Live data from Hacker News

Password Rules Are Bullshit

blog.codinghorror.com

231–240 of 283 posts

Re: Password Rules Are Bullshit

#231
post #223

Earlier quoted context omitted.

'legit users' There isn't a day that goes by that I don't get an email intended for someone else, often including personal information, due to a mistyped email address. Whoever decided that email verification was a poor user experience needs to be hit in the head with a shovel after he digs the appropriate sized hole. If you know Catherin (PA) let her know her round trip to vegas is confirmed Carolyn's (NYC) open tab…

> Whoever decided that email verification was a poor user experience needs to be hit in the head with a shovel after he digs the appropriate sized hole. That's why you get send the verification email first , when creating the application user, and don't do anything until the email is verified. The flow should be: User: Please give me an account; my email address is jim@example.invalid Server: I have sent an email to…

That is what I was trying to say. Apparently there is some number of designers that believe that that whole email verification process is too much friction for registering a user, so they simply opt not to do it at all.

Re: Password Rules Are Bullshit

#232
post #210

Earlier quoted context omitted.

How generic is your email address? This has literally never happened to me (to my recollection).

I have [first-initial][last-name]@gmail.con. My last name is pretty uncommon, but there are at least a thousand of us or so in the US. I probably get a dozen emails a month to people who are not me (not counting all the ones that end up in the spam folder after I'm on a damn list). Susan. Stephen. Another Sam. So many damn S. Lastnames around. On occasion I've tracked the people down. I've forwarded their emails if t…

The real problem is that you are all on the same email provider.

If we didn't have a monoculture in email providing, this would be far less of an issue.

Re: Password Rules Are Bullshit

#233
post #205

Earlier quoted context omitted.

> As someone with an unusual name...and who uses a fairly unusual email for personal stuff... that's pretty different from my experiences. I've never ended up with someone else's mail at all. I think it's more likely if you use an initial in your email address. I have a fairly unusual last name, but I used my first initial to create my gmail address, so I regularly get stuff meant for a couple of other people. Busine…

> do you really want to carry them around in case you need to put your email on a form? Yes. Or my name/address/phone number. It's essentially a machine-readable address label, the email is just one part of the vCard. Do you people really not keep a book of stamps in your car? Such inconvenience!

I could overload my pockets carrying around all kinds of special purpose labels and stickers, and track my stock of them so I don't run out....or I could carry a pen.

> Do you people really not keep a book of stamps in your car?

No, why would I do that?

Re: Password Rules Are Bullshit

#234

Somebody got into my bank account and attempted to steal some money. Luckily, we were able to stop it quickly and the bank had the money back in our account the same day. It was pretty upsetting so I sent a letter to them with a lot of questions about their system and eventually somebody from the inside called me. One of the questions I asked was why they limit password length. The (low) limit suggests that they were…

What bank? I wouldn't want to do business with them if that's how they handle security.

Re: Password Rules Are Bullshit

#235

Earlier quoted context omitted.

'legit users' There isn't a day that goes by that I don't get an email intended for someone else, often including personal information, due to a mistyped email address. Whoever decided that email verification was a poor user experience needs to be hit in the head with a shovel after he digs the appropriate sized hole. If you know Catherin (PA) let her know her round trip to vegas is confirmed Carolyn's (NYC) open tab…

What's even more annoying is that some sites ask for verification, but then proceed to email you stuff even if you don't click verify. Someone in Australia created an Apple ID using my email. I ignored the verification, but then I got a bunch of purchase receipts from them later. What I really wish for is a link in emails that say "I am not the intended recipient of this letter." Normal mail works like that. You can…

I had the same problem with someone signing up for an Apple ID with my email address.

I even tried calling Apple to get them to cancel the account, but they wouldn't let me because I couldn't answer any of the security questions on the account!

The guy on the phone acknowledged that of course I can't answer them, because I didn't create them, bit their policy forbids them from doing anything without the security questions...

