Settings

Theme

Why Autocorrect for Passwords Is a Great Idea

technologyreview.com

1 points by valhalla 10 years ago · 3 comments

Reader

nathan_long 10 years ago

Assuming they're right, if you don't store passwords in the clear, you'd have to build all acceptable variants of a password when you get the original, then hash and store all of them, then check them all at next login attempt.

If you wanted to add a new kind of "allowable typo" (eg "correct except with capslock") you'd have to wait until the user next logged in to store that variant.

green_lunch 10 years ago

“Websites should be changing their password policies to make users’ lives easier. The security degradation is pretty small.”

Security isn't supposed to be convenient. Autocorrecting passwords sounds like a bad idea all-around and will be exploited.

  • valhallaOP 10 years ago

    According to the article, they ran simulations and it only provided a .2% increase in likelihood of a breach

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection