Earlier quoted context omitted.
'legit users' There isn't a day that goes by that I don't get an email intended for someone else, often including personal information, due to a mistyped email address. Whoever decided that email verification was a poor user experience needs to be hit in the head with a shovel after he digs the appropriate sized hole. If you know Catherin (PA) let her know her round trip to vegas is confirmed Carolyn's (NYC) open tab…
> Whoever decided that email verification was a poor user experience needs to be hit in the head with a shovel after he digs the appropriate sized hole. That's why you get send the verification email first , when creating the application user, and don't do anything until the email is verified. The flow should be: User: Please give me an account; my email address is jim@example.invalid Server: I have sent an email to…
Password Rules Are Bullshit
231–240 of 283 posts
Re: Password Rules Are Bullshit
#232Earlier quoted context omitted.
How generic is your email address? This has literally never happened to me (to my recollection).
I have [first-initial][last-name]@gmail.con. My last name is pretty uncommon, but there are at least a thousand of us or so in the US. I probably get a dozen emails a month to people who are not me (not counting all the ones that end up in the spam folder after I'm on a damn list). Susan. Stephen. Another Sam. So many damn S. Lastnames around. On occasion I've tracked the people down. I've forwarded their emails if t…
If we didn't have a monoculture in email providing, this would be far less of an issue.
Re: Password Rules Are Bullshit
#233Earlier quoted context omitted.
> As someone with an unusual name...and who uses a fairly unusual email for personal stuff... that's pretty different from my experiences. I've never ended up with someone else's mail at all. I think it's more likely if you use an initial in your email address. I have a fairly unusual last name, but I used my first initial to create my gmail address, so I regularly get stuff meant for a couple of other people. Busine…
> do you really want to carry them around in case you need to put your email on a form? Yes. Or my name/address/phone number. It's essentially a machine-readable address label, the email is just one part of the vCard. Do you people really not keep a book of stamps in your car? Such inconvenience!
> Do you people really not keep a book of stamps in your car?
No, why would I do that?
Re: Password Rules Are Bullshit
#234Somebody got into my bank account and attempted to steal some money. Luckily, we were able to stop it quickly and the bank had the money back in our account the same day. It was pretty upsetting so I sent a letter to them with a lot of questions about their system and eventually somebody from the inside called me. One of the questions I asked was why they limit password length. The (low) limit suggests that they were…
Re: Password Rules Are Bullshit
#235Earlier quoted context omitted.
'legit users' There isn't a day that goes by that I don't get an email intended for someone else, often including personal information, due to a mistyped email address. Whoever decided that email verification was a poor user experience needs to be hit in the head with a shovel after he digs the appropriate sized hole. If you know Catherin (PA) let her know her round trip to vegas is confirmed Carolyn's (NYC) open tab…
What's even more annoying is that some sites ask for verification, but then proceed to email you stuff even if you don't click verify. Someone in Australia created an Apple ID using my email. I ignored the verification, but then I got a bunch of purchase receipts from them later. What I really wish for is a link in emails that say "I am not the intended recipient of this letter." Normal mail works like that. You can…
I even tried calling Apple to get them to cancel the account, but they wouldn't let me because I couldn't answer any of the security questions on the account!
The guy on the phone acknowledged that of course I can't answer them, because I didn't create them, bit their policy forbids them from doing anything without the security questions...
Re: Password Rules Are Bullshit
#236Earlier quoted context omitted.
Ran into one where it demanded I choose from a drop-down list, e.g. "What was your first pet" had "dog", "cat", "hamster", "gerbil", etc. I recall the list having a scrollbar, but there was not even enough choices for eight bits worth of entropy. Oh, and they referred to these security questions as "2FA."
And what if you never had a pet? I love the ones that ask about one's favourite sports team (not everyone likes sports), or first girl (or boy) friend (not everyone has dated) or first car (not everyone has ever owned a car).
Re: Password Rules Are Bullshit
#237Earlier quoted context omitted.
Related, some of these sites you forget what you used and have to create a new password - and some of them do this horrible "You cannot re-use your four last passwords" thing which leaves you in this sort of permanent "I'm never going to remember and always have to come up with something new" loop (for sites you go to only periodically, e.g. an HR portal, let's say). But hey, nothing important lives in an HR portal,…
Employee of a university here. Not only are the password requirements annoying, unless you close the browser you aren't logged out. Clicking "logout" makes it look logged out, but the next person to use email/payroll enters their credentials and gets the prior users account. Hilarity ensues with people applying for each other's leave, emailing responses to messages that weren't for them etc. The interim response is f…
* Go to some service A.
* Get redirected to SSO and authenticate.
* SSO confirms your identity and A issues you a session token.
* You log out using your SSO.
* Go back to A where you're still logged in with your session token.
At a certain point I would not be willing to commit to maintaining lots of patches to every product we host and just tell our users to close their browser.
Re: Password Rules Are Bullshit
#238grrrrrr
Re: Password Rules Are Bullshit
#239Earlier quoted context omitted.
How generic is your email address? This has literally never happened to me (to my recollection).
I have (first initial)(mid initial)(last name) at gmail. Same as my HN id. And a very common last name! 16 months into my first job out of University I got a call from a headhunter intended for the other Chris Miller sitting 2 cubicles away from me. At my second and fourth jobs there were also other Chris Millers. And from my list of examples, most all have the same last name.
"Hi X. The £80 million for the new biomedical building is approved, please make the transfer ASAP."
It turned out I had the same unusual name as the most senior financial officer.
Re: Password Rules Are Bullshit
#240Earlier quoted context omitted.
> if I use "aaaaaaaaa" as a password on a website I know full well what I'm doing You do. A lot of users don't consider automation when it comes to people hacking their account. I've heard "Nobody will ever guess it though" a few times during my career.
I am being serious when I ask this question: does anybody brute force passwords? I posit that using a unique password for every single website is sufficient, because no one brute forces passwords. What attack vector is a password with high entropy protecting against? The only one I can think of is an unreported database leak. The attacker may be able to more easily reverse the password hash and use your account on th…
root ssh:notty 116.31.116.44 Fri Mar 10 22:27 - 22:27 (00:00)
root ssh:notty 116.31.116.44 Fri Mar 10 22:27 - 22:27 (00:00)
...
My personal server has 153,246 entries from this single IP, from 1 March until now.