Re: Password Rules Are Bullshit

#236
post #227

Earlier quoted context omitted.

Ran into one where it demanded I choose from a drop-down list, e.g. "What was your first pet" had "dog", "cat", "hamster", "gerbil", etc. I recall the list having a scrollbar, but there was not even enough choices for eight bits worth of entropy. Oh, and they referred to these security questions as "2FA."

And what if you never had a pet? I love the ones that ask about one's favourite sports team (not everyone likes sports), or first girl (or boy) friend (not everyone has dated) or first car (not everyone has ever owned a car).

I hated those questions as a kid because I had nothing to answer them with.

Re: Password Rules Are Bullshit

#237
post #46

Earlier quoted context omitted.

Related, some of these sites you forget what you used and have to create a new password - and some of them do this horrible "You cannot re-use your four last passwords" thing which leaves you in this sort of permanent "I'm never going to remember and always have to come up with something new" loop (for sites you go to only periodically, e.g. an HR portal, let's say). But hey, nothing important lives in an HR portal,…

Employee of a university here. Not only are the password requirements annoying, unless you close the browser you aren't logged out. Clicking "logout" makes it look logged out, but the next person to use email/payroll enters their credentials and gets the prior users account. Hilarity ensues with people applying for each other's leave, emailing responses to messages that weren't for them etc. The interim response is f…

Shibboleth user? I can't even imagine how difficult that kind of problem is when you're working with other people's software.

* Go to some service A.

* Get redirected to SSO and authenticate.

* SSO confirms your identity and A issues you a session token.

* You log out using your SSO.

* Go back to A where you're still logged in with your session token.

At a certain point I would not be willing to commit to maintaining lots of patches to every product we host and just tell our users to close their browser.

Re: Password Rules Are Bullshit

#238
Another major problem I have with password restrictions - how about you make sure your stupid password dialog is capable of accepting the passwords generated by password managers? How about you just test the 5 or 6 most common ones? I hate it when I accept the suggested password from Safari or 1password and the stupid site won't accept it because it used the wrong kind of special character, or didn't include enough capital letters, or worst of all - it's too long.

grrrrrr

Re: Password Rules Are Bullshit

#239

Earlier quoted context omitted.

How generic is your email address? This has literally never happened to me (to my recollection).

I have (first initial)(mid initial)(last name) at gmail. Same as my HN id. And a very common last name! 16 months into my first job out of University I got a call from a headhunter intended for the other Chris Miller sitting 2 cubicles away from me. At my second and fourth jobs there were also other Chris Millers. And from my list of examples, most all have the same last name.

4 days into university, the first time I logged in to the email account, I had several messages waiting for me, all intended for the same person, the best of which was:

"Hi X. The £80 million for the new biomedical building is approved, please make the transfer ASAP."

It turned out I had the same unusual name as the most senior financial officer.

Re: Password Rules Are Bullshit

#240
post #49
post #38

Earlier quoted context omitted.

> if I use "aaaaaaaaa" as a password on a website I know full well what I'm doing You do. A lot of users don't consider automation when it comes to people hacking their account. I've heard "Nobody will ever guess it though" a few times during my career.

I am being serious when I ask this question: does anybody brute force passwords? I posit that using a unique password for every single website is sufficient, because no one brute forces passwords. What attack vector is a password with high entropy protecting against? The only one I can think of is an unreported database leak. The attacker may be able to more easily reverse the password hash and use your account on th…

If you have a server running SSH, you can try the "lastb" command, which shows failed logins. Or, look in the logfile, often /var/log/secure or similar.

  root     ssh:notty    116.31.116.44    Fri Mar 10 22:27 - 22:27  (00:00)    
  root     ssh:notty    116.31.116.44    Fri Mar 10 22:27 - 22:27  (00:00)    
  ...
My personal server has 153,246 entries from this single IP, from 1 March until now.
Post reply on HN