Live data from Hacker News

86% of CrashCrate subscribers used passwords already leaked in other breaches

troyhunt.com

101–110 of 145 posts

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#101
post #11
post #3

The truth is the password is just another failed security concept- because those that work, cant be remembered by the users. So ones security researches terrible, is a neurologists reasonable. The actually embarrassing part is that after years of research- we still do not have a alternative.

How about a password manager? Or even better: Some kind of hardware token and a good standard that goes with it?

Hardware token seems like the obvious solution. As soon as I'm no longer a student and can afford to spend money again, my first purchase will be one.

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#102

This riles me up so I will rant. I've given up remembering passwords for important accounts and just use the 'forgot me password' button to auth through email. If your site or service doesn't have more than 100 million users, please don't require a password for my email. Let me log in with another trusted account (Google, Twitter, etc). I miss the days of oauth2 and the flexibility of authenticating small services.

No thanks, it’s far better to handle your own user authentication and not depend on third parties.

Exactly... What other data am I giving them access to by signing up with an account that's closely linked to my IRL identity?

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#103
post #63

When I feel like a security goon's arbitrary and capricious password policy is irrational and counterproductive, I make my passwords worse in the hopes that I have to someday read it to someone, or perhaps it gets spilt outin the open, and then everyone will see how forcing me to pick a password that adheres to certain characteristics solved nothing. Just wait. Someday you will see dumps of pwnt password that look li…

I completely agree. "Your password must be at least 10 character long, include 2 upper case, 2 lower case, 2 digits, 2 special characters, must be changed every 60 days and cannot be reused for the next 3 years" G0Fuc4Y@urse!f To me this is a sure way that people are gonna pick horrible and stupid passwords.

> Your password must be at least 10 character long

You forgot "and may not be longer than 16 characters".

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#104
post #62

At bare minimum websites should use 2FA - a simple TOTP on any smartphone will do wonders. But, the issue is that 86% of all websites offer so little value that 86% of people would just not bother using the site if they had to do the 2FA dance each time. That is the fundamental problem here - not people reusing passwords, or password policies that break when encountering my password manager. It's not surprising peopl…

Please not. I don't want to use a 2FA for every crappy website with a login, nor do I have my phone with me all the time. (optional is fine of course)

The point i am making is that why are you using those crappy websites.

I am thinking of a mars bar right now - it's utterly fucking pointless for me - i'm fat enough as it is and it has no nutritional value. so anything that increases the height of the bar to me buying one is fine by my slow thinking rational self. Sugar taxes, backroom, top shelf mars bar vendors are my bag baby.

Just say no.

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#105

Earlier quoted context omitted.

I'm not sure what you are saying ... should I memorize dozens of passwords like WCLfx(edI%uHgjWM6RuEeC6Qh for the services I use or should I strap on getting those dozens of services to use a perfect SSO service that doesn't leak privacy and is perfectly secure and doesn't exist yet?

I'm saying all solutions are a compromise. (And you do need to memorize your password manager password - and your main email account password as well) Also a lot of leaked passwords were strong, they just got compromised because someone didn't know about 70's password security basics. Should we just never use any leaked password ever again? (Note I'm not saying: with the same login - or any of the "top 100") Should w…

But why is it a crutch for me to use a password manager? What's my non-crutch alternative?

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#106

When I feel like a security goon's arbitrary and capricious password policy is irrational and counterproductive, I make my passwords worse in the hopes that I have to someday read it to someone, or perhaps it gets spilt outin the open, and then everyone will see how forcing me to pick a password that adheres to certain characteristics solved nothing. Just wait. Someday you will see dumps of pwnt password that look li…

Such a rebel. Remember that at the end of the road it’s your identity your password protects.

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#107
post #63

Earlier quoted context omitted.

I completely agree. "Your password must be at least 10 character long, include 2 upper case, 2 lower case, 2 digits, 2 special characters, must be changed every 60 days and cannot be reused for the next 3 years" G0Fuc4Y@urse!f To me this is a sure way that people are gonna pick horrible and stupid passwords.

> Your password must be at least 10 character long You forgot "and may not be longer than 16 characters".

you just know they are storing it in a plaintext VARCHAR(16) column and not hashing it in any way ....

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#108
post #63

Earlier quoted context omitted.

I completely agree. "Your password must be at least 10 character long, include 2 upper case, 2 lower case, 2 digits, 2 special characters, must be changed every 60 days and cannot be reused for the next 3 years" G0Fuc4Y@urse!f To me this is a sure way that people are gonna pick horrible and stupid passwords.

> Your password must be at least 10 character long You forgot "and may not be longer than 16 characters".

HRBlock does this.

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#109

When I feel like a security goon's arbitrary and capricious password policy is irrational and counterproductive, I make my passwords worse in the hopes that I have to someday read it to someone, or perhaps it gets spilt outin the open, and then everyone will see how forcing me to pick a password that adheres to certain characteristics solved nothing. Just wait. Someday you will see dumps of pwnt password that look li…

Such a rebel. Remember that at the end of the road it’s your identity your password protects.

> your 90 day password expiration rotation schemes

Those scenarios are almost always a bad employer policy, in which case it's their data the password is protecting.

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#110
post #63

Earlier quoted context omitted.

I completely agree. "Your password must be at least 10 character long, include 2 upper case, 2 lower case, 2 digits, 2 special characters, must be changed every 60 days and cannot be reused for the next 3 years" G0Fuc4Y@urse!f To me this is a sure way that people are gonna pick horrible and stupid passwords.

> Your password must be at least 10 character long You forgot "and may not be longer than 16 characters".

Unless they've changed it in the last couple months, TRowe Price still limits passwords to 10 characters. And this is after a recent "We've upgraded our security!" push where I had to reset everything.

I've seriously considered closing my accounts over it.

Edit: Yep, still as bad

Password must be 6-10 characters and contain at least 2 numbers and 2 letters. Password may not contain the following special characters: space , + " % & ' ; = ^ or curly braces.

Post reply on HN