Live data from Hacker News

Password Rules Are Bullshit

blog.codinghorror.com

211–220 of 283 posts

Re: Password Rules Are Bullshit

#211
Let's imagine a theoretical world in which every service had a 12 or 15 character limit on their passwords and no other restrictions.

Does anyone really believe that the list of most common passwords would not contain equally inane entries as the ones presented in this article, just modified to be longer? "qwerty" would just become "qwertyuiop", etc. People using these passwords are just filling the minimum requirements with something easy to remember. Making them fill more characters wouldn't really change that.

The only reason the most common passwords are short is because so many services allow short passwords. Users gonna be users no matter how long their passwords need to be.

That said, I agree with the article in spirit. I hate password restrictions. I just think that the argument about most common passwords being short is a spurious one.

Re: Password Rules Are Bullshit

#212

Earlier quoted context omitted.

I simply type passwords in the answers. "What is your mother's maiden name?" - "gHk899iL@"

This is a good idea. Unfortunately if you have ever in the past (foolishly) answered these security questions honestly, you can't just now start answering them with your password, unless you keep track of which sites have your honest answers and which sites you just gave your password again.

I would put a _different_ password rather than the same password. Lots of site store security question answers in plain text for csrs to verify etc.

Re: Password Rules Are Bullshit

#213
post #25

I agree with almost everything but the he loses me towards the end: > I had a bit of a sad when I realized that we were perfectly fine with users selecting a 10 character password that was literally "aaaaaaaaaa". In my opinion, the simplest way to do this is to ensure that there are at least (x) unique characters out of (y) total characters. Isn't that exactly what you're complaining about with your arbitrary passwor…

I agree with what you have said but I think the new guidelines don't go far enough. The biggest problem is that in the balance of security and convenience, users will always opt for convenience. Only via legislation will that change, think credit card chips versus swiping. (We should have chip + PIN in my opinion.) We need to make passwords a much simpler thing to manage so that people don't create a bigger problem b…

2FA is something you know and something you have.

So fingerprint gives you part 2 and password gives you part 1.

No need for an additional MFA device.

Re: Password Rules Are Bullshit

#214
post #85

I just yesterday had to sign up for some bullshit "secure email" service to read some email from my late uncle's bank. They had all the rules described in the article, and I could not use highly secure generated passwords. I finally settled on some super weak password with one of each requirement (char, case, symbol) tacked on to the end. Sigh. To make matters worse, the email looked just like a phishing attempt. Rig…

I think I have the same bank, it also asks "what is the answer to your security question" as a security question.

At least you can put a strong generated password there!

Re: Password Rules Are Bullshit

#215

Earlier quoted context omitted.

What's even more annoying is that some sites ask for verification, but then proceed to email you stuff even if you don't click verify. Someone in Australia created an Apple ID using my email. I ignored the verification, but then I got a bunch of purchase receipts from them later. What I really wish for is a link in emails that say "I am not the intended recipient of this letter." Normal mail works like that. You can…

You better watch out, that's probably a felony depending on where you live.

I suppose there may be some sort of anti-hacking law that could be twisted to fit this case, and if the cops came to my door over it I'd definitely hire a lawyer before I said anything. I somehow doubt if I'd be charged with a felony for accessing an account that is registered under my name and email address and turning off email notifications, especially since I've tried everything else I could think of to stem the tide, including emailing support, etc.

Plus, this individual who keeps signing me up lives in Australia. I cannot imagine our system is so dysfunctional that both the United States and Australia would agree that a) this is a criminal offense, and that b) it would be worth going through the effort of extraditing me to face justice.

I mean, I haven't even received another password reset request from those websites I logged in to fix that issue, so I half imagine that person is using my email address as a plausible address for email they don't care about.

I understand what you mean, but I don't think I'm going to have to spend the rest of my life looking over my shoulder. The few personal emails I've gotten with financial details (gym membership bills, etc) I've responded letting them know about the mix-up and they've been more than happy to fix the issue. Feel free to say I told you so when I end up in a jail full of kangaroos though.

Re: Password Rules Are Bullshit

#216
post #74
post #25

I agree with almost everything but the he loses me towards the end: > I had a bit of a sad when I realized that we were perfectly fine with users selecting a 10 character password that was literally "aaaaaaaaaa". In my opinion, the simplest way to do this is to ensure that there are at least (x) unique characters out of (y) total characters. Isn't that exactly what you're complaining about with your arbitrary passwor…

Totally agree. If you annoy the user too much, they will not try to circumvent your rules, they will leave and find something else to do with their time. Also, the big question that's missing from the article is: who's the enemy? If the enemy are Russian genius hackers, then certainly very long passwords and maybe other measures are in order. But the enemy is not always remote. I just bought a new iPad and had to res…

It's also insecure to have password rules because people end up writing, printing, saving passwords in Google Docs, because they can't remember them anymore with those stupid rules.

Totally agree about the "security questions". They're just insecurity questions. Everyone knows what street I used to live on and what my previous phone numbers were.

Re: Password Rules Are Bullshit

#218
post #25

I agree with almost everything but the he loses me towards the end: > I had a bit of a sad when I realized that we were perfectly fine with users selecting a 10 character password that was literally "aaaaaaaaaa". In my opinion, the simplest way to do this is to ensure that there are at least (x) unique characters out of (y) total characters. Isn't that exactly what you're complaining about with your arbitrary passwor…

> Axei5aoc0i

I don't want to trust a bank who knows my password.

Re: Password Rules Are Bullshit

#219

Earlier quoted context omitted.

This is a good idea. Unfortunately if you have ever in the past (foolishly) answered these security questions honestly, you can't just now start answering them with your password, unless you keep track of which sites have your honest answers and which sites you just gave your password again.

That's a problem even if you answer honestly all the time. Does this website think my best friend's name is (example) Jake or Jacob? My solution is just to keep those answers in the "extra notes" section of my password manager.

Did I answer "Ste-Citée" or "Ste-Citee" or "Sainte Citée" or "Sainte-Citee" or ... oh, too late, only had two chances to answer. My account is now locked.

Re: Password Rules Are Bullshit

#220
While I've obviously encountered frustrating arbitrary password rules on various small/ancillary sites, Stackoverflow/Stackexchange is the only service I use regularly that I've hit real problems with...
Post reply on HN