454
top 36 comments
sorted by: hot top new old
[-] Etterra@discuss.online 1 points 7 hours ago

When it's for something I don't like, I like to include a nice insult in there.

[-] darthsundhaft@piefed.social 6 points 16 hours ago

For those wondering, sudo in Linux can be configured to insult you when you get your password wrong.

I am not making this up...

[-] unemployedclaquer@sopuli.xyz 2 points 13 hours ago

I told ma to pretend she is Linda Hamilton, not sure that worked

[-] clay_pidgin@sh.itjust.works 30 points 1 day ago* (last edited 1 day ago)

I just hate it when a program or website has a MAXIMUM password length, and despise even more when the password requirements/limits aren't shown on the page. "Failed to update password" WHY!? WHY DID IT FAIL!? Oh, you think 16 characters is enough? Were my extra 70 bytes of storage space hurting your margins?

I use a password manager and I've twice seen a website not let me in with my saved credentials, and on resetting my account discovering that the maximum password length is now shorter than the password I have been using for months. If you are going to change the password constraints, fine, but you could allow login once and immediately force a password change.

[-] JustAnotherKay@lemmy.world 18 points 22 hours ago

I’ve seen it one step further. I can’t remember what the service was, but I signed up for it and copy pasted the password into my password manager, then tried to sign in with it. Couldn’t. Went back and forth with the “forgot my password” page about three times before I realized that not only was there a limit to the text length: you auto-truncated my input upon saving with no indication to me

[-] lightnsfw@reddthat.com 3 points 19 hours ago

I've run into that before too. The extra stupid part was the app was different than their website so the password worked on one but I had to drop some characters to use it on the other.

[-] clay_pidgin@sh.itjust.works 5 points 21 hours ago

That's so annoying!

I've also seen a login form where the username field also has the password type, so my password manager pastes the password in both!

[-] nforminvasion@lemmy.world 3 points 22 hours ago

Believe it not, straight to jail.

[-] OwOarchist@pawb.social 7 points 21 hours ago

and despise even more when the password requirements/limits aren’t shown on the page

When they drip-feed you just one requirement at a time, only telling you one requirement that your chosen password doesn't meet, and then they'll tell you one more requirement that your next password doesn't meet...

[-] clay_pidgin@sh.itjust.works 5 points 21 hours ago

Maybe don't play this game...https://neal.fun/password-game/

[-] Nat997@lemmy.blahaj.zone 11 points 1 day ago

Correct me if I'm wrong, but if websites store your password in plain text, that's already bad enough. As far as I'm aware basic hashing - as in taking the password and transforming it into a fixed length sequence - is (or at least should be) common sense. So if credentials are stored as a hash (or a fixed sequence), then the only logical reason for enforcing a limit on password length should be hash collisions (which are only possible if you're using a terrible hashing algorithm). I don't really know what I wanted to say with this, my brain just spontaneously jumped to hashing and the bunch.

[-] marcos@lemmy.world 7 points 23 hours ago

It's somewhat common to limit password lengths to avoid DoS attacks that exploit a slow key generation function.

But that limitation should on some hundreds or a few thousands characters. Sites that use limits like "16" are probably storing them as plain text.

[-] clay_pidgin@sh.itjust.works 3 points 23 hours ago

I appreciate your comment anyway! I didn't know passwords would be hashed to a consistent length - I can see how that would be more secure.

I don't think in the cases that I mentioned, that the hash of my entered/saved/extralong password was being compared to the stored hash they had on file, I think what happened is the input field validation was changed and would no longer allow a password that was valid under their previous rules.

[-] Blue_Morpho@lemmy.world 36 points 1 day ago

Ok, I'll capitalize the first letter and add an exclamation point to the end. Happy?

I bet brute force hash checkers assume the first letter is capitalized because of current password policies.

[-] anomnom@sh.itjust.works 2 points 13 hours ago

I used to capitalize the last 2-3 when I still picked passwords. But now I less my keychain app do it all.

[-] jaybone@lemmy.zip 10 points 21 hours ago

The hacker known as 4chan.

[-] Jiggle_Physics@quokk.au 17 points 23 hours ago

Me, as I pour some water on myself: Oh, look, it doesn't damage me at all, in fact, it feels kinda nice! Let's see how well you deal with water being poured on you!

Computer: Your, password is fine, actually, nothing else needed!

Me: No, no, you are gonna find out what happens when I pour water into you power supply.

Computer: No need for that! You know, Linda really is a bitch! You have been dealing with a...

Me Pouring water: Yes, she is, isn't she?

Computer makes some fizzle, and pop noises, then completely silent, monitor blank: ...

[-] Grostleton@lemmy.dbzer0.com 25 points 1 day ago

At that point you just slap random letters and numbers without paying attention and then waste an hour+ contacting IT to get it reset because you "forgot" and got locked out.

Password policy is mostly bullshit anyway since most "hackers" these days are just performing social engineering on morons with no sense in order to get in.

