VideoLAN @videolan App Stores were a mistake. Currently, we cannot update VLC on Windows Store, and we cannot update VLC on Android Play Store, without reducing security or dropping a lot of users… For now, iOS App Store still allows us to ship for iOS9, but until when?

You are viewing a single thread.
View all comments View context
92 points

Banks are okay with it, but VLC feel more strongly than banks.

I mean banks are known for horrible security practices all around so that makes perfect sense.

permalink
report
parent
reply
3 points

Are they?

permalink
report
parent
reply
24 points

My bank restricts the length of my password to…16 characters, I think.

permalink
report
parent
reply
27 points

Mine only uses a 4-to-6 digit pin as a password, and sms for 2fa

permalink
report
parent
reply
14 points

Darren Kitchen from Hak5 has an amusing story about a bank teller who assured him email was entirely fine to send sPII through. “No sir, you just need to send it to us, and once we have your information then it’ll be secure.” No encryption. So, yes.

Also look into the Equifax security breach. Un-patched software for months.

It makes almost no sense to have a password length limit. 1_000_000, that’s One Million, characters is equal to 1MiB. That’s twice the length of the Lord of the Rings Trilogy and much less than most modern webpages. After hashing, which is how passwords should be stored, text length is irrelevant. All hashed inputs come out the exact same length. 65 characters for SHA256.

Very much known for their horrible security practices, yes. Absolutely.

permalink
report
parent
reply
10 points
*

Setting a max password length is sometimes done to prevent ddos attacks. Without it, attackers could just spam 1MB passwords constantly and force the login server to just spend all its cpu time hashing garbage.

That being said, a password limit of under 20 characters probably just means they are just storing passwords in plaintext.

permalink
report
parent
reply
13 points

Absolutely. They are entrenched in their regulations so much that it takes forever to change things.

Years ago, I had an account at an american big4 bank with an 8 character password and was going through and making all my passwords unique. I was changing everything to random strings of 20-30 characters (this isnt the best practice, btw, but still better than 8chars), so when I get to this bank account it capped me at 15chars. I couldnt believe the forced low entropy they gave me for something as vital as a bank account.

I asked them why, and basically they said their system would break with anything over 15chars.

permalink
report
parent
reply
2 points

How many wrong guesses were you allowed before the system would lock your account?

permalink
report
parent
reply
1 point

The equivalent of a 20-30 character random password with numbers and characters is a 7-11 word passphrase. Seeing how passphrase generators default to 4-5 words (equivalent to 11-14 characters) what you did isn’t so bad

permalink
report
parent
reply
-24 points

Be your own bank, use monero.

permalink
report
parent
reply
8 points

Who do you think makes the decisions for a bank?

The person writing the Android app?

Or the person who just wants customers to be able to access the app and use the services?

permalink
report
parent
reply
4 points
*

Banks have laws and regulations that they must abide by to secure the access to and information of customer accounts. A security team will surely have to sign off on whatever the app developer or customer experience manager wants to implement.

permalink
report
parent
reply

Privacy

!privacy@lemmy.ml

Create post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

Community stats

  • 4.6K

    Monthly active users

  • 2.9K

    Posts

  • 77K

    Comments