SitePoint Sponsor

User Tag List

Results 1 to 7 of 7

Thread: page with two passwords

  1. #1
    SitePoint Addict
    Join Date
    Oct 2005
    Posts
    214
    Mentioned
    1 Post(s)
    Tagged
    0 Thread(s)

    page with two passwords

    Here's an out-of-the-box thought. What if I require more than one password on my sign-in page? Would that confound the phishing bots? (If so, then I could even allow the client to enter relatively easily remembered passwords).

    grNadpa

  2. #2
    dooby dooby doo silver trophybronze trophy
    spikeZ's Avatar
    Join Date
    Aug 2004
    Location
    Manchester UK
    Posts
    13,535
    Mentioned
    79 Post(s)
    Tagged
    3 Thread(s)
    Isn't 2 passwords really just the same as username + password combination or do you mean that users have to remember 3 things?!
    Mike Swiffin - Community Team Leader

    Only a woman can read between the lines of a one word answer.....
    I started out with nothing... and still got most of it left!

  3. #3
    SitePoint Addict
    Join Date
    Oct 2005
    Posts
    214
    Mentioned
    1 Post(s)
    Tagged
    0 Thread(s)
    Quote Originally Posted by spikeZ View Post
    Isn't 2 passwords really just the same as username + password combination or do you mean that users have to remember 3 things?!
    My point is that the malicious software phising bots expect just one password in addition to the username. Hence the bizarre requirements for developing passwords (e.g. 8 characters, uppercase, lower case, number, special characters) as protection.

    Adding a second password (or as you put it "remember 3 things") I'm thinking would defeat these bots because, even it it guesses one of the passwords, it's not expecting a second one -- and therefore will fail to break into the site.

    As such, the passwords need not be so complex.

    grNadpa

  4. #4
    ¬.¬ shoooo... silver trophy logic_earth's Avatar
    Join Date
    Oct 2005
    Location
    CA
    Posts
    8,974
    Mentioned
    7 Post(s)
    Tagged
    0 Thread(s)
    Afraid it would just making things more complicated for your users. Your users alone are responsible for creating strong passwords and managing them. Its not yours. The only thing you have to do is store them in a secure matter. And those bots could easily adapt to the change anyways.
    Logic without the fatal effects.
    All code snippets are licensed under WTFPL.


  5. #5
    Unobtrusively zen silver trophybronze trophy
    SitePoint Award Recipient paul_wilkins's Avatar
    Join Date
    Jan 2007
    Location
    Christchurch, New Zealand
    Posts
    14,162
    Mentioned
    39 Post(s)
    Tagged
    0 Thread(s)
    Quote Originally Posted by Grnadpa View Post
    Adding a second password (or as you put it "remember 3 things") I'm thinking would defeat these bots because, even it it guesses one of the passwords, it's not expecting a second one -- and therefore will fail to break into the site.

    As such, the passwords need not be so complex.
    Sadly, exactly the opposite thing will happen. Your strange and odd security measures will attract the attention of all sorts, resulting in special attention being paid to your site from groups who attempt to automate their way around such things.

    Your best bet to avoid notice is to apply the same best practice techniques that others use. Those are the most reliably known ways to reman secure without annoying your uses too much.
    Programming Group Advisor
    Reference: JavaScript, Quirksmode Validate: HTML Validation, JSLint
    Car is to Carpet as Java is to JavaScript

  6. #6
    SitePoint Member
    Join Date
    Apr 2013
    Posts
    7
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Nothing is impossible for a malicious software trying to detect a password. Even if you put something new, you would rather attract the attention of programmers as you are the founder of this innovation. They would go to far ends just to crack this challenge! In regards to the security, if you use md5 encryption, and if you instruct your users to create a difficult password with a combination of symbols, letters and numbers, with NO word from the english dictionary and no numbers in a proper sequence, there is no way a malware can decrypt it. This is because the encrypted code of every password keeps changing and only your server will be aware of the combination. Not even you!

  7. #7
    SitePoint Wizard
    Join Date
    Oct 2007
    Location
    Boston, MA
    Posts
    1,353
    Mentioned
    2 Post(s)
    Tagged
    0 Thread(s)
    Too complicated, some people wouldn`t bother remembering those passwords. Just use a good captcha along with the password, like skrill.com does and you should be fine. But no way 2 passwords.

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •