Some services it's easier to just bag their authentication and use the "forgot my password" method every time like a one-time code. Especially if it a rarely used service.
49% of workers, forced to change passwords, reuse same one with minor change
41–50 of 316 posts
Re: 49% of workers, forced to change passwords, reuse same one with minor change
#42Companies should provide a password manager solution for their employees, if they care. They make us change it every 30-90 days, tell us not to write it down anywhere, and don't want us to just add '1' on the end, but expect us to memorize it. I'm not going to pony up my own money for a password manager to use at work and try to make it work there. I pay for one for my own use and it stays for personal use.
Re: 49% of workers, forced to change passwords, reuse same one with minor change
#43Re: 49% of workers, forced to change passwords, reuse same one with minor change
#44The company I work for requires a password change every 60 days and a history of 9 passwords. Every other password I have in my 1Password so its ultra strong and secure (I use a 5 word passphrase). For my login password I just change the last digit in a loop between 0 and 9.
Pro tip: With a history of 9 passwords, change your password 10 times every time you change it until you loop back to the original. That way you can use the same password indefinitely.
Re: 49% of workers, forced to change passwords, reuse same one with minor change
#45Earlier quoted context omitted.
And yet, you're also making it impractical for them to actually use a unique password, see what the GP said.
Nothing stops them from using a unique passphrase. I am subjected to the same password requirements and use a unique passphrase every time. I see harvested passwords as a larger threat than bruteforcing, so some kind of expiry is important. Some users might use good, unique passwords, but most will not.
Re: 49% of workers, forced to change passwords, reuse same one with minor change
#46The password requirements at my job are, in my opinion, insane. It has to be a specified length (an exact number of characters, no more, no less), can't contain any 3+ character words found in a dictionary, and a few other requirements like at least one capital letter and at least one number. And it has to change every three months. So yes, when I have to change my password I end up changing a single character or dig…
Re: 49% of workers, forced to change passwords, reuse same one with minor change
#47Earlier quoted context omitted.
Nothing stops them from using a unique passphrase. I am subjected to the same password requirements and use a unique passphrase every time. I see harvested passwords as a larger threat than bruteforcing, so some kind of expiry is important. Some users might use good, unique passwords, but most will not.
Are you saying NIST and Schneier are wrong about this?
I make the assumption that the longer a password exists, the more likely it's reused and compromised. I don't have insight into every password dump, but I know my users reuse passwords a lot. I think a long expiry is the best balance in my environment.
Re: 49% of workers, forced to change passwords, reuse same one with minor change
#48Earlier quoted context omitted.
Are you saying NIST and Schneier are wrong about this?
Schneier says "don't make people change their passwords unless there's indication of compromise" I make the assumption that the longer a password exists, the more likely it's reused and compromised. I don't have insight into every password dump, but I know my users reuse passwords a lot. I think a long expiry is the best balance in my environment.
Re: 49% of workers, forced to change passwords, reuse same one with minor change
#49The thing I hate the most is random websites forcing you to use a password with "at least 8 characters, capital letters, numbers, .." I only care about my email account and a couple of other important websites. I want to be able to use the same simple password on other websites. So what if my account on pinterest or my local news website or some random forum is compromised... I don't care. I will either reset my pass…
Re: 49% of workers, forced to change passwords, reuse same one with minor change
#50Wonder how many % use the password reset as an effective one-time password (unless cached) as they can't be arsed to remember the password complexity rules for every single site thwarting their simple password variations scheme.