News: 1646908151

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Reg reader rages over Virgin Media's email password policy

(2022/03/10)


A Register reader has raised concerns over UK ISP Virgin Media's password policies after discovering he couldn't set a password longer than 10 characters or one that includes non-alphanumeric characters.

Our reader Nick told us he was facing repeated attempts to take control of an @virgin.net email account he owns – adding that the company's password policy left him vulnerable to what he described as a sustained brute-forcing attack.

"I am having a running battle with a hacker who is able to crack a 10-character password used for Virgin or Virginmedia email in less than a day," Nick complained, saying the attacker was setting up auto-forward rules to divert his emails as well as being able to guess newly reset passwords within a day.

[1]

He added that Virgin's password policy enforced weak-by-design choices on him which made his apparent attacker's efforts easier: the ISP's email account policy wouldn't allow him to set a password longer than 10 characters; nor would it allow him to add two-factor authentication (2FA); the first character had to be a letter; and non-alphanumeric characters weren't allowed.

[2]

[3]

A spokesperson for the Liberty Global-owned telco told The Register : "Ensuring customer data is secure is of utmost importance to us and we continually invest in our security systems to keep our customers safe online. Our login process requires customers to use unique passwords using a variety of up to 10 characters, enhanced by additional technical controls and anti-fraud measures which defend against unauthorised login attempts. Our engineers regularly update our systems to improve security, with further improvements due to be implemented in the near future."

However, on its [4]website we note that the company says users should "aim for 8 to 12 characters" and use "symbols… or special characters."

[5]

Nick is not alone in wondering what Virgin's up to with email account passwords. Last year someone [6]posted on their customer support forum asking for help setting a password that would pass Virgin's systems, to be told: "We do advise to use a password between 6-10 characters long, including at least 1 number, 1 capital letter, 1 lower case letter and ensuring that it isn't your surname or first name."

[7]Virgin Media router security flap follows weak password expose

[8]Like a Virgin, hacked for the very first time... UK broadband ISP spills 900,000 punters' records into wrong hands from insecure database

[9]Virgin Media blocks 'wankers' from permissible passwords

[10]Google dumps ISP email support. Virgin Media takes ball, stomps home

Another customer [11]wondered why he was restricted to "maximum of 10 alpha numeric characters lower or upper case", adding: "Why are no special characters and longer than 10 alpha numeric passqwords allowed?" [sic]

Similarly, a Redditor [12]posted a thread titled "It's 2021 and VirginMedia only allows password 8-10 characters long, letters and numbers only" complete with a screenshot of the password page explaining the requirements.

Meanwhile, in 2019, the company's social media operatives were confident enough to say this about their password policy:

10 characters is ample enough to keep the password secure. ^GT — Virgin Media (@virginmedia) [13]March 11, 2019

Britain's National Cyber Security Centre, an offshoot of GCHQ, [14]has this advice about email account passwords:

Machine-generated passwords eliminate those passwords that would be simple for an attacker to guess. They require little effort from the user to create, and can produce passwords that are random and unique. However, most machine-generated passwords are very difficult for people to remember. For this reason, the NCSC recommend that they should be used with a password manager.

Machine-generated passwords in this day and age all come with options to set non-alphanumeric characters and in lengths of greater than 10 characters – none of which, it appears, would pass Virgin Media's requirements.

Back in 2015, Virgin had to [15]shift itself off Gmail for consumer email accounts after the adtech monolith dropped support for ISP accounts. It's had problems in the past with security as well; in 2020, 900,000 customers' records were dumped online thanks to a [16]poorly secured database . ®

Get our [17]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YinaWDF81Sm3TukSBll3ugAAAII&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YinaWDF81Sm3TukSBll3ugAAAII&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YinaWDF81Sm3TukSBll3ugAAAII&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://www.virginmedia.com/help/security/how-to-create-a-strong-password

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YinaWDF81Sm3TukSBll3ugAAAII&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://community.virginmedia.com/t5/Forum-Archive/Problems-creating-a-password-to-register/td-p/4147463

[7] https://www.theregister.com/2017/06/23/virgin_media_router_security_flap/

[8] https://www.theregister.com/2020/03/05/virgin_media_subscriber_data_leak/

[9] https://www.theregister.com/2014/09/01/virgin_password_blocks/

[10] https://www.theregister.com/2015/07/21/google_ends_isp_email_support/

[11] https://community.virginmedia.com/t5/Email/Weak-Password-Rules/td-p/4641976

[12] https://www.reddit.com/r/VirginMedia/comments/ltm8eg/its_2021_and_virginmedia_only_allows_password_810/

[13] https://twitter.com/virginmedia/status/1105114142632038401?ref_src=twsrc%5Etfw

[14] https://www.ncsc.gov.uk/collection/passwords/updating-your-approach#tip5-password-collection

[15] https://www.theregister.com/2015/07/21/google_ends_isp_email_support/

[16] https://www.theregister.com/2020/03/05/virgin_media_subscriber_data_leak/

[17] https://whitepapers.theregister.com/



Virgin, bringing you the barely-adequate security from 2002

SsiethAnabuki

It really is laughable that they consider this to be sufficient to secure _any_ system available online, let alone customer email accounts. I dread to think what infrastructure they have behind this that requires it be alphanumeric and can't have the field resized beyond 10 characters....

Re: Virgin, bringing you the barely-adequate security from 2002

Doctor Syntax

It makes you wonder what their internal security might be like as well.

Doctor Syntax

Simple solution. Don't use an ISP-provided email service. If you do you're not only lumbered with crap like this if the ISP doesn't care, it also makes it harder to ditch your ISP.

devin3782

You know when you see a policy like that they're storing passwords as plain text. Microsoft are also guilty of password upper limits so are several banks along with specific character subsets.

If you storing passwords: (One way uniquely salted hashes using a slow strong hashing algorithm and compare in constant time) then the only characters that matter are null chars as they cause some hashing algorithms to exit so remove those otherwise don't restrict.

Also every bone in the manager's crotch (that's what I'll break) for deciding to prevent pasting passwords into form fields.

Rainbow tables anyone?

42656e4d203239

Anyone responsible for setting password policy should be aware that rainbow tables for up to 14 characters are easily available which reduces the pasword crack time for passwords shorter than 14 characters to trivial lengths of time. All the bad guy has to do is get your password hash and boom, he has your password (providing its a password of < 14 characters) - ok it may take a while to find in the table but its much quicker than trying all the possible combinartions against the login.

I expect that in this case the Virgin login page trivially hashes the password and passes it over to the server for storage, so the bad guy in question just has to scan his rainbow table (hence crack times less than a day) and login. Virgin's security mechanisms aren't triggered and our mark gets hacked once more.

Long passwords are best boys and girls - obligatory [1]XKCD

[1] https://xkcd.com/936/

Time to give VM the finger

Steve Davies 3

and move your email to a provider that takes security at least half serious rather than none at all as VM clearly don't care.

Yes, it can be difficult but it is possible if you take your time.

However, if you are fighting a determined hacker then you have to go for broke.

VM need to be hauled up before the ICO not that they can do anything but any publicity that shames them can't be bad.

Move on already

chivo243

Cut your losses, and move to another email provider from this century! Don Q something...? It's only email...

Drink and dance and laugh and lie
Love, the reeling midnight through
For tomorrow we shall die!
(But, alas, we never do.)
-- Dorothy Parker, "The Flaw in Paganism"