Nothing infuriates me more than when they ask me to reduce my 20 char alphanumeric+symbols unique password to a 4 char numeric pin for my security.
post
It's also a gigantic red flag when sites say there's a password limit
Bitch, my password is supposed to be hashed so even if I uploaded the LOTR trilogy extended edition in 4K, it should still come out the same length as any other SHA256 hash
Clearly you have undiscovered SHA256 collisions that you want to attack the website with.
I appreciate the enthusiasm but my load balancer will get sad if I let you send more than 1500 bytes.
Must be 8 to 14 characters 😡
I make my passwords complex phrases with spaces and punctuation included. e.g. "Correct, horse battery staple!"
(obligatory that's not my password)
In systems that accept whitespace, “Live, Laugh, Love” is considered a strong password.
With that being said, “In systems that accept whitespace, “Live, Laugh, Love” is considered a strong password.” is an even stronger password.
I love systems that accept "With that being said, "In systems that accept whitespace, "Live, Laugh, Love" is considered a strong password." is an even stronger password." as my password.
For those that have full Unicode support, including newline characters and a very high or nonexistent character limit, using:
For those that have full Unicode support, including newline characters and a very high or nonexistent character limit, using:
I love systems that accept "With that being said, "In systems that accept whitespace, "Live, Laugh, Love" is considered a strong password." is an even stronger password." as my password.
as your password is an even stronger password.
as your password is an even stronger password.
all fun and games until you find out it strips whitespace/newlines on save without telling you and you gotta go figure out why your passwords not working
This reads like xkcd
Your password must be at least 10 characters long.
ERROR: INVALID PASSWORD ENTERED!!!
PASSWORD MUST NOT EXCEED 12 CHARACTERS!
And don't you dare use stuff like , or ç as a special character!
I like it when they ban ;
I have 5-6 apps I log into for work that all have different password requirements and are on different expiration periods. One of them is so crazy that I have to take 3-4 spins on a password generator before I get one it will accept. We also don't have a password manager that's approved to install. So, the result of all this is that I store my passwords in onenote. Very secure. Great job everyone. At least for the less severe ones I can just put whatever number I'm tagging on the end of the usual password I use.
We had a system at one of my old companies that with each password change, you couldn't have any of the same characters that were in your last password (12 character max so it was never impossible to solve), you couldn't have the same character in the same place as any of your last 10 passwords, or the same character type (letter or number) in the same space as the last password. Also no special characters.
The end result was everyone ended up using a1a1a1a1 for the first password, then 2b2b2b2b, c3c3c3c3, 4d4d4d4d, etc. The draconian password requirements resulted in everyone using the same passwords.
You know some turd in the IT department was so proud of themselves for coming up with that too.
At work my main password has to be changed every two weeks and has insane requirements and we can only use some shit company approved password manager which I cant even install on a rooted phone. This has resulted me in just changing 1 digit every 2 weeks, 10/10 guys!
Fun fact: As an anti-scam measure, if you type your password in a comment, Lemmy will automatically censor it for you.
Like this:
************
Cool, right?
How does mine look?
Hunter2
correct horse battery staple
Requiring specific characters reduces the number of permutations. The only thing that makes a password more secure is increasing the minimum length. As the OP suggests, enforcing special characters makes most people just put a special character at the end. What you have effectively done is make the last character so easy to guess that it might as well not exist.
My new job has us doing various security trainings every month and they also send out fake phishing emails. I initially ignored the emails prompting me to do the training because they require you to click a personalized link in the email to access the training. Eventually, my manager reached out and asked why I hadn't done the training, so I explained, but finally clicked through to do it. That month's training was about how a long passphrase is more secure than a list of character type requirements. Guess whose password requirements are a list of character type requirements?
for real, why is it so hard to count entropy?
Do you want your password to be sent raw into a service to analyze your password entropy and detect common patterns, OR do you want a simple rule which can be checked client side?
You don't send full raw hashes, k-anonymity is a thing. HaveIBeenPwned just takes the first 5 of a hash and sends you back a list that you compare clientside so it never leaves as a usable password.
Analyze password entropy client-side. https://dropbox.tech/security/zxcvbn-realistic-password-strength-estimation

top 50 comments