Recommended Posts

I ask because when I sign in using an account I give as a 'spam this email' with an inheritly rubbish password I am greeted with a page displaying;

"Your password is too easy to guess

Your current password is on a list of passwords that hackers frequently try to use. Create a new one to help keep your account secure."

So either it's stored unencrypted, or reverse-encrypted or it's a one-way hash and they've got a list of hashes that are easy to guess?

Anyone know which it is?

If I were to guess, I'd say it was a list of hashes, or list of plaintext passwords scrubbed from obvious attacks. I doubt Microsoft would store Hotmail passwords in plaintext or reversable encryption. If they did I'd expect to see "this is your password" emails instead of "reset your password" emails.

There are specific passwords that are simple to guess...that make an easy to decrypt hash. They are warning you on the basis of that fact.

Even if it's an account you don't use for anything other than spam it's still wise to protect it, just in case of any other links. You'd be surprised just how little information someone needs to make a link between things and go after master accounts and such.

It's a spam account in that it's got nothing on it at all, doesn't even have email access.

It wouldn't store the password security on registered, it's a pretty old account from before they had the strength indicator :p.

I wouldn't think they'd use plain text or reversible encryption but I am starting to worry that they do, even if they stored it in plain text, they wouldn't allow you to see the password and would still require you reset the password.

"whats so hard to understand? if you password is hashed, then they've hashed common passwords and compare them to your hash,which ends up being the same."

Do you work for microsoft, can you say you've seen the database scheme to comment like you know exactly how their database is setup ?

whats so hard to understand? if you password is hashed, then they've hashed common passwords and compare them to your hash,which ends up being the same.

Probably this.

I wager it is a simple look up to see what matches to common hashed items that they gleaned from hacker attempts, and also just basic common passwords that everyone and their brother use).

Best method to confirm would contact the Hotmail team/devs and look into it.

It's a spam account in that it's got nothing on it at all, doesn't even have email access.

It wouldn't store the password security on registered, it's a pretty old account from before they had the strength indicator :p.

I wouldn't think they'd use plain text or reversible encryption but I am starting to worry that they do, even if they stored it in plain text, they wouldn't allow you to see the password and would still require you reset the password.

"whats so hard to understand? if you password is hashed, then they've hashed common passwords and compare them to your hash,which ends up being the same."

Do you work for microsoft, can you say you've seen the database scheme to comment like you know exactly how their database is setup ?

vcfan has not, unless I am mistaken. However I have...I worked on a team that was directly responsible for the monitoring and safety of Xbox LIVE so I have more than a little experience in this matter.

I cannot comment on specifics (of course for security reasons), but there's no need to worry about the level of security employed here. Just don't use an easy password...that's the point of that message. Easy passwords can be guessed without any sort of skill really required.

They store them as a plain text file trust me ive seen it, i know your passwords! lol =P

Nah as said they will have a list of common passwords encrypted however they encrypt there passwords, they will then probably do a match up when you change your password and give you a warning if it matches one of the encrypted ones on there list. Shouldnt be anything to worry about, but if you are then just make it harder symbols and numbers are always nice.

whats so hard to understand? if you password is hashed, then they've hashed common passwords and compare them to your hash,which ends up being the same.

But if you throw in salt, even the same password would not generate the same hash... because of the salt.

And I would hope they store salted passwords :-/

I would expect that they use salted hashes, which would mean you couldn't compare it against a pre-calculated list of encrypted hashes either. More likely, the server tries to *guess* your password from a list of common passwords, meaning it would have to generate a salted hash for each password and compare it to the salted hash of your password. But for a small list of common passwords (100-1000), this would only take a fraction of a second to test for each account registration / password change.

Bear in mind that as you said, you just logged in. As part of the logging in process, you provided an unencrypted version of your password. It would be easy as part of the login process for them to check that against a stored list of weak passwords, and forward you on to a page warning you of its weakness, no need to be able to decrypt the stored password to do that.

Maybe i am just being dumb here but

when you type in a username it automatically check to see if thats available using ajax/jquery for example

whats stopping it doing the same for passwords before its encrypted?

Another "maybe I am dumb" question here..

Isn't it the case that when you create a password, that it would be transmitted unhashed anyway? (plaintext - over SSL of course!) So the server receives it as plaintext and can easily do text comparison to a list of unsecure passwords?

Then when it saves it, it would salt+hash the password. When you login, it would do the same thing - transmit plaintext, then the server hashes it and compares it with the stored hash?

