Enjoy unlimited access to all forum features for FREE! Optional upgrade available for extra perks.
Sedo

moniker Moniker - Password Security suggestion - to make accounts more secure

This is a discussion about the domain name register/company Moniker.
Status
Not open for further replies.

woeger

Level 5
Legacy Platinum Member
Joined
Jun 18, 2002
Messages
498
Reaction score
3
I just found out by reading on another domain forum that Moniker's passwords were NOT case-sensative. I have always thought that they were. Even Godaddy honors the case sensativity in passwords!

To try, I typed in my account username and then my password in all lower case and it worked and let me login. This is a big security error in my opinion, as it makes it easier for bots and hackers to try and compromise a Moniker account by guessing passwords or using brute force login automated routines.

It would make it much harder if Moniker didn't bypass in their account login routine the case that people have already embedded into their passwords when they selected them.

Please, Monte, change the login routine to honor the correct case in our passwords to keep our accounts as secure as possible. I am with Moniker because of security and customer service, as I want my names protected from thieves and others.

Password: xYzz12Y is much more secure than say xyzz12y, and there are many more permutations of mixed upper and lower case that will add to security. Enabling "any case matching" algorithm for passwords that you apparently are now using cuts down on permutations of embedded password security by a significant factor. I am not a mathematician, but I know enough about permutations of upper and lower case letters to know that eliminating the case hurts the diversity of combinations otherwise possible in a mixed upper/lower case password.

No change to the passwords already stored in our Moniker accounts need be made, just a change in the login verification algorithm/routine you are using to do an exact match check on the whole password (including checking the case of all alphabetic characters the user has selected in their password).

Thanks Monte for considering this security enhancement suggestion! We'll all sleep better once this feature is implemented knowing that there is less chance of someone breaking into our account(s) at Moniker. You have an excellent reputation for account security, and this should help strengthen that.

---

Update: Monte replied to me via E-mail within a few hours of this post and says that they have 5 security steps one would have to get through to break in and steal names from a Moniker account, and that they have NEVER lost a name to theft! That is good news and a fast reply from Monte!

He said that they will look into the case sensative password issue also.

Thanks Monte (and Moniker) for "looking out for us" (the domain owners who are your customers). I appreciate all your security for protecting domains that are with Moniker.

Update 2: An employee from Moniker just sent me the following:
"Hello Adam,

Thank you for the valuable feedback you provided regarding our password policies. We found your observations completely valid and agreed with your recommendation.
A few minutes ago we updated our system to enforce case-sensitive password verifications.

The Moniker Tech team thanks you for helping us improve our systems."

Thanks Moniker for a very quick reply to my password security suggestion!
 
Dynadot - Expired Domain Auctions

BigBoss

DNF Newbie
Legacy Exclusive Member
Joined
Mar 21, 2006
Messages
107
Reaction score
0
An other security problem is, if somebody hack my email address, he can go to moniker.com --> Forgot Your Password --> enter my email and get my password ;)

There is no security questions something like "What is your dogs name? or "Do you love your wife?" :D

For more security, I would change "Forgot Your Password" in 2 steps:
1- email or account number or username
and
2- security question

Maybe monte (moniker) can implement this security feature ;)
 

VirtualT

Level 8
Legacy Exclusive Member
Joined
Aug 11, 2006
Messages
2,228
Reaction score
19
I like what my bank has, when you register they ask you 3 security questions, dogs name, place of birth etc.

When you log in, as well as a password your presented with one of the security questions to answer before you get access. VERY secure, you may forget your password but if you forget your place of birth then you might as well give up :)

Maybe this could be implemented an an option?
 

woeger

Level 5
Legacy Platinum Member
Joined
Jun 18, 2002
Messages
498
Reaction score
3
I just E-mailed Monte about your suggestion you offered. I also had this concern about Moniker sending a password to a potentially compromised E-mail account (the E-mail account is the weakest link in the security chain).

I gave Monte a link to this thread so he can read and/or reply about your suggestion.

Thanks again Monte (and Moniker staff) for implementing the case sensative password security strengthening measure today!
 
Joined
Oct 29, 2003
Messages
650
Reaction score
1
we have addressed the PW suggestion already.

we have other methods which have protected from email hijacking but are looking into more security features all the time.

thanks for the suggestions.!
 
Status
Not open for further replies.

Who has viewed this thread (Total: 1) View details

Who has watched this thread (Total: 1) View details

The Rule #1

Do not insult any other member. Be polite and do business. Thank you!

Members Online

Sedo - it.com Premiums

IT.com

Premium Members

MariaBuy

Upcoming events

New Threads

Our Mods' Businesses

UrlPick.com

*the exceptional businesses of our esteemed moderators

Top Bottom