Forums

Password with special chars

Quick find code: 278-279-869-66194880

black falck

black falck

Posts: 352 Silver Posts by user Forum Profile RuneMetrics Profile
Hi everyone,

I couldn't believe what I saw when I wanted to change my password.
You are only allowed to use a-z, A-Z and 0-9. Now more than ever it is very important to use secure passwords in combination with 2 factor.

The brute force decryption time greatly increases when you use special chars in your password.
For example a password length of 9. With the current rules the password can be brute forced in 6hrs. When adding special characters it increases to 2 years.

Hopefully this is something that can be upgraded in the future.

Happy scaping!

23-Dec-2020 07:42:01

ToP BaSS

ToP BaSS

Posts: 19,464 Opal Posts by user Forum Profile RuneMetrics Profile
Brute Force (or failed password guessing) has a very early cut off point on RS.

The vast majority of account breaches (if not all) are not accessed by poor password security.

Most hijackings are achieved by account holders giving away their account security details (by various means) to the hijacker, this includes their password.

So no matter a password is used it will not prevent hijackings.

23-Dec-2020 07:55:04 - Last edited on 23-Dec-2020 07:57:52 by ToP BaSS

black falck

black falck

Posts: 352 Silver Posts by user Forum Profile RuneMetrics Profile
I understand that a secure password doesn't prevent hijackings. In my opinion a secure password has nothing to do with password hijackings.
And even if RS has an early cut off points for brute force attempts, I still feel that having the ability to use special characters is a basic feature that every application nowadays should provide.

Never trust one line of defence, always create multiple :)

23-Dec-2020 08:43:23

ToP BaSS

ToP BaSS

Posts: 19,464 Opal Posts by user Forum Profile RuneMetrics Profile
Why do you consider a password with "special characters is a basic feature that every application nowadays should provide" ?

No support because it would serve no purpose.
In fact in could be counter productive.
The more complicated a password the more is the likelihood that people would memorialise it with a hard copy - this in itself is a security issue.
The numbers of "lost / cant remember password" issues for Jagex to sort out would increase beyond the effort of making this change.

23-Dec-2020 10:22:53

Pippyspot
Feb Member 2007

Pippyspot

Posts: 84,190 Emerald Posts by user Forum Profile RuneMetrics Profile
The amount of passwords brute-forced are fairly low I believe, it usually only applies to very obvious passwords. The other ways people get compromised are entering details on a phishing website, through using the same password on other websites that are breached, or they have some sort of keylogger/virus on their computer. In these cases, having special characters in passwords would not benefit them unfortunately
*
´¨)
¸.
*
´
(¸.
*

23-Dec-2020 17:21:32

black falck

black falck

Posts: 352 Silver Posts by user Forum Profile RuneMetrics Profile
Thanks Tuffty for moving it to the correct section.

Glad to hear that it has been requested before. A bit sad that is hasn't been implemented.

I think the argument that the chances are low of it happening isn't a very good argument.
Ofcourse RS has a good first line of defence. But in case that line of defence fails, or they have a leak where user information gets out. I rather have a strong password that makes brute forcing impossible.
By the way; The chances of RS database being compromised is very small, but I hope they still hash our passwords. (I understand that this is a over the top example :) )

I agree with Top Bass that forcing all kinds of rules for a password increases the likelihood for people writing it down or something. But i'm not asking to force people to use special characters. I'm simply asking to enable them so people can use them as they wish.


So to summarize: I understand that using special chars in your password isn't the holy grail that prevents you from being hacked, ever. However it's such a simple little extra security benefit. And from a development perspective, it shouldn't too difficult to support it. (depending on multiple factors ofcourse).
Even if it decreases hacks with 0.5% it would still be worth it. And I can't think of the downside when you make specials chars optional possible.

Hopefully the development team will consider it.

23-Dec-2020 18:51:18

333333333

333333333

Posts: 36,620 Sapphire Posts by user Forum Profile RuneMetrics Profile
Nah, no needed since we already have authenticator! It's not easy to guess or hack an up to 20 character passwords plus you can't access that account anyway because it requires authenticator code on another side of the earth!

23-Dec-2020 22:42:11

Draco Burnz
Dec Member 2011

Draco Burnz

Posts: 79,296 Emerald Posts by user Forum Profile RuneMetrics Profile
ToP BaSS said :
Why do you consider a password with "special characters is a basic feature that every application nowadays should provide" ?

No support because it would serve no purpose.
In fact in could be counter productive.
The more complicated a password the more is the likelihood that people would memorialise it with a hard copy - this in itself is a security issue.
The numbers of "lost / cant remember password" issues for Jagex to sort out would increase beyond the effort of making this change.


^

No support.

Just use the already available options to keep your acc secure.
Draco Burnz
Anime Fanatic
Defender of the logical

23-Dec-2020 23:58:24 - Last edited on 23-Dec-2020 23:59:20 by Draco Burnz

Quick find code: 278-279-869-66194880 Back to Top