on 30-10-2021 18:59
Hello
What is the reason for the 10 character limit for passwords and no special characters?
It doesn’t seem very secure
Paul
on 30-10-2021 20:18
😲 Vzg94w
Given a 10 character alphanumeric password has around 916,132,832 combinations ( a-z, A-Z, 0-9) ...
What the hell are you trying to secure !!!
🤔
😜
on 30-10-2021 20:38
Thanks, helpful
on 31-10-2021 11:47
on 31-10-2021 12:47
Limitation is likely due to legacy systems; best guess as Virgin Media do not discuss reasons.
on 31-10-2021 13:04
@RainmakerRaw wrote:
Seeing as modern hardware can make more than that many guesses per second...
That is the case but hard to achieve if sign in process is rate limited, i.e. using a CAPTCHA scheme, progressively longer delays between attempts before locking account , etc.
IMHO Virgin Media should have solved their legacy issues long ago but having not done so customers should mitigate the risk by looking elsewhere for a more secure email service.
on 31-10-2021 15:38
Rate limiting only works if the attempt remains online. If the database is exfiltrated and saved offline (see every insecure elasticsearch database ever, and various recent telco breaches) then no such limitation applies. I'd rather be the person with a 50 character passphrase than <10 basic chars in that situation. It's poor form, and needs upgrading. Even these forums don't allow MFA that I can see, but from the company with plain text router logins and such I won't hold my breath lol.
02-11-2021 17:29 - edited 02-11-2021 17:34
Multiple threads on topic gong back a long time and a total joke as even free pr0n sites have had better protection for a decade+
And P.S you always get one smartarse making dumb clueless comments in these threads.
I do not have a 100% Total Security Score on LastPass as both my Virgin accounts score only 75%, every other site is 100% and all are 20 Character (inc specials).
on 02-11-2021 23:49
At lot of us may not like the password restrictions, but a you signed up for VM you have to live with their system. It’s an utter waste of time trying to do anything about,
on 03-11-2021 07:01
And that helps how?
FYI I have been with VM since TW-BY days so signed up before we had dial up so I didn't sign up for weak security.