Live data from Hacker News

Password Rules Are Bullshit

blog.codinghorror.com

171–180 of 283 posts

Re: Password Rules Are Bullshit

#171
post #35
post #25

I agree with almost everything but the he loses me towards the end: > I had a bit of a sad when I realized that we were perfectly fine with users selecting a 10 character password that was literally "aaaaaaaaaa". In my opinion, the simplest way to do this is to ensure that there are at least (x) unique characters out of (y) total characters. Isn't that exactly what you're complaining about with your arbitrary passwor…

Yes and yes! Many throwaway accounts I have use some variation of the same password, because I don't care if someone hacks my HN or reddit or youtube account. I don't use my real name on any of them. If I lose control of it, I'll just make a new one. (Karma doesn't pay the bills, and I don't make money from my very excellent youtube comments; someone else does.) This is why all these accounts get an email account tha…

> because I don't care if someone hacks my HN or reddit or youtube account. I don't use my real name on any of them. Så heter du inte Sverige?

Re: Password Rules Are Bullshit

#172
post #25

I agree with almost everything but the he loses me towards the end: > I had a bit of a sad when I realized that we were perfectly fine with users selecting a 10 character password that was literally "aaaaaaaaaa". In my opinion, the simplest way to do this is to ensure that there are at least (x) unique characters out of (y) total characters. Isn't that exactly what you're complaining about with your arbitrary passwor…

Yes! Left me make my own bad life decisions and get out of my way.

Nothing makes me immediately dismiss a site or piece of software faster than nannying me, especially from go.

Re: Password Rules Are Bullshit

#173
post #3

Here's another problem that isn't discussed very much: error messaging and failure modes. I use a command line tool to generate passwords, and I use a password database to store them. It has happened to me before that the maximum password length is something disconcertingly small, like 20 characters. I would copy and paste my password, submit, and then failed to be able to login. Why? Because my password in the "crea…

Hotmail did that my super long password, it freaked me out at first and I had to guess where the cut-off happened because I couldn't find the damn password length.

Re: Password Rules Are Bullshit

#174

Earlier quoted context omitted.

You really shouldn't be re-using passwords across sites anyway, since all your accounts are compromised if any of them are compromised. Since re-using passwords is a problem solved by using a password manager, I'm assuming you're not using one, in which case you likely won't even remember the list of sites where you have accounts that have a shared password if you need to change it when any of the other sites are com…

Most of my accounts use my low-security password, I don't care much if they all get compromised. I only use my high-security password on 1 site. Password managers are horrible - Whenever I change machines, I could never remember all my passwords and I certainly don't want to store my passwords in the cloud.

> I certainly don't want to store my passwords in the cloud

But you're not. You're storing an encrypted blob in the cloud. You just need a good master password and a password manager that isn't broken.

Re: Password Rules Are Bullshit

#175
post #25

I agree with almost everything but the he loses me towards the end: > I had a bit of a sad when I realized that we were perfectly fine with users selecting a 10 character password that was literally "aaaaaaaaaa". In my opinion, the simplest way to do this is to ensure that there are at least (x) unique characters out of (y) total characters. Isn't that exactly what you're complaining about with your arbitrary passwor…

> "your bank password is Axei5aoc0i, write it down somewhere safe"

"So I send it to my mail account for when I am on the go... that account with the qwerty password..."

The point being, you can't really protect users from themselves so a bank can't build it's security model upon the assumption of safe user accounts.

Re: Password Rules Are Bullshit

#176
post #49

Earlier quoted context omitted.

I am being serious when I ask this question: does anybody brute force passwords? I posit that using a unique password for every single website is sufficient, because no one brute forces passwords. What attack vector is a password with high entropy protecting against? The only one I can think of is an unreported database leak. The attacker may be able to more easily reverse the password hash and use your account on th…

I was wondering this as I read it as well. Yes, we know it would be fairly easy to compromise an individual account by guessing common passwords. But that assumes you have one particular account in mind. If you're just looking for bank accounts to access, you first need a list of usernames to try (ideally usernames of non-tech-savvy people) and then you need to run your entire password guessing routine for each one.…

My wife had an account hacked years ago. I don't know for sure that it was brute forced (could have been phished or exfiltrated by a keylogger or session jacked with an XSS vulnerability or...), but I also don't know that it wasn't brute forced. She used very short, simple passwords at the time.