[-] ZeDoTelhado@lemmy.world 18 points 1 day ago

There is actually a lot more to this: a lot of people in the it sec crowd have been saying for many years that this habit of the gibberish passwords with symbols capitals and whatnot is actually a net deficit in security. Mostly because for the longest time people had to mostly remember all passwords and the policies for rotation were to aggressive (which lead to "lazy" changes). Nowadays unfortunately we still have people that inherited this thinking and still enforce this, but you also see a lot of people understanding that pass phrases are a lot better (of course should not be a predictable phrase like good morning, but it is possible to make it much better with way less effort)

[-] agamemnonymous@sh.itjust.works 5 points 18 hours ago

Correct horse battery staple

[-] Hasherm0n@lemmy.world 2 points 14 hours ago

More that just "... a lot of people..." NIST themselves published real research backing this up over a decade ago.

[-] OwOarchist@pawb.social 8 points 21 hours ago

Password policy is mostly bullshit anyway since most “hackers” these days are just performing social engineering on morons with no sense in order to get in.

Ah, now I get it. That's why they enforce password policies that make the password impossible to remember -- you can't give a hacker your password if you don't know your password! Genius!

[-] DanceMomsSavedMe@lemmy.zip 6 points 19 hours ago

This is what I feel like as the user every time I have to dual boot into Windows.

Not the password thing. Just the overall way the computer treats me

[-] lightnsfw@reddthat.com 5 points 19 hours ago

Part of your password was found in our database of passwords that have been compromised by someone somewhere. No we're not going to tell you which part. Pick a new password.

[-] shininghero@pawb.social 13 points 1 day ago

Active Directory by default does not enforce a minimum password age. If you have a good strong one already that you know isn't compromised, you could just spam 24 password changes as fast as you want and boom. Your old password drops out of the history and can be used again.

[-] AngryCommieKender@lemmy.world 8 points 23 hours ago
[-] LeFrog@discuss.tchncs.de 7 points 23 hours ago
[-] baggachipz@sh.itjust.works 7 points 23 hours ago

My company’s password policy requires, among many other things, “no repeating characters”. Like what the Christ. How does all this bullshit make it more secure? I store my login in a password manager with far looser requirements, so fuck yo security

[-] terranoid@lemmy.cafe 4 points 21 hours ago* (last edited 21 hours ago)

Me: uses random string from password manager

Computer: password not secure enough

Me: provides 30 randomly selected words from a large dictionary and a cryptographically secure random number generator

Computer: no no I meant add a ! to the end, really yell your password. Make me think you mean it :)

[-] FiniteBanjo@feddit.online 5 points 22 hours ago
[-] Some_Emo_Chick@lemmy.world 9 points 21 hours ago

I'll be alright. sniff

[-] ThatWeirdGuy1001@lemmy.world 2 points 19 hours ago

New password cannot be the same as old password

[-] MutantTailThing@lemmy.world 3 points 1 day ago

Just roll your face across your entire keyboard three times.

[-] Makhno@lemmy.world 2 points 1 day ago

Hahaha Oh Linda! Its always Linda isnt it, folks?

laugh track to shitty generic joke

[-] Viceversa@lemmy.world 1 points 17 hours ago

Are you Linda or her associate?

[-] ndupont@lemmy.blahaj.zone 0 points 20 hours ago

Wow, what kind of prompt do you need to have Claude talk back to you like that?

this post was submitted on 27 Jul 2026
454 points (96.3% liked)

Lemmy Shitpost

41056 readers
5614 users here now

Welcome to Lemmy Shitpost. Here you can shitpost to your hearts content.

Anything and everything goes. Memes, Jokes, Vents and Banter. Though we still have to comply with lemmy.world instance rules. So behave!


Rules:

1. Be Respectful


Refrain from using harmful language pertaining to a protected characteristic: e.g. race, gender, sexuality, disability or religion.

Refrain from being argumentative when responding or commenting to posts/replies. Personal attacks are not welcome here.

...


2. No Illegal Content


Content that violates the law. Any post/comment found to be in breach of common law will be removed and given to the authorities if required.

That means:

-No promoting violence/threats against any individuals

-No CSA content or Revenge Porn

-No sharing private/personal information (Doxxing)

...


3. No Spam


Posting the same post, no matter the intent is against the rules.

-If you have posted content, please refrain from re-posting said content within this community.

-Do not spam posts with intent to harass, annoy, bully, advertise, scam or harm this community.

-No posting Scams/Advertisements/Phishing Links/IP Grabbers

-No Bots, Bots will be banned from the community.

...


4. No Porn/ExplicitContent


-Do not post explicit content. Lemmy.World is not the instance for NSFW content.

-Do not post Gore or Shock Content.

...


5. No Enciting Harassment,Brigading, Doxxing or Witch Hunts


-Do not Brigade other Communities

-No calls to action against other communities/users within Lemmy or outside of Lemmy.

-No Witch Hunts against users/communities.

-No content that harasses members within or outside of the community.

...


6. NSFW should be behind NSFW tags.


-Content that is NSFW should be behind NSFW tags.

-Content that might be distressing should be kept behind NSFW tags.

...

If you see content that is a breach of the rules, please flag and report the comment and a moderator will take action where they can.


Also check out:

Partnered Communities:

1.Memes

2.Lemmy Review

3.Mildly Infuriating

4.Lemmy Be Wholesome

5.No Stupid Questions

6.You Should Know

7.Comedy Heaven

8.Credible Defense

9.Ten Forward

10.LinuxMemes (Linux themed memes)


Reach out to

All communities included on the sidebar are to be made in compliance with the instance rules. Striker

founded 3 years ago
MODERATORS