Forum Settings
Forums

Password requirements - are passwords stored in clear text?

New
May 11, 2018 10:58 AM
#1
Offline
Jan 2016
1
I'm going through all my accounts on the Web and upgrading their security. Today landed me on MAL.

So I went to change my password. These days I use my password manager to generate a long, random password and 'remember' it for me. I did just that, and...



I was quite surprised to see this. A 290-bit entropy password ends up rejected, because it's... too strong? This concerns me for two reasons.
1. User password complexity is being kind of limited. Now I'll admit, 290 bits of entropy is a bit on the ridiculous side, but that's mostly because of length - I didn't even include weird non-ASCII characters in the mix, which I usually do.
2. The limitations on the acceptable characters in a password suggest to me that they may be stored in clear text in a database. Of course, I can't say for sure that they are, but if they were not, then these limitations wouldn't make sense - anything that goes through a hashing function comes out the other end in a known, small character set anyway.

What is the reason behind the limitations on characters in passwords?
May 14, 2018 6:02 AM
#2
Lead Admin
Faerie Queen

Offline
Aug 2007
6423
Passwords are not stored in clear text.

outfrost said:
What is the reason behind the limitations on characters in passwords?
The special characters were restricted to those which appear on a standard US keyboard because the majority of our users are from English-speaking countries (with an emphasis on the US). There wasn't a very specific reason behind it other than "many websites restrict passwords to ASCII characters" and "most people probably won't use chars not in a standard US keyboard". I think you're reading too much into it :)

Since many casual users are also increasingly moving away from desktop and towards mobile devices, which often have even more limited keyboards (without installing extra packages), it makes reasonable sense to me.
KinetaMay 14, 2018 6:08 AM
May 14, 2018 6:12 PM
#3
Offline
Nov 2013
22
I'd rather argue that with more and more people using password managers (hopefully), this will only increase.

Why spend extra effort to block these characters? True, most won't use them, but it's really annoying for those that do wan't a bit of a stronger password. I'd understand if you don't want to allow all Unicode characters, but the characters shown ("@$#&()%) are both perfectly fine ASCII and present on standard US keyboards?

What it all boils down to, why force people to less secure passwords just because "most websites do", while allowing secure passwords should really not be a problem (which it isn't as long as you pull them through a hash function).
May 14, 2018 6:22 PM
#4

Offline
Apr 2017
2694
my password was asdasd123 for like the first year of being on mal, then i changed it to my birthday

now i don't know what my password is


nobody cares enough to hack someone on an anime listing site, you're good
May 14, 2018 7:03 PM
#5

Offline
May 2018
20
sekai- said:
nobody cares enough to hack someone on an anime listing site, you're good


Not true. Many people unfortunately use only one password for every site they have an account on so hackers will more often try places where their isn't big security and then try this same password elsewhere (Facebook account, Mail, Google and others). So it's not because you are on an anime listing site that you are safe.

But in any case, if you have many passwords (one for every service you use or at least more than one) it shouldn't be that easy. Also having double identification on sites is a good idea to help secure your accounts.
DrYibuuMay 14, 2018 7:09 PM
May 14, 2018 7:07 PM
#6

Offline
Apr 2017
2694
DrYibuu said:
sekai- said:
nobody cares enough to hack someone on an anime listing site, you're good


Not true. Many people unfortunately use only one password for every site they have an account on so hackers will more often try places where their isn't big security and then try this same password else where (Facebook account, Mail, Google and others). So it's not because you are on an anime listing site that you are safe.

Ye but they'd have to be some good hackers to find out a password that even I dunno

I had this problem like a month ago so I changed it but I forgot again

I think the hackers just feel bad for me then
May 14, 2018 7:10 PM
#7
Offline
Jan 2013
10764
sekai- said:
my password was asdasd123 for like the first year of being on mal, then i changed it to my birthday

now i don't know what my password is


nobody cares enough to hack someone on an anime listing site, you're good
you joke bout that but I've seen a few russian hackers posting from dead accounts now that's spooky
gone bai bai
May 14, 2018 7:13 PM
#8

Offline
Apr 2017
2694
Mkim said:
sekai- said:
my password was asdasd123 for like the first year of being on mal, then i changed it to my birthday

now i don't know what my password is


nobody cares enough to hack someone on an anime listing site, you're good
you joke bout that but I've seen a few russian hackers posting from dead accounts now that's spooky

Not joking at all

Please Russian hackers, do ur worst

High key tho I really should change it

Later, I'll do it later
May 14, 2018 7:14 PM
#9

Offline
May 2018
20
sekai- said:
Ye but they'd have to be some good hackers to find out a password that even I dunno


No, it depends on many factors and one of them is out of our control. It's mainly how they stock our passwords on their ends just like outfrost said. If it's in clear text, the problem is for everyone, not just a few users.
May 14, 2018 7:18 PM

Offline
Apr 2017
2694
DrYibuu said:
sekai- said:
Ye but they'd have to be some good hackers to find out a password that even I dunno


No, it depends on many factors and one of them is out of our control. It's mainly how they stock our passwords on their ends just like outfrost said. If it's in clear text, the problem is for everyone, not just a few users.

So it's outta my control either way I guess

I don't really have any valuable accs anyway so they'd just be wasting their time

More topics from this board

» How can I see the date I added an entry to my list? (if I didn't mark an episode as watched)

EterTC - Feb 14, 2023

20 by hacker09 »»
6 hours ago

» unable to reach "about me design"

Darkzepheran - Yesterday

4 by Darkzepheran »»
10 hours ago

» Do MyAnimeList uses awstrack.me in email links?

CheeseBreeze - Yesterday

1 by -DxP- »»
Today, 2:37 AM

» App Not Working

Reecey91 - Yesterday

8 by Reecey91 »»
Today, 12:42 AM

» MAL Signature site is not working?

UKhira - Oct 5

5 by Alexioos95 »»
Oct 6, 7:33 AM
It’s time to ditch the text file.
Keep track of your anime easily by creating your own list.
Sign Up Login