Index  | Recent Threads  | Unanswered Threads  | Who's Active  | Guidelines  | Search
 

Quick Go »
No member browsing this thread
Thread Status: Active
Total posts in this thread: 7
[ Jump to Last Post ]
Post new Thread
Author
Previous Thread This topic has been viewed 587 times and has 6 replies Next Thread
TheSwedishLord
Cruncher
Joined: Jun 3, 2012
Post Count: 1
Status: Offline
Project Badges:
Reply to this Post  Reply with Quote 
Password only 15 characters?

Why can't WCG accept longer passwords than 15 characters? That forces me to use a much less safe password than I normally would use.

Please fix ASAP so we can use longer password than 15 characters!


/Henke
----------------------------------------
[Edit 1 times, last edit by port513 at Mar 9, 2013 1:53:29 PM]
[Mar 9, 2013 1:52:23 PM]   Link   Report threatening or abusive post: please login first  Go to top 
Former Member
Cruncher
Joined: May 22, 2018
Post Count: 0
Status: Offline
Reply to this Post  Reply with Quote 
Re: Password only 15 characters?

Opinions differ on the matter but if you google on safe passwords lengths and consider the context of what we do here [not banking money], 15 is considered well and truly sufficient. A good mix of random letters and numbers and using capitals and small interspersed gives you one Ford Knox security would accept. For the moment, don't think anyone is interested to do a brute force attack on the BOINC crunching accounts to steel the points, or hijack your account. A brief wiki article for reference: http://en.wikipedia.org/wiki/Password_strength

BTW, I've got a free program called Keepass in which you can test a passwords bit-strength, 15 characters gives easily 80 bit hardened passwords, and that's only alphanumeric. You'd need a supercomputer equivalent to crack that or lots of time, by which higher number of attempts IBM will long have locked the account and send interpol out to catch the villain.
[Mar 9, 2013 4:32:43 PM]   Link   Report threatening or abusive post: please login first  Go to top 
Former Member
Cruncher
Joined: May 22, 2018
Post Count: 0
Status: Offline
Reply to this Post  Reply with Quote 
Re: Password only 15 characters?

P.S. Never ever use a password in 2 places [though if you use the central control BOINC Account Manager, it is advisable for all BOINC projects]. The password used in BOINC world is strongly advised to only apply to BOINC world, will it never expose anything else you do on the internet. Also the use of an email address for the sole purpose of using in the Grid computing world, a jettable email account so to speak, would add to your security.
[Mar 9, 2013 4:41:38 PM]   Link   Report threatening or abusive post: please login first  Go to top 
cjslman
Master Cruncher
Mexico
Joined: Nov 23, 2004
Post Count: 2082
Status: Offline
Project Badges:
Reply to this Post  Reply with Quote 
Re: Password only 15 characters?

Most organizations consider 8 characters the minimum necessary for a password. A 15 character password is more than enough secure.

CJSL

Crunching for a better future...
----------------------------------------
I follow the Gimli philosophy: "Keep breathing. That's the key. Breathe."
Join The Cahuamos Team


[Mar 10, 2013 3:54:59 AM]   Link   Report threatening or abusive post: please login first  Go to top 
rilian
Veteran Cruncher
Ukraine - we rule!
Joined: Jun 17, 2007
Post Count: 1442
Status: Offline
Project Badges:
Reply to this Post  Reply with Quote 
Re: Password only 15 characters?

"640kb ought to be enough for anybody" (c)

if WCG limits password length, then probably password is stored in unencrypted/unsalted way

Also now appear a lot of software that produce a hash from your user-input password, and you use this hash on sites, instead of using user-generated password
----------------------------------------
[Mar 10, 2013 11:21:05 AM]   Link   Report threatening or abusive post: please login first  Go to top 
cjslman
Master Cruncher
Mexico
Joined: Nov 23, 2004
Post Count: 2082
Status: Offline
Project Badges:
Reply to this Post  Reply with Quote 
Re: Password only 15 characters?

I would be really surprised if users passwords of this site weren't encrypted... but let's ask the techs: Are our passwords encrypted?

CJSL

Crunching for a better tomorrow...
----------------------------------------
I follow the Gimli philosophy: "Keep breathing. That's the key. Breathe."
Join The Cahuamos Team


[Mar 11, 2013 3:35:02 AM]   Link   Report threatening or abusive post: please login first  Go to top 
Former Member
Cruncher
Joined: May 22, 2018
Post Count: 0
Status: Offline
Reply to this Post  Reply with Quote 
Re: Password only 15 characters?

What you think about WCG being the only BOINC project using https instead of http to connect ;?
[Mar 11, 2013 9:29:52 AM]   Link   Report threatening or abusive post: please login first  Go to top 
[ Jump to Last Post ]
Post new Thread