Come to think of it, I also had an old account with a very weak password that I hadn't used in years mysteriously hacked one day. The language settings were changed to Russian when I went to reset my password. The fact that no other account of mine appeared to be compromised and I hadn't used the site in years certainly suggests brute forcing.

Re: Password Rules Are Bullshit

#177

Earlier quoted context omitted.

Wonder what other sins are there. A couple of years ago when iCloud was first a thing, I did a couple of password changes in quick succession. It resulted in me having different login passwords for different iCloud services. It worked for a short time then broke and another reset fixed it all.

Enforced password reset questions. There's a limited set of about 10 questions (trivial stuff like "where were you born?"), and you have to set 3 of them. About half a year ago, I was forced to do this in order to be able to log in again (I'm only occasionally using it for publishing iOS apps). What is this, Hotmail in 2005?

My favorite restaurant in college is a high-end hotel in Johannesburg (actually it's not, and I've never even been to Africa unless you count a week I spent on Tenerife as a child).

Re: Password Rules Are Bullshit

#178

Earlier quoted context omitted.

Imposed passwords aren't the only solution. Something like Google Authenticator is an alternative. Or key fobs. Or send a confirmation code to their phone. Or something like Barclays' PINsentry [1] for cards where you need the gadget, the card and the PIN. Or face recognition, which I recently saw demonstrated (it includes liveness checks like asking you to blink). [1] http://www.barclays.co.uk/Helpsupport/UpgradetoP…

Authenticator is great, but then you get the arsehole effect - every arsehole company decision maker wants you to only use their authenticator. So, I made an account on MS recently and can't use GA because "fuck you user, we won't stop until we own every facet of your digital existence" or something. That shows you where such companies rank security. [FWIW I expect the reverse situation is probably the same, this is…

Assuming MS means Microsoft then you are incorrect. You can use Google Authenticator just fine with Microsoft accounts (because I'm doing it.)

Re: Password Rules Are Bullshit

#179
post #82

Earlier quoted context omitted.

Two ways why I think E-Mails are useful at signup: - Password Recovery (this can be optional though, for my sites it usually is) - 'Legit Users', sending an email and having them confirmed through a code in them gives a bit more confidence in the user

'legit users' There isn't a day that goes by that I don't get an email intended for someone else, often including personal information, due to a mistyped email address. Whoever decided that email verification was a poor user experience needs to be hit in the head with a shovel after he digs the appropriate sized hole. If you know Catherin (PA) let her know her round trip to vegas is confirmed Carolyn's (NYC) open tab…

As someone with an unusual name (used for my public-facing email address) and who uses a fairly unusual email for personal stuff... that's pretty different from my experiences. I've never ended up with someone else's mail at all.

That's a solid argument for business cards with vCard QR codes as I see it. Or a pack of stickers with QR codes that you could slap on whatever documents you needed.

It's too bad QR code adoption is so horrible. I'm just as guilty of it as anyone else, I assume that any QR code is probably just some marketing thing.

But vCards seem like one of the very legit use-cases. Now that I am imagining using stickers and never filling out my contact info on a form again, I realize that's definitely a world I want to live in.

Re: Password Rules Are Bullshit

#180
post #82

Earlier quoted context omitted.

Two ways why I think E-Mails are useful at signup: - Password Recovery (this can be optional though, for my sites it usually is) - 'Legit Users', sending an email and having them confirmed through a code in them gives a bit more confidence in the user

'legit users' There isn't a day that goes by that I don't get an email intended for someone else, often including personal information, due to a mistyped email address. Whoever decided that email verification was a poor user experience needs to be hit in the head with a shovel after he digs the appropriate sized hole. If you know Catherin (PA) let her know her round trip to vegas is confirmed Carolyn's (NYC) open tab…

What's even more annoying is that some sites ask for verification, but then proceed to email you stuff even if you don't click verify. Someone in Australia created an Apple ID using my email. I ignored the verification, but then I got a bunch of purchase receipts from them later.

What I really wish for is a link in emails that say "I am not the intended recipient of this letter." Normal mail works like that. You can ask the United States Postal Service to only deliver mail that has your name on it, and if you send back mail with someone else's name they will add that person's name to a database that says the mail is undeliverable.

I don't want to mark these organizations as spam, but that's basically what they are to me. I've started using the password reset to log in and change the email preferences so I don't get these emails anymore.

Post reply on HN