in reply to Re^6: Mind the meta! (case, DBs)
in thread Mind the meta!

Really, of all options, it is Bcrypt that you would endorse?

I'd take properly salted&hashed, folded passwords any day over this, for example. There's nothing inherently wrong with caseless passwords.

Replies are listed 'Best First'.
Re^8: Mind the meta! (case, DBs)
by Your Mother (Archbishop) on Mar 04, 2016 at 17:02 UTC

    Case-insensitive passwords diminish complexity. It means abcdefgh matches not one password but 256 of them. The cracker has less work. I find that inherently wrong.

      Make your password longer then? It's about entropy, not the symbol set. In practice, one could remember to "put a dot before uppercase", or some other encoding notion (hitting shift does not save on keystrokes either). One might be able to memorize longer passwords when the case is unimportant. And the "horse staple battery" thing? It's essentially chinese block characters, spelt out in english. You have no convincing argument.

      Remembered pass phrases are not well suited for strong access protection. Slow to enter and hard to remember.