Home / Security / John Lewis Poor Password Security

Security

John Lewis Poor Password Security

I knew I had not capitalised one of the letters and was waiting for an “incorrect password” error. There was no error. I was in the account.

That is a basic failure. Authentication should reject a password that does not match exactly. If a retailer accepts a near-miss, anyone who has seen a similar password — or who can guess the usual substitutions — is closer to the account than they should be.

The lesson has not aged: length and uniqueness still matter, but they only work if the site checks what you typed. Use a password manager. Turn on two-factor authentication where the shop offers it. If a site lets you in on a password you know is wrong, tell them, then change it.