Menu
Reply
On our wavelength
  • 27
  • 2
  • 4
Registered: ‎23-06-2017
Message 1 of 24 (473 Views)

My Virgin Media password strength

The current enforced policy just isn't good enough:

"8-10 characters long, letters and numbers only, no spaces. First character must be a letter."

When will it be possible to use a password longer than 10 characters that can contain i.e. !%@# characters?


Accepted Solutions
Forum Team
  • 6.68K
  • 282
  • 1.2K
Registered: ‎07-04-2015
Message 6 of 24 (646 Views)
Helpful Answer
confirmed by jlippa
‎16-07-2017 21:39

Re: My Virgin Media password strength

Hi jlippa.

Many thanks for joining us on the community and for raising your concerns with us about this.

We are constantly reviewing our processes and take our customers data security very seriously.

Ensuring customer data is secure is of utmost importance to us and we continually invest in our security systems to keep our customers safe online.

In common with every other company, our login process requires customers to use unique passwords using a variety of characters. Additional technical controls and anti-fraud measures defend against unauthorised login attempts.

Our engineers regularly review our systems and carry out updates – and account security is always a top priority.

More information on setting strong passwords can be found here: http://virginmedia.com/strongpassword

With respect to your feelings on our current security standards, I would like to log your dissatisfaction about this officially.

If you would like me to do this for you then please respond to the PM I've sent to you that you can find in the purple envelope next to your forum name.

Kind regards.

Karen_A
Forum Team

Need a helpful hand to show you how to make a payment? Check out our guide - "How to pay my Virgin Media bill"

See where this Helpful Answer was posted

0 Kudos

All Replies
Knows their stuff
  • 2.24K
  • 30
  • 195
Registered: ‎02-02-2011
Message 2 of 24 (428 Views)

Re: My Virgin Media password strength

LastPass nags me all the time about all 3 of the passes I use for Virgins services.

They are simply too short and basic.

In this day and age they should be able to be made at least 12 long with additional characters.

Trouble shooter
  • 2.72K
  • 44
  • 357
Registered: ‎30-05-2013
Message 3 of 24 (408 Views)

Re: My Virgin Media password strength

You could try one of the online password generators eg https://lastpass.com/generatepassword.php   which can be adjusted to 10 characters long

0 Kudos
Knows their stuff
  • 2.24K
  • 30
  • 195
Registered: ‎02-02-2011
Message 4 of 24 (395 Views)

Re: My Virgin Media password strength

VM's passwords can never be good in LP's eyes as they cannot use special characters only letters and numbers, it would need at least 1 special like "£" or "^" to be 100% which can be 100% in less than 10 characters.

I have the full version of LP and can do the same inside it that that link can do.

It will always be low scoring in the security test.

0 Kudos
On our wavelength
  • 27
  • 2
  • 4
Registered: ‎23-06-2017
Message 5 of 24 (382 Views)

Re: My Virgin Media password strength

I'm still waiting for an "official" reply from someone who works at VM: "When will it be possible to use a password longer than 10 characters that can contain i.e. !%@# characters?"

This is the "Security matters" community group. I should think that this issue requires attention or at least a response from VM if security really does matter.

0 Kudos
Forum Team
  • 6.68K
  • 282
  • 1.2K
Registered: ‎07-04-2015
Message 6 of 24 (647 Views)
Helpful Answer
confirmed by jlippa
‎16-07-2017 21:39

Re: My Virgin Media password strength

Hi jlippa.

Many thanks for joining us on the community and for raising your concerns with us about this.

We are constantly reviewing our processes and take our customers data security very seriously.

Ensuring customer data is secure is of utmost importance to us and we continually invest in our security systems to keep our customers safe online.

In common with every other company, our login process requires customers to use unique passwords using a variety of characters. Additional technical controls and anti-fraud measures defend against unauthorised login attempts.

Our engineers regularly review our systems and carry out updates – and account security is always a top priority.

More information on setting strong passwords can be found here: http://virginmedia.com/strongpassword

With respect to your feelings on our current security standards, I would like to log your dissatisfaction about this officially.

If you would like me to do this for you then please respond to the PM I've sent to you that you can find in the purple envelope next to your forum name.

Kind regards.

Karen_A
Forum Team

Need a helpful hand to show you how to make a payment? Check out our guide - "How to pay my Virgin Media bill"

0 Kudos
Knows their stuff
  • 2.24K
  • 30
  • 195
Registered: ‎02-02-2011
Message 7 of 24 (331 Views)

Re: My Virgin Media password strength

I posted in this thread and another on similar topics the same day.

Where has that other thread gone?

It had a reply from a staff member AFAIR agreeing it was a joke in this day and age (not in those words).

0 Kudos
On our wavelength
  • 27
  • 2
  • 4
Registered: ‎23-06-2017
Message 8 of 24 (302 Views)

Re: My Virgin Media password strength

Thanks Karen I've replied to your private message and I appreciate you filing an official complaint.

I'm under no illusion that it would be an easy change for Virgin Media to enable longer and more complex passwords on their systems. I've worked on what I imagine would be a similar sized system (~2M active users) at the sharp end of making security improvement changes to stored salted and hashed passwords on existing user accounts. Definitely tricky but certainly not impossible and it just requires the will of those in charge to consider it important enough to bump it up the priority stack to make it happen.

0 Kudos
Forum Team
  • 6.68K
  • 282
  • 1.2K
Registered: ‎07-04-2015
Message 9 of 24 (287 Views)

Re: My Virgin Media password strength

Hi jlippa

Many thanks for getting back to me on your PM. I've popped back to me on this with the steps we have taken to record this on your behalf.

If you could pop back to me then that would be fab.

Thanks again.

Karen_A
Forum Team

Need a helpful hand to show you how to make a payment? Check out our guide - "How to pay my Virgin Media bill"

0 Kudos
Highlighted
Superfast
  • 210
  • 8
  • 76
Registered: ‎04-06-2015
Message 10 of 24 (274 Views)

Re: My Virgin Media password strength

This simply won't happen any time soon.

As it stands, 10 chars (whilst not ideal) is secure enough for most purposes, if chosen correctly.  Unfortunately, there's far more to it than simply hashing & salting... it's not hashed at all right now.

I've lost count how often this topic has arisen... typically followed by some inane drivel about rainbow tables, brute force attacks and how Virgin are completely insecure.  It's just nonsense.

If security is of paramount importance to you, don't use Virgin's email services as your primary account.  Ensure your password is strong (ie - don't follow Virgin's own advice) and entirely unique and forget about it.

0 Kudos