Live data from Hacker News

Dumb Password Rules

github.com

21–30 of 86 posts

Re: Dumb Password Rules

#23
post #7

My favorites are the ones where you can't use more than a certain number of characters or where you can't use special characters.

Like Microsoft account passwords (at least for office 365). I don't understand why they do this.

Re: Dumb Password Rules

#24
I use KeePass to store all of my (randomly generated) passwords.

One ongoing annoyance is that it's increasingly difficult to generate a random string will be meet a given site's Dumb Password Rules, because so many sites have them, and there's surprisingly little overlap in the rules.

I would really like to see a database of sites and their corresponding Dumb Password Rules, so that I can tell KeePass (or any other app using the database) to generate me a new Mindware password, or a new Williams-Sonoma password, and get a random string that conforms to all the relevant DPRs.

Re: Dumb Password Rules

#25
post #7

My favorites are the ones where you can't use more than a certain number of characters or where you can't use special characters.

Or they say cannot accept repeating characters. Like "2j4lwroiw4lkf9wwjsofserow111" is still bad because of 111.

Re: Dumb Password Rules

#26
post #5

In the same spirit, can we please do away with the idea of expiring passwords -- and then enforcing that we can't even re-use our last X number of passwords. It just causes locked out accounts, written down passwords or adding on one more of whatever character was at the end.

There is a specific reason for having "cant reuse last X number of passwords" combined with having an "expiring password" rule. The idea is that if someone was silently in your account, and doing a "stealth" attack - then they could change your password, then change it back to your original password, thus "resetting" your expiring password timer, giving them more time in the system - and you would not know that the p…

Although, a lot of accounts send immediately E-mail on changes (e.g. bank says “the password on your account was changed” so you would know if someone was changing it and changing it back). It actually seems pretty reasonable to send E-mails on every single account update, as some sites do.

Re: Dumb Password Rules

#27
I think that if you intend to “shame” something, you should at least start out with proper channels (e.g. send an E-mail, file a bug, whatever). Also, it’s not really going to shame them unless you point them to the place they’re being shamed.

In the end, what is more important: seeing the situation improved or just complaining?

Re: Dumb Password Rules

#28
post #23
post #7

My favorites are the ones where you can't use more than a certain number of characters or where you can't use special characters.

Like Microsoft account passwords (at least for office 365). I don't understand why they do this.

They do this because it makes it easier for the 3 letter US agency to guess the password.

Re: Dumb Password Rules

#29
post #13
post #11

How about allowing special characters and not just a-zA-Z0-9.

Usually, there is some legacy system behind the scenes that can't be updated because reasons. Not an excuse, but it isn't always that easy.

I wonder if another reason may be the differences between traditional PCs and mobile devices with virtual keyboards. I've seen special characters that are two taps away on my phone that I'd have to look up an Alt code for on my PC.

Re: Dumb Password Rules

#30

I use KeePass to store all of my (randomly generated) passwords. One ongoing annoyance is that it's increasingly difficult to generate a random string will be meet a given site's Dumb Password Rules, because so many sites have them, and there's surprisingly little overlap in the rules. I would really like to see a database of sites and their corresponding Dumb Password Rules, so that I can tell KeePass (or any other…

KeePass should let users configure a pattern for passwords, like "8-25 letters or numbers or these symbols, must have 1 uppercase letter", and just replicate that socially (the pair of web site and pattern) across all KeePass users.
Post reply on HN