Live data from Hacker News

When it comes to composition and length, passwords mostly don't matter

techcommunity.microsoft.com

81–90 of 160 posts

Re: When it comes to composition and length, passwords mostly don't matter

#81
post #52

Earlier quoted context omitted.

I was blown away when I discovered that there was no way for me to export my Google Authenticator TOTP secrets from my locked Android phone, since unlocking it wipes the disk. I guess I will not make the mistake of not immediately unlocking an Android phone again.

So what do you do? How did you get your account back?

I ran into a similar issue. I had 1100 dollars in an account secured by authenticator and did not save the recovery codes when I set it up. I had to jump through hoops to get it back, which is good.

But I didnt realize I would have to reset up every single code on authenticator on the new phone. When you have a lot of accounts it's pretty obnoxious even with recovery codes. It didnt help that google support directly told me that they would be automatically be restored on the new phone along with the rest of the settings.

Re: When it comes to composition and length, passwords mostly don't matter

#82
post #73
post #58

Earlier quoted context omitted.

My old bank used to "encrypt" your password as you typed it into the input field, on keydown it would take the character you typed and — and I'm not making this up — ROT13 it . This had the effect of making it impossible to paste anything into the input field since the script would capture your ctrl+v and replace it with the letter "i". The icing on the cake is that when I called to complain about it, the support age…

>since the script would capture your ctrl+v and replace it with the letter "i". not an issue on firefox because you can toggle the dom.event.clipboardevents.enabled to false, and sites won't be able to hijack your pastes.

My guess is if you did that and pasted "password" you would get "passworq" and then your password would be wrong according to their "encryption" method.

Re: When it comes to composition and length, passwords mostly don't matter

#83
If you are using a password manager, use the maximum possible length – there’s no usability downside if you are already cutting and pasting.

That's fine and dandy until you need to manually type it in somewhere (e.g. reading it from your phone, typing it in on another device). Has this guy ever even used a password manager? He understands how they work in theory, but in practice it's not always quite so clean. Humans will be human.

Re: When it comes to composition and length, passwords mostly don't matter

#84

Earlier quoted context omitted.

This is why you need two options. It could be a yubikey and your phone, or a yubikey and backup codes kept in a safe, or two yubikeys, one of which might belong to a trusted relative. Or if you're really worried about getting locked out, maybe three options.

And keeping a truly reliable backup is hard. Do you print out recovery codes, laminate the paper, and put them in a fire resistant home safe, or a safe deposit box?

Yes, those are good ideas. It's not that hard. You need somewhere to keep other important papers anyway.

Re: When it comes to composition and length, passwords mostly don't matter

#85
post #73
post #58

Earlier quoted context omitted.

My old bank used to "encrypt" your password as you typed it into the input field, on keydown it would take the character you typed and — and I'm not making this up — ROT13 it . This had the effect of making it impossible to paste anything into the input field since the script would capture your ctrl+v and replace it with the letter "i". The icing on the cake is that when I called to complain about it, the support age…

>since the script would capture your ctrl+v and replace it with the letter "i". not an issue on firefox because you can toggle the dom.event.clipboardevents.enabled to false, and sites won't be able to hijack your pastes.

The only problem with that is that the stupid ROT13 step wouldn't be performed so the site would reject your login attempt anyway. It was one of the dumbest design decisions I've ever seen, honestly.

Re: When it comes to composition and length, passwords mostly don't matter

#86

If you are using a password manager, use the maximum possible length – there’s no usability downside if you are already cutting and pasting. That's fine and dandy until you need to manually type it in somewhere (e.g. reading it from your phone, typing it in on another device). Has this guy ever even used a password manager? He understands how they work in theory, but in practice it's not always quite so clean. Humans…

The best is typing that 20 character mixed-case-plus-numbers-and-symbols password for Netflix into your TV app using an on screen keyboard and directional arrows...

Re: When it comes to composition and length, passwords mostly don't matter

#87

Earlier quoted context omitted.

This is why you need two options. It could be a yubikey and your phone, or a yubikey and backup codes kept in a safe, or two yubikeys, one of which might belong to a trusted relative. Or if you're really worried about getting locked out, maybe three options.

And keeping a truly reliable backup is hard. Do you print out recovery codes, laminate the paper, and put them in a fire resistant home safe, or a safe deposit box?

You don't need to laminate or fireproof as long as you promptly regenerate the key if one of the two is destroyed.

Re: When it comes to composition and length, passwords mostly don't matter

#88
post #77

Earlier quoted context omitted.

> unknowingly divulge your password What's to keep you from unknowingly divulging your MFA token's current generated code? You're right that being phished/keylogged pwns a password-only account no matter how strong the password, but MFA isn't immune to phishing/keylogging/clipboard stealing either. Yes, the generated code will only give them access for 30 seconds (or whatever the algorithm's time window), but that's…

My main gripe with MFA, is that once you have 20+ services each one with a different token, it becomes tedious to sift through them to find the right one. I'd much rather have some MFA app capable of detecting where you're logging in, and a "click to authorize" option. That wouldn't completely stop someone from being able to steal the token, but it would thwart most simple keyloggers.

1Password has that :-)

So if you auto-fill on a login page, it will place your username, password, and 2FA codegen into the site's authentication fields. It will not auto-suggest a login if you're not on the site it originated from - which is often enough to cause people to take a second look at the URL (which really helps thwart phishing).

Plus, it sends your authentication info to the browser via a secure connection to the 1Password browser extension, so (a) your credentials can't be keylogged, and (b) they never touch the clipboard, so they can't be stolen from there either.

But all of that is also true of non-MFA logins from 1Password. So again, I don't see the added benefit of MFA if you're already using 1Password with long random passwords.

Re: When it comes to composition and length, passwords mostly don't matter

#89
post #86

If you are using a password manager, use the maximum possible length – there’s no usability downside if you are already cutting and pasting. That's fine and dandy until you need to manually type it in somewhere (e.g. reading it from your phone, typing it in on another device). Has this guy ever even used a password manager? He understands how they work in theory, but in practice it's not always quite so clean. Humans…

The best is typing that 20 character mixed-case-plus-numbers-and-symbols password for Netflix into your TV app using an on screen keyboard and directional arrows...

Netflix is needlessly hard on TV. Hotstar has an amazing system where it shows a 4 letter code. You open the website on your laptop or phone and enter the code. No typing in TV.

Re: When it comes to composition and length, passwords mostly don't matter

#90
post #60

Earlier quoted context omitted.

Pretty sure you can remove sms from the 2fac process by going to: My Account > Security & Privacy > Additional Security Verification > Update Your Phone Numbers Used for Account Security And then setting the preferred method to "use verification code from app". Once you finish setting up the authenticator app you can delete your phone number from the 2fac list. At the end of that process you should be left with only…

When I uncheck Authentication phone I get a red error message: "Configure at least one phone so that if you lose the app you are not locked out of the account." If You are able to remove it, I’m wondering if there is some sort of policy or limitation our VAR is adding to our instance. edit - added quotes to the error message

Yes, same thing happens to me. I’m the first account (and the only current admin) that purchased all the licenses so I wonder if that’s why. Is your account an admin or do you have any additional privileges? It makes sense that they need at least one phone number on file but there should be a way to opt out of SMS 2FA.
Post reply on HN