Jacob Aron, reporter
"Give me letters two, three and six from your password," is a request Brits who bank online will be very familiar with, as most UK banks use this kind of partial password authentication. The idea is to prevent someone from snooping on your entire password at once, theoretically offering more protection - but now it seems the scheme may not actually work.
David Aspinall of the University of Edinburgh and Mike Just of Glasgow Caledonian University, UK used real-world passwords from a leak in 2009 to see just how easy it is to guess a partial password. Crucially, some passwords are more common than others, and some letters crop up in certain positions more regularly than the rest.
For example, "a" was the second character in the leaked database's eight-letter passwords nearly 20 per cent of the time, while "password" was the most-used password. Putting these together, if I see you enter "s", "w" and "r" for the fourth, fifth and seventh letters of your password, I can take a pretty good guess at what the rest are.
Overall the pair found they could have guessed a 10-character password over 80 per cent of the time after watching just four partial password attempts. An attacker could easily gain this information by installing a keylogger on your computer or even just watching over your shoulder.
Aspinall and Just surveyed the major British banks, as well as banks in other countries that use partial passwords, and found that some were too reliant on the technique, using it in combination with other easy-to-spoof details like credit cards, birthdates and short PINs, or even with nothing else at all.
"Our guess is that a bank using something like a short PIN as the first level of authentication is hoping for some additional level of security from the partial passwords," says Just, who will present the research at the Financial Cryptography and Data Security conference in Okinawa, Japan, in April. "In these cases, I'd have a little concern."
- Board index
- Search
-
- It is currently Wed Jun 18, 2025 10:55 pm
- All times are UTC+05:30
Bank's partial passwords are easy to guess
General Discussions
Return to “General Discussions”
Jump to
- Programmable Electronics
- ↳ Arduino
- ↳ Raspberry Pi
- ↳ Microcontrollers
- ↳ FPGA
- ↳ Digital Signal Processors
- ↳ Other
- Programming
- ↳ Web programming
- ↳ PHP & MySQL
- ↳ ASP & ASP.Net
- ↳ .Net & Other Programming
- ↳ .NET Programming
- ↳ Visual Basic Programming
- ↳ Java Programming
- ↳ C/C++ Programming
- Engineering
- ↳ Electronics & Electrical Engineering
- ↳ Embedded Systems
- ↳ Computer Science
- ↳ Software Engineering
- ↳ Data Structures & Algorithms
- ↳ Programming Languages & Compiler Theory
- ↳ Operating Systems
- ↳ Cryptography
- ↳ Computer Networks
- ↳ SQL & Database
- ↳ Computer Architecture
- ↳ Graphics & Vision
- ↳ Artificial Intelligence
- ↳ Neural Networks
- ↳ Multimedia
- ↳ Mathematics
- ↳ Other
- ↳ Control Systems & Robotics
- ↳ Mechanical
- ↳ Thermodynamics
- ↳ Fluid Dynamics
- ↳ Aerodynamics
- ↳ Manufacturing
- ↳ Energy
- ↳ Dynamics
- ↳ Statics
- ↳ Automobile
- ↳ Other
- ↳ Other
- Operating Systems
- ↳ Windows
- ↳ Linux
- ↳ Mac OS
- ↳ Android
- ????? ????
- ↳ ???????? ?????
- ↳ ??????? ???? ?????
- ↳ ????? ?????? ???? (Buy Guide)
- ↳ ??????? ???? ??????? (Where to buy)
- ↳ ????????? ???????? (Recommend - Complain - Review)
- General
- ↳ News & Announcements
- ↳ General Discussions
- ↳ Viruses, Trojans, Spyware and Adware
- ↳ Computer & Network Security
- ↳ Web Related
- Members Zone
- ↳ Project Assistance
- ↳ Advertising
- ↳ Jobs & Investment Opportunities
- ↳ Introductions
- ↳ Presents & Donations
- ↳ Entertainment
- ↳ Music & Albums
- ↳ Movies
- ↳ Games