|
|
这个评论写的不错:
–]
bob
TUESDAY, JUNE 5, 2012 AT 3:26 PM
Yes. It’s been a while since I worked in security, but I remember it struck me as strange when Westpac changed from their 8 character case-sensitive password to a 6 character case-insensitive password. That basically means that although they’re (most likely) storing it in encrypted form, it’s two-way encrypted which means that it’s reversable, i.e. someone could take the encrypted garbage string from their database, and with the right private key, decrypt it. That’s the only way they could have translated my case-sensitive password into a case insensitive one, or compare my case-insensitive input via their little keyboard thingy with the case-sensitive encrypted version. Sooooo crap. They should always do it in one direction, i.e. encrypt the password to store it, and then encrypt the attempt and compare the two encrypted strings. |
|