Feed aggregator
Microsoft Forms Superintelligence Team Under AI Chief Suleyman 'To Serve Humanity'
Read more of this story at Slashdot.
iOS 26.2 to Allow Third-Party App Stores in Japan Ahead of Regulatory Deadline
Read more of this story at Slashdot.
Cloudflare Tells US Govt That Foreign Site Blocking Efforts Are Digital Trade Barriers
Read more of this story at Slashdot.
Amazon is Testing an AI Tool That Automatically Translates Books Into Other Languages
Read more of this story at Slashdot.
Google Plans Secret AI Military Outpost on Tiny Island Overrun By Crabs
Read more of this story at Slashdot.
FBI Subpoenas Registrar for Details on Anonymous Archiving Site Owner
Read more of this story at Slashdot.
Trump AI Czar Says 'No Federal Bailout For AI' After OpenAI CFO's Comments
Read more of this story at Slashdot.
A New White-Collar Gig Economy: Training AI To Take Over
Read more of this story at Slashdot.
Why Manufacturing's Last Boom Will Be Hard To Repeat
Read more of this story at Slashdot.
Automattic Inc. Claims It Owns the Word 'Automatic'
Read more of this story at Slashdot.
OpenAI CFO Says Company Isn't Seeking Government Backstop, Clarifying Prior Comment
Read more of this story at Slashdot.
US Software Firm SAS Exits China After 25 Years
Read more of this story at Slashdot.
Thousands of Flights in Danger of Cancellation as FAA Announces Major Cuts
Read more of this story at Slashdot.
'Grand Theft Auto' Studio Says Fired Employees Were Leaking Information
Read more of this story at Slashdot.
Nvidia's Jensen Huang Says China 'Will Win' AI Race With US
Read more of this story at Slashdot.
Manufacturer Bricks Smart Vacuum After Engineer Blocks It From Collecting Data
Read more of this story at Slashdot.
China Delays Shenzhou-20 Crew Return After Suspected Space Debris Impact
Read more of this story at Slashdot.
Universe Expansion May Be Slowing, Not Accelerating, Study Suggests
Read more of this story at Slashdot.
Secure to Great Lengths
Our submitter, Gearhead, was embarking on STEM-related research. This required him to pursue funding from a governmental agency that we’ll call the Ministry of Silly Walks. In order to start a grant application and track its status, Gearhead had to create an account on the Ministry website.
The registration page asked for a lot of personal information first. Then Gearhead had to create his own username and password. He used his password generator to create a random string: D\h.|wAi=&:;^t9ZyoO
Upon clicking Save, he received an error.
Your password must be a minimum eight characters long, with no spaces. It must include at least three of the following character types: uppercase letter, lowercase letter, number, special character (e.g., !, $, % , ?).
Perplexed, Gearhead emailed the Ministry’s web support, asking why his registration failed. The reply:
Hello,The site rejects password generators as hacking attempts. You will need to manually select a password.
Ex. GHott*01
Thank you,
Support
So a long sequence of random characters was an active threat, but a 1990s-era AOL username was just fine. What developer had this insane idea and convinced other people of it? How on earth did they determine what was a "manually selected" string versus a randomly-generated one?
It seems the deciding factor is nothing more than length. If you go to the Ministry’s registration page now, their password guidelines have changed (emphasis theirs):
Must be 8-10 characters long, must contain at least one special character ( ! @ # $ % ^ & * ( ) + = { } | < > \ _ - [ ] / ? ) and no spaces, may contain numbers (0-9), lower and upper case letters (a-z, A-Z). Please note that your password is case sensitive.
Only good can come of forcing tiny passwords.
The more a company or government needs secure practices, the less good they are at secure practices. Is that a law yet? It should be.
[Advertisement] Plan Your .NET 9 Migration with ConfidenceYour journey to .NET 9 is more than just one decision.Avoid migration migraines with the advice in this free guide. Download Free Guide Now!
A New Ion-Based Quantum Computer Makes Error Correction Simpler
Read more of this story at Slashdot.
