Live data from Hacker News

86% of CrashCrate subscribers used passwords already leaked in other breaches

troyhunt.com

111–120 of 145 posts

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#111

Earlier quoted context omitted.

Because my password manager is faster than checking mail. Because spam. Because people change mails and may forget to let you know. Because bots scan emails and they are mostly in clear text.

> Because bots scan emails and they are mostly in clear text. If the password reset email goes through the same route then this doesn't matter. It's essentially a 'password reset' with every login. And because they are short lived you'd expect that if they had been used already that there would be no re-use possible, which would mean the attacker would have to be super fast and the victim would immediately know they…

No you would mostly use it for phishing.

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#112

Earlier quoted context omitted.

> Your password must be at least 10 character long You forgot "and may not be longer than 16 characters".

Unless they've changed it in the last couple months, TRowe Price still limits passwords to 10 characters. And this is after a recent "We've upgraded our security!" push where I had to reset everything. I've seriously considered closing my accounts over it. Edit: Yep, still as bad Password must be 6-10 characters and contain at least 2 numbers and 2 letters. Password may not contain the following special characters: s…

my bank's password has to be exactly 8 characters and is case insensitive

it's pretty insane considering it's like the most important password I have

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#113

When I feel like a security goon's arbitrary and capricious password policy is irrational and counterproductive, I make my passwords worse in the hopes that I have to someday read it to someone, or perhaps it gets spilt outin the open, and then everyone will see how forcing me to pick a password that adheres to certain characteristics solved nothing. Just wait. Someday you will see dumps of pwnt password that look li…

>> 90 day password expiration rotation schemes

I have a bank site that I have to log in to every month, but only once a month. So every 3rd time I use the site, I have to choose a new password. Very annoying.

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#114
post #82

My biggest bugbear is with the really important sites like Apple and Google who force you to type out your passwords several times a day when using their services. I really want to pick a long complex password, but not if I have to keep typing it into login screens or pop-up windows where password managers don't work. Microsoft is doing a lot of good things in this area with passwordless logins and asking for PIN cod…

Google only makes me login once per 90 days per device.

And even that I believe is simply because they don't want me forgetting the password.

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#115

Earlier quoted context omitted.

before I got into a password manager, I resorted to song lyrics, capitalizing the first character, including a number and a symbol at the start. '#1I'm picking up good vibrations', for instance.

A tad off topic, which password manager would you recommend?

It isn't awesome, but the best all around one I have seen is LastPass.

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#116
post #93
post #48

Earlier quoted context omitted.

If you ever reuse that password anywhere else, then you should care A LOT. If you go "i only reuse passwords on low-consequence sites", then I have to ask you 1) why reuse at all? and 2) are you sure? I bet that that's not true, I bet you think that's true but it turns out that your Uber password is the same as your RandomSite password. Just use a password manager. It's easier and it's safer, and you never have to th…

Yeah I do this. I also work in security. >why reuse at all? Because it's easy. There's many sites I create an account for once or twice and I never use again, mainly e-commerce. I don't care if someone logs in, at best they get an address and maybe a few card details. That's all practically public information. >are you sure? I bet that that's not true Yup, 100%. And even if a few get missed, anything super important…

I got into the habit of using a separate password for each site I use, except for the throwaway sites.

I have a method I use regardless if 2fa is an option or not.

I have a fairly secure password that I have memorized. Then for each site I pick something about it that I can remember to add on to the password.

For example if my current ebay password is: Pa$$w0rd the new one would be: Pa$$w0rdEb or EbPa$$w0rd Amazon would be: Pa$$w0rdam

That has helped a few people I know keep separate passwords for each site without having to go through a password manager. YMMV of course.

The way I look at it is if the sites DB gets dumped, at least the scripts will fail using the password on other sites, even if it's not the most secure password.

You're point about the phishing e-mails is spot on though. No amount of secure passwords will stop that

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#117

Earlier quoted context omitted.

'Security' is some kind of religion in tech circles. I don't know if it is just that risk analysis isn't part of your standard tech education, or if they think it makes them look cool to talk about always using 200 character hardware-RNG generated passphrases when ordering pizza online, or what exactly, but they're everywhere.

Seconded The usual cargo-cult thinking usually ends up with someone leaving their 1024 bit secret key under the doormat, or worrying too much about nation states hacking your routers instead of worrying about Bob clicking a suspicious link.

How many seconds have you, GP, and a couple of other commenters in this subthread devoted to thinking that maybe people who use password managers for everything find it not merely secure but also convenient?

I don't know about you but I don't like having to remember passwords. But people here can feel free to impress everyone with their memorized password they use on pizzahut.com, right up until they find out that they reused it somewhere important they totally forgot about because they don't have a convenient database of all the websites they have an account on.

Seriously, this counter-culture of being proud to have shitty passwords is the same mindset that makes antivax and climate science deniers a thing. You want to reuse shitty passwords, nobody is stopping you (I've certainly done it), but don't be proud of it and don't shit on people who care more than you.

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#118
post #63

When I feel like a security goon's arbitrary and capricious password policy is irrational and counterproductive, I make my passwords worse in the hopes that I have to someday read it to someone, or perhaps it gets spilt outin the open, and then everyone will see how forcing me to pick a password that adheres to certain characteristics solved nothing. Just wait. Someday you will see dumps of pwnt password that look li…

I completely agree. "Your password must be at least 10 character long, include 2 upper case, 2 lower case, 2 digits, 2 special characters, must be changed every 60 days and cannot be reused for the next 3 years" G0Fuc4Y@urse!f To me this is a sure way that people are gonna pick horrible and stupid passwords.

Even better if it just says "your password does not fit our requirements" :)

I was signing up for a bank account and had to make a password for my online account in the branch. Turns out my 16-character randomly generated password made the system unhappy. Tried 6 more times with newly generated passwords (character-only, alphanumeric only, alphanumeric and "#" or "$" only) and it just said the password was not acceptable. So in the end I used my probably ~15 bits of entropy super easy to crack password from when I was 10, with a few randomly generated characters on the end (because more than a few would make the system complain again).

The pervasiveness of poor UI and security design baffles me. You would've thought that one of the largest banks in the world would have a little more competency but nope.

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#119
post #63

When I feel like a security goon's arbitrary and capricious password policy is irrational and counterproductive, I make my passwords worse in the hopes that I have to someday read it to someone, or perhaps it gets spilt outin the open, and then everyone will see how forcing me to pick a password that adheres to certain characteristics solved nothing. Just wait. Someday you will see dumps of pwnt password that look li…

I completely agree. "Your password must be at least 10 character long, include 2 upper case, 2 lower case, 2 digits, 2 special characters, must be changed every 60 days and cannot be reused for the next 3 years" G0Fuc4Y@urse!f To me this is a sure way that people are gonna pick horrible and stupid passwords.

exactly -- that and write down those horrible and stupid passwords on sticky-notes and attach them to their monitor bezel or keyboard.

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#120
post #64

Earlier quoted context omitted.

To be honest, the first one that comes to mind is HN. There is zero consequence if someone was to get a hold of my credentials here — I don't care about the score and I can still recover the bookmarks.

What if the person that takes over the account posts messages that arouse the interest of authorities? Your IP addresses and other info are associated with the account.

I think this is a pseudo-problem in pretty much any country except for, perhaps, totalitarian regimes or similar. If any large body would take interest in the account seriously enough to get the associated IP, they would also automatically get the new account holder's IP and the clear correlation.
Post reply on HN