Live data from Hacker News

86% of CrashCrate subscribers used passwords already leaked in other breaches

troyhunt.com

121–130 of 145 posts

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#121
post #93

Earlier quoted context omitted.

Yeah I do this. I also work in security. >why reuse at all? Because it's easy. There's many sites I create an account for once or twice and I never use again, mainly e-commerce. I don't care if someone logs in, at best they get an address and maybe a few card details. That's all practically public information. >are you sure? I bet that that's not true Yup, 100%. And even if a few get missed, anything super important…

I got into the habit of using a separate password for each site I use, except for the throwaway sites. I have a method I use regardless if 2fa is an option or not. I have a fairly secure password that I have memorized. Then for each site I pick something about it that I can remember to add on to the password. For example if my current ebay password is: Pa$$w0rd the new one would be: Pa$$w0rdEb or EbPa$$w0rd Amazon wo…

Exactly!! I have a scheme like this but more convoluted, low/medium/high consequence sites, different random 'main chunks' that I can remember, and a quasi-methodical per-site head/mid/tail chunk that is related to each site.

Never found any of even the main chunks in the PW lists, but I'm sometimes forced into stupid PWs by stupid rules as in above comments.

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#122

Earlier quoted context omitted.

Seconded The usual cargo-cult thinking usually ends up with someone leaving their 1024 bit secret key under the doormat, or worrying too much about nation states hacking your routers instead of worrying about Bob clicking a suspicious link.

How many seconds have you, GP, and a couple of other commenters in this subthread devoted to thinking that maybe people who use password managers for everything find it not merely secure but also convenient ? I don't know about you but I don't like having to remember passwords. But people here can feel free to impress everyone with their memorized password they use on pizzahut.com, right up until they find out that t…

I'm not talking about password managers (in this case)

You should worry about strong passwords, but the point is moot if the rest of the system has other major flaws.

See: people who have their security answer as a long hex string, and customer service doesn't check the digits.

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#123

Earlier quoted context omitted.

How many seconds have you, GP, and a couple of other commenters in this subthread devoted to thinking that maybe people who use password managers for everything find it not merely secure but also convenient ? I don't know about you but I don't like having to remember passwords. But people here can feel free to impress everyone with their memorized password they use on pizzahut.com, right up until they find out that t…

I'm not talking about password managers (in this case) You should worry about strong passwords, but the point is moot if the rest of the system has other major flaws. See: people who have their security answer as a long hex string, and customer service doesn't check the digits.

It's hard to tell what security answers are used for when you're writing it in. If it's for use with customer support, it should probably be something like "CSR IMPORTANT: DO NOT ACCEPT VAGUE ANSWERS 309c91b10edb2"

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#124

When I feel like a security goon's arbitrary and capricious password policy is irrational and counterproductive, I make my passwords worse in the hopes that I have to someday read it to someone, or perhaps it gets spilt outin the open, and then everyone will see how forcing me to pick a password that adheres to certain characteristics solved nothing. Just wait. Someday you will see dumps of pwnt password that look li…

The only appropriate password requirement is length.

A policy that requires 12 or 14 characters alone will have much better security than all these character sets, time limits, and other nonsense while only requiring 6 or 8 characters.

And these sites that limit password length to ridiculous short lengths are infuriating. Who could have possibly ever thought that was a good idea???

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#125

Earlier quoted context omitted.

Why not whitelist the cookies of sites where you're going to log right back in?

Firefox Containers work great for this!

I second Firefox Containers.. very useful feature.

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#127

Aside from the thought that a portion of these bad passwords may be for throwaway accounts, I think what we really need is a "Beyond Passwords" movement similar to the push for Let's Encrypt. I use KeePass 2.x on my laptop and it's been great for having complex passwords, but the few seconds it consumes to load it up every time just to log into a site is annoying. Worth the trade off, of course, but can't we do bette…

FIDO 2.0

It's flexible and secure, and most of the major players are onboard with the standard. I use and love KeePassXC (as everyone should at this point), but passwords have too many fundamental problems to be the future.

Yubikeys are nice, but don't fit everyone or everywhere. The FIDO standard is flexible enough so that it can use one or more of many different authentication factors, biometrics on your smart phone, secrets stored in the browser, PINs, Yubikeys, and others.

https://fidoalliance.org/about/what-is-fido/

Particularly exciting to me is W3C's recent standardization of the protocol. It's starting to take off!

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#128

When I feel like a security goon's arbitrary and capricious password policy is irrational and counterproductive, I make my passwords worse in the hopes that I have to someday read it to someone, or perhaps it gets spilt outin the open, and then everyone will see how forcing me to pick a password that adheres to certain characteristics solved nothing. Just wait. Someday you will see dumps of pwnt password that look li…

The only appropriate password requirement is length. A policy that requires 12 or 14 characters alone will have much better security than all these character sets, time limits, and other nonsense while only requiring 6 or 8 characters. And these sites that limit password length to ridiculous short lengths are infuriating. Who could have possibly ever thought that was a good idea???

Not necessarily. "aaaaaaaaaaaa", "password1234", and "pennsylvania" are all 12 characters, but they're all insecure. These might seem like stupid passwords that nobody would use, but if you enforce a minimum password length as your only requirement, then I guarantee some user is going to use something like this.

I agree that length is generally much more important than anything else - but it's not the only factor. Long passwords can be insecure too. Unfortunately it's not easy to validate what exactly what makes an insecure password, and as a result we get stupid requirements that prevent some very good passwords (e.g. diceware-generated passwords).

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#129

This riles me up so I will rant. I've given up remembering passwords for important accounts and just use the 'forgot me password' button to auth through email. If your site or service doesn't have more than 100 million users, please don't require a password for my email. Let me log in with another trusted account (Google, Twitter, etc). I miss the days of oauth2 and the flexibility of authenticating small services.

Absolutely no way.

Google and a few other massive corporations already control way to much of my life, adding control over authentication of my online accounts is simply unacceptable.

It'd be way more acceptable if it was an open standard and I could choose which trusted ID provider I wanted to use, but I've not seen it work like that so far.

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#130
post #8

Earlier quoted context omitted.

Remembering a unique one for every site is hard.

Again, password managers. You can have a "correct horse battery staple"-type password for that.

Password managers are a band-aid on a fundamentally flawed technology. They are what we have now, so (if your tech savvy) that's what you're using. But it's an absolute shame that this is where we're at.

I'm optimistic about the FIDO standard as a password replacement. Exciting things happening in that space recently!

Post reply on HN