Live data from Hacker News

49% of workers, forced to change passwords, reuse same one with minor change

grahamcluley.com

41–50 of 316 posts

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#41
Nothing like asinine password requirements, with frequent rotations. Especially if it has absurdly low login failure counts before the account is locked and requires manual intervention.

Some services it's easier to just bag their authentication and use the "forgot my password" method every time like a one-time code. Especially if it a rarely used service.

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#42
post #8

Companies should provide a password manager solution for their employees, if they care. They make us change it every 30-90 days, tell us not to write it down anywhere, and don't want us to just add '1' on the end, but expect us to memorize it. I'm not going to pony up my own money for a password manager to use at work and try to make it work there. I pay for one for my own use and it stays for personal use.

I still need a password to get into a machine to use it and another password to open it.

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#43
The thing I hate the most is random websites forcing you to use a password with "at least 8 characters, capital letters, numbers, .." I only care about my email account and a couple of other important websites. I want to be able to use the same simple password on other websites. So what if my account on pinterest or my local news website or some random forum is compromised... I don't care. I will either reset my password or make a new account.

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#44
post #16

The company I work for requires a password change every 60 days and a history of 9 passwords. Every other password I have in my 1Password so its ultra strong and secure (I use a 5 word passphrase). For my login password I just change the last digit in a loop between 0 and 9.

Pro tip: With a history of 9 passwords, change your password 10 times every time you change it until you loop back to the original. That way you can use the same password indefinitely.

Great idea.

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#45

Earlier quoted context omitted.

And yet, you're also making it impractical for them to actually use a unique password, see what the GP said.

Nothing stops them from using a unique passphrase. I am subjected to the same password requirements and use a unique passphrase every time. I see harvested passwords as a larger threat than bruteforcing, so some kind of expiry is important. Some users might use good, unique passwords, but most will not.

Are you saying NIST and Schneier are wrong about this?

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#46

The password requirements at my job are, in my opinion, insane. It has to be a specified length (an exact number of characters, no more, no less), can't contain any 3+ character words found in a dictionary, and a few other requirements like at least one capital letter and at least one number. And it has to change every three months. So yes, when I have to change my password I end up changing a single character or dig…

When a place requires a specific number of characters, that sets off all kinds of alarms in my head. It makes me think they are storing the password rather than a hash derived from the password.

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#47

Earlier quoted context omitted.

Nothing stops them from using a unique passphrase. I am subjected to the same password requirements and use a unique passphrase every time. I see harvested passwords as a larger threat than bruteforcing, so some kind of expiry is important. Some users might use good, unique passwords, but most will not.

Are you saying NIST and Schneier are wrong about this?

Schneier says "don't make people change their passwords unless there's indication of compromise"

I make the assumption that the longer a password exists, the more likely it's reused and compromised. I don't have insight into every password dump, but I know my users reuse passwords a lot. I think a long expiry is the best balance in my environment.

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#48

Earlier quoted context omitted.

Are you saying NIST and Schneier are wrong about this?

Schneier says "don't make people change their passwords unless there's indication of compromise" I make the assumption that the longer a password exists, the more likely it's reused and compromised. I don't have insight into every password dump, but I know my users reuse passwords a lot. I think a long expiry is the best balance in my environment.

That’s not an indication of compromise: just you increasing the odds of people creating predictable passwords. If you’re concerned about dumps, setup one of the services which checks against HIBP for known-leaked passwords and then put all of your effort into MFA (especially FIDO) because that will stop the kind of attacks which are common in this century: immediate use of compromised credentials, high-skill phishing, etc.

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#49
post #43

The thing I hate the most is random websites forcing you to use a password with "at least 8 characters, capital letters, numbers, .." I only care about my email account and a couple of other important websites. I want to be able to use the same simple password on other websites. So what if my account on pinterest or my local news website or some random forum is compromised... I don't care. I will either reset my pass…

Until recently my HN password was all zeroes. It was accepted. That's fine. I don't care too much if I lose my account.

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#50

Wonder how many % use the password reset as an effective one-time password (unless cached) as they can't be arsed to remember the password complexity rules for every single site thwarting their simple password variations scheme.

Funny you mentioned this. A friend's girlfriend revealed that that's how she uses Twitter the other day. I'd imagine it's more common than we think.
Post reply on HN