Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Same here. With call forwarding our 24/7 support usually rang at my house. Night was the 'drunk shift' and usually login problems. One user was particularly edgy about his password and would not say it even to me, they were stored as crypts, so I could reset it. He said he had pasted it from another place (which probably means he forgot it and was too arrogant to admit it) Round and round until I checked the logs and he was trying to sign on with a pw of '********' which is how it had gone into the clipboard. Instead of engaging with him further I set his pw to that. Problem solved.

My greatest win was to add a few lines to our RADIUS server to flip case one time on bad logins, so if 'mYpASSWORD123' failed it would try 'MyPassword123' and let them in if it worked. Logs showed thousands of fixed logins per month and reduced tech support calls to less than a third. We declared victory over CAPSLOCK.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: