top 50 comments

sorted by: hot top controversial new old
[–] 32 points 3 days ago (3 children)

Nothing infuriates me more than when they ask me to reduce my 20 char alphanumeric+symbols unique password to a 4 char numeric pin for my security.

  • source
  • hideshow 3 child comments
  • [–] 7 points 3 days ago (2 children)

    My (soon to be ex) bank recently decided to make everyone use their ID card number which can be obtained from many sources and does not change, a username with symbols and numbers and minimal length requirements which cannot be changed and a 4 digit pin code. No 2FA at all, so its only saving grace is that you get locked out at 3 tries.

    I'm guessing they are trying to align everything to their legacy ATM pin code system instead of making the ATM system better.

  • source
  • parent
  • hideshow 2 child comments
  • load more comments (2 replies)
  • [–] 119 points 3 days ago (21 children)

    It's also a gigantic red flag when sites say there's a password limit

    Bitch, my password is supposed to be hashed so even if I uploaded the LOTR trilogy extended edition in 4K, it should still come out the same length as any other SHA256 hash

  • source
  • hideshow 21 child comments
  • [–] 58 points 3 days ago (6 children)

    In systems that accept whitespace, “Live, Laugh, Love” is considered a strong password.

    With that being said, “In systems that accept whitespace, “Live, Laugh, Love” is considered a strong password.” is an even stronger password.

  • source
  • hideshow 6 child comments
  • [–] 27 points 3 days ago (3 children)

    I love systems that accept "With that being said, "In systems that accept whitespace, "Live, Laugh, Love" is considered a strong password." is an even stronger password." as my password.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 19 points 3 days ago (2 children)

    For those that have full Unicode support, including newline characters and a very high or nonexistent character limit, using:

    For those that have full Unicode support, including newline characters and a very high or nonexistent character limit, using:

    I love systems that accept "With that being said, "In systems that accept whitespace, "Live, Laugh, Love" is considered a strong password." is an even stronger password." as my password.

    as your password is an even stronger password.

    as your password is an even stronger password.

  • source
  • parent
  • hideshow 2 child comments
  • load more comments (1 reply)
  • [–] 32 points 3 days ago (1 child)

    Your password must be at least 10 characters long.

    ERROR: INVALID PASSWORD ENTERED!!!

    PASSWORD MUST NOT EXCEED 12 CHARACTERS!

  • source
  • hideshow 1 child comment
  • [–] 14 points 3 days ago (4 children)

    And don't you dare use stuff like , or ç as a special character!

  • source
  • hideshow 4 child comments
  • [–] 5 points 3 days ago (3 children)
  • [–] 13 points 3 days ago (11 children)

    I have 5-6 apps I log into for work that all have different password requirements and are on different expiration periods. One of them is so crazy that I have to take 3-4 spins on a password generator before I get one it will accept. We also don't have a password manager that's approved to install. So, the result of all this is that I store my passwords in onenote. Very secure. Great job everyone. At least for the less severe ones I can just put whatever number I'm tagging on the end of the usual password I use.

  • source
  • hideshow 11 child comments
  • [–] 12 points 3 days ago (5 children)

    We had a system at one of my old companies that with each password change, you couldn't have any of the same characters that were in your last password (12 character max so it was never impossible to solve), you couldn't have the same character in the same place as any of your last 10 passwords, or the same character type (letter or number) in the same space as the last password. Also no special characters.

    The end result was everyone ended up using a1a1a1a1 for the first password, then 2b2b2b2b, c3c3c3c3, 4d4d4d4d, etc. The draconian password requirements resulted in everyone using the same passwords.

  • source
  • parent
  • hideshow 5 child comments
  • [–] 29 points 3 days ago (15 children)

    Fun fact: As an anti-scam measure, if you type your password in a comment, Lemmy will automatically censor it for you.

    Like this:

    ************

    Cool, right?

  • source
  • hideshow 15 child comments
  • load more comments (3 replies)
    [–] 25 points 3 days ago (1 child)

    correct horse battery staple

  • source
  • hideshow 1 child comment
  • [–] 16 points 3 days ago

    Requiring specific characters reduces the number of permutations. The only thing that makes a password more secure is increasing the minimum length. As the OP suggests, enforcing special characters makes most people just put a special character at the end. What you have effectively done is make the last character so easy to guess that it might as well not exist.

  • source
  • [–] 14 points 3 days ago

    My new job has us doing various security trainings every month and they also send out fake phishing emails. I initially ignored the emails prompting me to do the training because they require you to click a personalized link in the email to access the training. Eventually, my manager reached out and asked why I hadn't done the training, so I explained, but finally clicked through to do it. That month's training was about how a long passphrase is more secure than a list of character type requirements. Guess whose password requirements are a list of character type requirements?

  • source
  • [–] 2 points 2 days ago

    Let me introduce you to MyP4s$worcl*websitename**@

  • source
  • [–] 13 points 3 days ago (1 child)

    for real, why is it so hard to count entropy?

  • source
  • hideshow 1 child comment
  • load more comments (1 reply)
    [–] 3 points 3 days ago (2 children)

    Do you want your password to be sent raw into a service to analyze your password entropy and detect common patterns, OR do you want a simple rule which can be checked client side?

  • source
  • hideshow 2 child comments
  • [–] 5 points 2 days ago

    You don't send full raw hashes, k-anonymity is a thing. HaveIBeenPwned just takes the first 5 of a hash and sends you back a list that you compare clientside so it never leaves as a usable password.

  • source
  • parent
  • load more comments
    view more: next ›