dc:creator><pubDate>Fri, 20 Apr 2007 10:15:36 -0000</pubDate></item><item><title>Re: The List Of Shame: Websites That Don&amp;#8217;t Allow Special Characters In Their Passwords</title><link>http://dmiessler.com/blog/the-list-of-shame-websites-that-dont-allow-special-characters-in-their-passwords#comment-4353845</link><description>"The ones that stand out are the financially-oriented sites, obviously, but the fact that Digg doesn’t allow special characters just blows my mind (Reddit does). "&lt;br&gt;&lt;br&gt;Becareful of taking a holier than thou attitude, while you can use special characters in reddit, they are stored plain text in their database despite the fact that their backups containing the passwords were stolen from the back of a van a few months ago.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Jared</dc:creator><pubDate>Fri, 20 Apr 2007 09:43:35 -0000</pubDate></item><item><title>Re: The List Of Shame: Websites That Don&amp;#8217;t Allow Special Characters In Their Passwords</title><link>http://dmiessler.com/blog/the-list-of-shame-websites-that-dont-allow-special-characters-in-their-passwords#comment-4353847</link><description>I remember once (a long long time ago) I was installing some version of linux, and when I put in my password for the root account it told me the password was too long and I had to pick another one.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Tim</dc:creator><pubDate>Fri, 20 Apr 2007 08:55:59 -0000</pubDate></item><item><title>Re: The List Of Shame: Websites That Don&amp;#8217;t Allow Special Characters In Their Passwords</title><link>http://dmiessler.com/blog/the-list-of-shame-websites-that-dont-allow-special-characters-in-their-passwords#comment-4353848</link><description>Ok, maybe it's trivial to implement, but I don't think the benefits are much, for the reasons you mentioned. Plus, you are using a bad password generator if it doesn't allow you to change its settings to, e.g., not use special characters.&lt;br&gt;&lt;br&gt;What's much more shameful, imo, are corporations, etc. that make users change their passwords every month. That's absolutely terrible.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">E</dc:creator><pubDate>Fri, 20 Apr 2007 01:23:28 -0000</pubDate></item></channel></rss>