Thursday 22 May 2014

eBay's hack highlights a short sighted password policy

For me, yesterday's big news was that yet another big website has fallen victim to hackers. This time it's eBay and so I dutifully logged in to change my password only to be confronted with a pathetic situation.

However I discovered that eBay's passwords can only be between 6 and 20 characters long. They don't tell you the upper limit any more but it's still there! 

This really annoys me massively because from a technical perspective, there's no reason they can't allow you to have any length password you want. The best current password advice is to use 4 unrelated words together as a password, allowing much longer passwords is dramatically safer and my passwords are routinely over 20 characters long.

eBay's page about the security breach says "We take security on eBay very seriously" and "our team is committed to making eBay as safe and secure as possible" - I'm thinking longer passwords would increase the security.

No comments:

Post a Comment