Right you are, it does send the password unencrypted! I always assumed it uses client-side javascript to MD5 it which is why I assumed it sent the details to an 'md5crum' page but it doesn't! Learn something new every day :p

Right you are, it does send the password unencrypted! I always assumed it uses client-side javascript to MD5 it which is why I assumed it sent the details to an 'md5crum' page but it doesn't! Learn something new every day :p

Well they're using HTTPS so it's technically still secure... Right?

This topic is now closed to further replies.
  • Posts

    • Of course the problem was Secure Boot's new certificates. Install media created by the official Media Creation Tool is already signed with a valid certificate from Microsoft, so maybe that certificate isn't "up-to-date" enough for machines with the new ones installed in the UEFI. There's really no other logical explanation.
    • Here is how I fixed Windows 11 not booting after clean installation by Taras Buria Story time. A couple of weeks ago, I experienced a very odd thing with my computers. I was trying to reinstall Windows 11 on my primary device, and everything was going smoothly until the installer performed the first restart. After that, my computer entered the boot disk selection screen instead of continuing the setup process. Huh, that's odd, said I, and selected Windows Boot Manager only to see it fall back into the same screen right away. Then I tried booting from the USB drive with the same result—the PC kept returning to the boot device selection screen, and removing the drive would send my PC to UEFI, again, with no way to launch Windows 11. I fired up my spare laptop, which has been sitting unused for quite a while, to see if I am dealing with a defective USB drive. Nope, Windows 11 installed and started without issues. After trying another drive and checking all the possible settings in UEFI, I decided to try disabling Secure Boot. Lo and behold, Windows 11 started as it should have been in the first place, continued the setup process, and reached the initial setup screen. Victory! After I finished the setup and applied all updates, I re-enabled Secure Boot, and Windows 11 started without issues. Some time later, I tried reinstalling Windows 11 on my laptop only to experience similar issues, with UEFI claiming a Secure Boot violation. I checked whether the drive works on my main PC, and yes, it installed Windows 11 without errors. I scratched my head, went to UEFI, turned off Secure Boot, and installed Windows 11 without issues. After that, I enabled Secure Boot. Note: I used the official Media Creation Tool app for my USB drive. Also, UEFI was properly configured for Windows 11, including no Legacy Mode, a GPT-partitioned drive, and TPM and Secure Boot enabled. From my experience, if you are dealing with similar symptoms, I recommend two things: If you use old Windows 11 install media, create a new one with the latest Windows 11 release, especially if you know your PC already has the latest Secure Boot certificates. If you cannot create a new one, turn off Secure Boot, complete the installation, download all available updates, and then re-enable Secure Boot in UEFI. Note that you need to turn off Secure Boot after installing Windows 11. Otherwise, the installer won't run, claiming a hardware requirements mismatch. I believe the problem hides in Secure Boot certificates that expire this month. Microsoft is currently rolling out new certificates, and maybe a mismatch was causing these issues for both of my systems. I am out of my depth to make a definitive statement; this article is flagged as "Opinion," as I only share my experience and some tips on how to fix the problem. If some of you possess deeper knowledge and understanding of the situation, please share it in the comments. As for everyone else struggling with computers not booting after a clean install, the two steps above should get you out of the pickle.
    • I gave the tool a chance the other day to make a USB. An hour later it was stuck at 0% downloaded. I downloaded the official ISO, downloaded Rufus, and made the USB myself in 15 min.
    • <Moved to software discussion and support> I've got fond memories of Winamp. Changing the skins, the different visualisations etc. But now I just need a simple music player. MSN messenger would be another one, MSN Messenger Plus (I think?) offered so many different plugins. But again, it probably wouldn't work for me these days. And then there is miRC. i think it's still going these days, but lord i had fun with that back in the day. Now it's mostly stuff like Discord, WhatsApp group chats, Signal, Telegram... /me is showing his age...
  • Recent Achievements

    • Conversation Starter
      flexorcist earned a badge
      Conversation Starter
    • One Month Later
      AndreaB earned a badge
      One Month Later
    • One Month Later
      agatameier earned a badge
      One Month Later
    • Week One Done
      agatameier earned a badge
      Week One Done
    • Week One Done
      ssd21345 earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      518
    2. 2
      +Edouard
      198
    3. 3
      PsYcHoKiLLa
      147
    4. 4
      ATLien_0
      94
    5. 5
      Steven P.
      77
  • Tell a friend

    Love Neowin? Tell a friend!