Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The tragicomic part is how they enforcing password complexity:

Your password is not strong enough. New passwords must: Be at least six characters long Contain one or more numbers Include at least one of the following special characters: !"#$%&'()*+,-./:;<=>?@[\]^_`{|}~, or a space

So password efZeLmur3ivio4t7 is not safe enough to be used by last.fm and they use md5 without salt to protect it?



A password that follows that "security scheme" is pass1!, which KeePass 2 reports as having a quality of 18 bits. efZeLmur3ivio4t7, an illegal password, has a quality of 86 bits. Whoever was responsible for that decision should be fired. Either implement a real password strength algorithm based on entropy, or don't implement any except maybe minimum length.


not just fired, but shot dead :-)


This was in 2012. Their password enforcement policies were most likely different back then.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: