TSP password enhanced today

Non-investing personal finance issues including insurance, credit, real estate, taxes, employment and legal issues such as trusts and wills.
Post Reply
Topic Author
TSR
Posts: 1252
Joined: Thu Apr 19, 2012 9:08 am

TSP password enhanced today

Post by TSR »

I was gratified to see that when I logged into the TSP site today, I was prompted to change my password to something with at least ten digits, at least one capital and one lowercase letter, one number, and one special character. Greater password security has been a long time coming for the TSP and I'm happy it's here! Go in and change your passwords when you get a chance.
SamB
Posts: 826
Joined: Mon Mar 12, 2007 3:17 pm

Re: TSP password enhanced today

Post by SamB »

This is good for TSP security, but it looks like the outside funds option display on the Vanguard website is set to a maximum of eight characters. I wonder when they will fix this. My TSP listings all went away.
powersmo
Posts: 43
Joined: Mon Jan 07, 2008 3:34 pm

Re: TSP password enhanced today

Post by powersmo »

I also noticed a need to change password to conform with security requirements. What does everyone use for a combined view of all accounts (VG, TSP et all) that will not bomb once a week? I had looked at Mint some time ago but wondered if there was a better alternative.
JVT
Posts: 95
Joined: Sun Feb 23, 2014 10:40 am

Re: TSP password enhanced today

Post by JVT »

SamB wrote:This is good for TSP security, but it looks like the outside funds option display on the Vanguard website is set to a maximum of eight characters. I wonder when they will fix this. My TSP listings all went away.
I already talked with VG and they passed it along to CashEdge, the VG rep seemed to think it would be taken care of pretty quickly.
powersmo
Posts: 43
Joined: Mon Jan 07, 2008 3:34 pm

Re: TSP password enhanced today

Post by powersmo »

VG fast reply is good news. I still wouldn't mind looking at other alternatives. I have used the VG interface for this at some length and have more or less liked it ok.
Alan S.
Posts: 12669
Joined: Mon May 16, 2011 6:07 pm
Location: Prescott, AZ

Re: TSP password enhanced today

Post by Alan S. »

Is having more possible characters and combinations a meaningful source of added security, or is the greater risk someone hacking in and determining exactly what you set up as your password, as well as all the other TSP participants? Remembering all your various passwords is less likely the longer they get, which means you write them down and your notes could be lost or stolen? So is this really a practical security improvement considering all the implications? And is so, when will we be typing in 20 or 30 characters?
User avatar
TimeRunner
Posts: 1939
Joined: Sat Dec 29, 2012 8:23 pm
Location: Beach-side, CA

Re: TSP password enhanced today

Post by TimeRunner »

Alan S. wrote:Is having more possible characters and combinations a meaningful source of added security, or is the greater risk someone hacking in and determining exactly what you set up as your password, as well as all the other TSP participants? Remembering all your various passwords is less likely the longer they get, which means you write them down and your notes could be lost or stolen? So is this really a practical security improvement considering all the implications? And is so, when will we be typing in 20 or 30 characters?
Use a password manager and a completely random password.
One cannot enlighten the unconscious. | "All I need are some tasty waves, a cool buzz, and I'm fine." -Jeff Spicoli
stan1
Posts: 14246
Joined: Mon Oct 08, 2007 4:35 pm

Re: TSP password enhanced today

Post by stan1 »

Glad to see it, maybe they will add two factor authentication sometime before I retire in 2024.
Warning: I am about 80% satisficer (accepting of good enough) and 20% maximizer
TheGreyingDuke
Posts: 2219
Joined: Fri Sep 02, 2011 10:34 am

Re: TSP password enhanced today

Post by TheGreyingDuke »

What is TSP :?:
"Every time I see an adult on a bicycle, I no longer despair for the future of the human race." H.G. Wells
User avatar
baw703916
Posts: 6681
Joined: Sun Apr 01, 2007 1:10 pm
Location: Seattle

Re: TSP password enhanced today

Post by baw703916 »

Thrift
Savings
Plan

The Federal government equivalent of a 401k.

Noteworthy because it has even lower expenses than Vanguard, and a bond fund that makes TBM pale by comparison.
Most of my posts assume no behavioral errors.
sherwink
Posts: 332
Joined: Mon May 28, 2007 9:48 am

Re: TSP password enhanced today

Post by sherwink »

Thrift Savings Plan. It's the US Government employees 401k plan.
JVT
Posts: 95
Joined: Sun Feb 23, 2014 10:40 am

Re: TSP password enhanced today

Post by JVT »

Linked accounts now works again with new password requirements.
rkhusky
Posts: 17766
Joined: Thu Aug 18, 2011 8:09 pm

Re: TSP password enhanced today

Post by rkhusky »

Alan S. wrote:Is having more possible characters and combinations a meaningful source of added security, or is the greater risk someone hacking in and determining exactly what you set up as your password, as well as all the other TSP participants? Remembering all your various passwords is less likely the longer they get, which means you write them down and your notes could be lost or stolen? So is this really a practical security improvement considering all the implications? And is so, when will we be typing in 20 or 30 characters?
I have an account that requires 15+ characters with 2 each of upper, lower, number, special character. And you have to change it every 60 days.

The long password requirements are not to prevent hacking via the web interface, because a 6-8 character password and limiting the number of login attempts would handle that. It is to prevent someone from stealing the password file from the company's internal computer network and using supercomputer and/or cloud computing resources to break the encryption on the file.
User avatar
Epsilon Delta
Posts: 8090
Joined: Thu Apr 28, 2011 7:00 pm

Re: TSP password enhanced today

Post by Epsilon Delta »

rkhusky wrote:
Alan S. wrote:Is having more possible characters and combinations a meaningful source of added security, or is the greater risk someone hacking in and determining exactly what you set up as your password, as well as all the other TSP participants? Remembering all your various passwords is less likely the longer they get, which means you write them down and your notes could be lost or stolen? So is this really a practical security improvement considering all the implications? And is so, when will we be typing in 20 or 30 characters?
I have an account that requires 15+ characters with 2 each of upper, lower, number, special character. And you have to change it every 60 days.

The long password requirements are not to prevent hacking via the web interface, because a 6-8 character password and limiting the number of login attempts would handle that. It is to prevent someone from stealing the password file from the company's internal computer network and using supercomputer and/or cloud computing resources to break the encryption on the file.
Not really. If you're using a properly salted slow hash function 10 character lower case is fine. The long password requirements are either pure theater or because the person running the site thinks it's easier to blame the user than do his job.
User avatar
Blues
Posts: 2501
Joined: Wed Dec 10, 2008 10:58 am
Location: Blue Ridge Mtns

Re: TSP password enhanced today

Post by Blues »

Thanks for bringing this to our attention. Updated with a significantly stronger password. :beer
rkhusky
Posts: 17766
Joined: Thu Aug 18, 2011 8:09 pm

Re: TSP password enhanced today

Post by rkhusky »

Interesting article on password file cracking that shows why you shouldn't use dictionary words in your passwords:

http://arstechnica.com/security/2013/05 ... passwords/
Post Reply