Home / Security / John Lewis Poor Password Security
Security
John Lewis Poor Password Security
I knew I had not capitalised one of the letters and was waiting for an “incorrect password” error. There was no error. I was in the account.
That is a basic failure. Authentication should reject a password that does not match exactly. If a retailer accepts a near-miss, anyone who has seen a similar password — or who can guess the usual substitutions — is closer to the account than they should be.
The lesson has not aged: length and uniqueness still matter, but they only work if the site checks what you typed. Use a password manager. Turn on two-factor authentication where the shop offers it. If a site lets you in on a password you know is wrong, tell them, then change it.