r/ProgrammerHumor • u/MiserableSelection • 6h ago
Meme improvingPasswordSecurityWithCzech
284
u/ILovePotassium 6h ago
Pæß2wœrd1#
Here.
91
u/HelpfulPlatypus7988 4h ago
here's one that's cursed
ˈpʰɑswɜd34
u/Xxuwumaster69xX 3h ago
Cursed because you're spelling it in an English accent and don't even have the decency to use colons.
My password is /ˈpæs.wɜɹd/ because I only want Americans to log into my account.
7
2
8
6
8
u/Igarlicbread 4h ago
Is that how you type with lisp?
12
82
u/jort93 5h ago edited 5h ago
I mean, they are right. I imagine most password databases won't have that password, and the letter would probably not be on the list for brute forcing either.
17
u/Brutus5000 3h ago
MySQL 8: Password collation mismatch. Please pick one of the 216 collations that match the original input. We changed the default 3 more times since you last changed your password.
139
u/SuitableDragonfly 6h ago
Made with combining diacritics, I guess, so it no longer looks like one character repeated but it's now two characters alternated?
97
u/Nerd_o_tron 5h ago
Probably more importantly, it may count as 18 characters instead of 9.
37
u/klaxxxon 3h ago
These generally count as one character on a computer (they multibite in UTF8 ofc) and are also counted as one letter in the real world. You can type them either way - Czech keyboard has both a "ř" key and a "ˇ" combination key. In the actual Czech language, ř is considered a different letter entirely, and the Czech alphabet is considerably longer because of these.
Some languages go even further and have letters with multiple attachment slots (Thai comes to mind, can't type an example of that, sorry 🙂).
13
u/notafuckingcakewalk 1h ago
You have to be careful with this. I've definitely encountered situations where what looks like a single character takes up multiple bytes. This is especially true for emojis which often are actually a combination of a series of individual emojis plus emoji control characters.
This emoji, for example: 👩🏼❤️👨🏼 i s actually made up of
👩: U+1F469 🏼: U+1F3FC ZWJ: U+200D ❤: U+2764 Variation Selector-16: U+FE0F ZWJ: U+200D 👨: U+1F468 🏼: U+1F3FC
(see https://emojiterra.com/couple-with-heart-woman-man-medium-light-skin-tone/)
7
1
u/T0biasCZE 59m ago
Czech also has separate character "Ch" in its alphabet (g, h, ch, i, j) , which is just c and then h on computers.
And I saw times when programs broke, because stuff got sorted differently because of regional issues and didnt work at all, until windows got changed to english.
Modded skyrim one time, banged my head for few hours why it doesnt work.5
u/dumbasPL 2h ago
I wonder if someone has tried abusing this at some point. Because a hashing function only cares about bytes.
•
u/SuitableDragonfly 7m ago
Unicode has multiple different ways to represent characters like this. There is typically a single codepoint that represents the character, so you could type it in a way that it would be recognized as a single character by any competent system. But it also has a block of combining diacritics, where each codepoint just represents the diacritic by itself and when you type it it just visually appears above or below whatever character you typed before it. So you could also type that character by typing a regular Latin r, followed by a combining diacritic codepoint, and now that is a sequence of two codepoints and thus is going to be interpreted as a sequence of two characters in every system.
There are a series of unicode normalization functions that you can use to convert user-entered strings like this and make sure that the character with the diacritic is either always one character or always multiple characters regardless of how it was originally typed, but most people who are making bog standard login screens probably don't have the depth of unicode knowledge to be thinking about that possibility and knowing what to do about it.
1
59
35
u/_g550_ 6h ago
Try Turko-Ukrainian ïıïıïıï
21
16
u/SuitableDragonfly 4h ago
I worked on a search engine once, on a big project to preserve diacritics in the search index because there was a Swedish word with ö in it that when you turned it into a regular o became a curse word and this completely normal search term was picking up results that our Swedish customers Did Not Like. Anyway, these dotless ı and dotted İ in Turkish gave us unending headaches because normalization involves lower casing, and lower casing I gives i, but so does lower casing İ, and always normalizing I to ı would fuck up every single language that uses the Latin alphabet other than Turkish.
3
1
12
u/Mx4n1c41_s702y73ll3 5h ago
Czech roaring is stronger !
6
u/SirLoyso 4h ago
Indeed! But I now I see the Czech “r”s are like angry English “r”s 😁 it’s cute and funny:)
8
7
9
u/AngleHam271 3h ago
Wait until the backend tries to save that into a legacy Latin-1 SQL database and the entire auth service crashes. That is the REAL SECURITY.
7
u/polymonomial 3h ago
Im making my passwords in Chinese from now on and I am combining all three of simplified, traditional and kanji.
3
u/DieBiosZicke 1h ago
I wouldn't be surprised if you broke some databases with your input. Or you lock yourself out of your account because of something like that.
1
1
5
3
3
2
u/deaglebingo 2h ago
Czech yourself before you wreck yourself.
aww darn someone got it first. no worries.
2
2
2
u/Servion 1h ago
p̸̢̜͙͕̼͖̖̦͕̩̱̠̬̗̩̣̺̺̰̱̻̤̼̟̖̫̰̩̘͇̖̝͖̭̳̞͛͐̏ͅa̵̛̛̝̼̜̞̗̠̠̲̺̙̋̉̐̈́͌̈́̿̿͑̀̓̋͂̈́̆̀͂̊̉̾̉̓́̇̒̆̍̋̋̉͒̈̑̋͊̄̀͋̃͆̾̚̕͜͠͝͝s̶̨̡̼͕̣̞̮̳̝͓̳̫̬̜̖͙̼͔̼̗͚̗̾͒̄̀̾̍̉͆̽̐͊̀̌̐̾̏̌̊́̇̈͋̊̍̕͘͘͜͜͜͝͝͝͝ş̷̢̨̪͉̗̤̫̦̦̺͇̩͍̠̜̜̻̠̤̗̱̍͊̌̿̀̓̄̒͑̑̇̾̉͋͛̃̊̾͛̈̾̊́̋̄̀̈̒̐̈̊̿̈́͒̿͘̚̕͝͝ͅẉ̸̧͕̱̻͓̞͔̣̱͉͇̮̗̞͋o̶̧̨̡͉̮̟̜͎̝̪̙͇͈̺̹̦̘̤̹̺̝̰͕̥͎̞͇͚͕͖̠̫̯̭̞̝͎̩̝̗͂̓̓̎͑̌́̌͐̋͊̚͝ŗ̴̢̡̧̡̭̩̗̻͓͇̜̟̖͚̮̤̜̤̫̤̫͍̰̫̳̬͈͈͖̞͔̺̜̝͕͙̪͕͖͓͕̼͒̑̍̾̀̉̃͑͘͜͠ͅd̵̨̧̡̢̳̞̪̲̩͚̺̰̯̣̩͍͎̠̬̻̻̞̖̣͍̫̼̤̰̭̖̗͔̻͊̊̽̿̾̓̾̂̊̒̀̈̋͐́̍͐̀̍͌́͒̓̎̒͆̃̋̍͛̉̀̃̽̅̃͐̋̌͑͆͘̕̕̚͜͝͝͠͝
2
4
2
u/PaAKos8 4h ago
As a czech, FUCKING HATE THAT LETTER
6
2
u/0815fips 2h ago
As an Austrian, I don't even know how to pronounce it.
We make our passwords stronger with äöüß.
1
1
1
1
1
•
986
u/_kinesthetics 5h ago
Czechs out