Password for log in not case sensitive

Locked
Dark Lord Shaitan
Fledgling Forumer
Posts: 211
Joined: Sat Dec 09, 2006 3:27 pm
Race: System Lord
ID: 53511
Location: Right behind you, with a knife.
Contact:

Password for log in not case sensitive

Maybe I am wrong with this, but I always thought the passwords we put in were case sensitive. At work, our comps are set with caps locked, and well went through the usual log in, and it went through.
The eternal struggle of mankind is,
to survive adversity,
and excel at diplomacy.
All else fails, NUKE EM!

Image
Image




User avatar
Juliette
Verified
The Queen
Posts: 31802
Joined: Sun Feb 06, 2005 6:57 pm
Race: Royalty
ID: 4323
Alternate name(s): Cersei Lannister
Location: Ultima Thule

Re: Password for log in not case sensitive

Thought they always were case-insensitive? :)
Image
Dark Lord Shaitan
Fledgling Forumer
Posts: 211
Joined: Sat Dec 09, 2006 3:27 pm
Race: System Lord
ID: 53511
Location: Right behind you, with a knife.
Contact:

Re: Password for log in not case sensitive

I always thought they were case sensitive for players security from possible "hacks." If not then maybe they should be?
The eternal struggle of mankind is,
to survive adversity,
and excel at diplomacy.
All else fails, NUKE EM!

Image
Image




Dark Lord Shaitan
Fledgling Forumer
Posts: 211
Joined: Sat Dec 09, 2006 3:27 pm
Race: System Lord
ID: 53511
Location: Right behind you, with a knife.
Contact:

Re: Password for log in not case sensitive

I have brought this issue back to the first page, since I remember telling admin about it in a meeting a few months back and that he would look into it. And it seems that it still has not been worked on, or changed.
The eternal struggle of mankind is,
to survive adversity,
and excel at diplomacy.
All else fails, NUKE EM!

Image
Image




User avatar
Child of the wolf
Forum Newbie
Posts: 48
Joined: Sun Dec 16, 2007 7:56 pm
Race: Wolf
ID: 1922723

Re: Password for log in not case sensitive

SGW pass words have never been case sensitive, though yes, I think they should be as well.
Previous sigs
Image

Image

Image
Harlequin
Fledgling Forumer
Posts: 157
Joined: Wed Dec 19, 2007 11:29 am
Alliance: Alcoholics Anonymous
ID: 0
Location: Cambridge, UK

Re: Password for log in not case sensitive

Case insensitivity suggests that the passwords are either converted to entirely lowercase and hashed and the password you enter into the login form converted+hashed; or they are stored their raw form.

The latter means that the password you use for SGW can be read by anyone with database access, legally or otherwise.

The former is not without faults, either. Any attacker is safe in the knowledge that case is irrelevant, thus excluding 26 possible characters from their search. This is quite a serious issue, and I hope it is addressed by the admin.
Image
Locked

Return to “Bugs Archive”