Slashdot Mirror


Amazon Flaw Lets Password Variants Through

Wired reports that it has confirmed a password flaw affecting some Amazon accounts. If your password hasn't been changed in a while ("the past several years"), it may be less secure than you'd like. As Wired explains, for these older accounts, "[...] if your password is “Password,” Amazon.com will also let you log in with 'PASSWORD,' 'password,' 'passwordpassword,' and 'password1234.'" The article suggests that Amazon's use of the Unix crypt() tool may be at fault. (Hat tip to E. Maureen Foley for pointing this out.)

7 of 159 comments (clear)

  1. Uhm... by Anonymous Coward · · Score: 5, Funny

    Is it supposed to show all of my passwords in the article? Or do you just see stars?

    1. Re:Uhm... by SpooForBrains · · Score: 3, Funny

      I see Hunter2

      --
      "The dew has clearly fallen with a particularly sickening thud this morning"
  2. Thankfully... by Junta · · Score: 4, Funny

    My password of hunter2 was not compromised.

    --
    XML is like violence. If it doesn't solve the problem, use more.
    1. Re:Thankfully... by smellotron · · Score: 3, Funny

      Hey that's my ********, you insensitive clod!

      What?

  3. 5f4dcc3b5aa765d61d8327deb882cf99 by metalmaster · · Score: 3, Funny

    I think its safe to say my password is safe

  4. Re:Why exactly is this a problem? by MichaelSmith · · Score: 5, Funny

    Just this morning my wife said she had gone to the bank to open an account for our son and they told her this bank has accounts for five people with the same name. We thought his name was less common than that. I asked her why she thought that was a big deal and she said "you know, when you use your name as your password" and I said what?.

  5. passwordpassword by Arancaytar · · Score: 3, Funny

    I hear the site also accepts minor misspellings, anagrams, close synonyms and Cockney rhyming slang.