Live data from Hacker News

49% of workers, forced to change passwords, reuse same one with minor change

grahamcluley.com

81–90 of 316 posts

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#81
post #75
post #43

The thing I hate the most is random websites forcing you to use a password with "at least 8 characters, capital letters, numbers, .." I only care about my email account and a couple of other important websites. I want to be able to use the same simple password on other websites. So what if my account on pinterest or my local news website or some random forum is compromised... I don't care. I will either reset my pass…

> The thing I hate the most is random websites forcing you to use a password with "at least 8 characters, capital letters, numbers, .." You can come up with a simple and easy-to-remember phrase for those. If it expresses your irritation with those rules and annoying mandatory logins, it's easier to remember. For example, FuckOff1234!

same here I have good passwords on my password manager for things that I care about a password for things I don't care that much enough to use the manager and a password for throwaway stuff

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#82
post #51
post #11

Earlier quoted context omitted.

please memorize: ZBkhTG1mchw7tr5bdKqknGGqFifuGDi7

Zaphod Beeblebrox's kite harasses Tuscon. Great, one more collapsing home. Why? 7 termites risk 5 bad days. Knight's queen kills narcs; Good Game queen. Fighting inside futons upends Greater Detroit in 7. But that's because you forced the choice on me, and I'm only willing to work so hard for a Hacker News post. Ideally, you turn it into one coherent story. If I can choose my password, and I usually can after all: Za…

How fast can you enter that password? Like, is it a reasonable time or are you basically pecking at your keys?

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#83
post #61

Earlier quoted context omitted.

I guess the point is that the 1400-strong pw manager is the antithesis of defence in depth. If you get malware'd, better that they nab a few passwords than /all/ of the passwords.

Having unique passwords for every service, all of which are stored entirely in your brain, is almost certainly more secure than a password manager. However, I'm inclined to believe this is virtually impossible, for all but a handful of exceptionally talented individuals. So if realistic options are (A) access all services via one password which is only stored in your password manager, or (B) access all services via o…

Of course there are more options than that.

Pen and paper works well for the more important stuff, while you can come up with passwords that are easier to remember for all the silly online services that demand a login but don't really matter if they get compromised.

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#84

Earlier quoted context omitted.

And yet, you're also making it impractical for them to actually use a unique password, see what the GP said.

Nothing stops them from using a unique passphrase. I am subjected to the same password requirements and use a unique passphrase every time. I see harvested passwords as a larger threat than bruteforcing, so some kind of expiry is important. Some users might use good, unique passwords, but most will not.

[deleted]

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#85
post #11

This should not be a surprise, as this supports the NIST's revised recommendations (from June 2017!) that passwords should not expire [0], because it actually leads to less-secure passwords for this exact reason. Furthermore, many corporate systems do not integrate well with password managers, such as when first logging in to your system in the morning. This means that the password is likely to be one of the few that…

please memorize: ZBkhTG1mchw7tr5bdKqknGGqFifuGDi7

> writes it down in his phone, protected by a 4 digit pin code

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#88
post #51
post #11

Earlier quoted context omitted.

please memorize: ZBkhTG1mchw7tr5bdKqknGGqFifuGDi7

Zaphod Beeblebrox's kite harasses Tuscon. Great, one more collapsing home. Why? 7 termites risk 5 bad days. Knight's queen kills narcs; Good Game queen. Fighting inside futons upends Greater Detroit in 7. But that's because you forced the choice on me, and I'm only willing to work so hard for a Hacker News post. Ideally, you turn it into one coherent story. If I can choose my password, and I usually can after all: Za…

That technique works if you're good at remembering long phrases/stories/quotes verbatim.

Not everyone has a memory works that way. I've tried mind palace style and mnemonic techniques, and I will always remember the general gist, but typically not the exact order and specific words used. Same issue with reciting quotes. I can just about remember the 7 word phrase that I use to unlock my password manager, and I still sometimes mess it up.

Similarly I can never remember the plot of films more than a few days after I watch them - though one great thing about that is you can always re-watch films like they're new. Yet simultaneously, I maintain a working memory of several programming languages/frameworks, and otherwise generally have a good semantic memory.

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#89
post #70

Of course we do. My password manager does not work for the Windows login and I need to change it every 3 months. I can remember 1 large complicate pass-sentence, but not a different one every three months.

Same here. I have a fairly complex (secure) password I use at work and they make me change it every 90 days so I just appended an "01" to it which I increment on every change.

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#90

This should not be a surprise, as this supports the NIST's revised recommendations (from June 2017!) that passwords should not expire [0], because it actually leads to less-secure passwords for this exact reason. Furthermore, many corporate systems do not integrate well with password managers, such as when first logging in to your system in the morning. This means that the password is likely to be one of the few that…

People should remember that the recommendations are part of a large security program and assume the implementation of others that are not so straightforward. Multi-factor auth and resistance to offline attacks on a stolen database or MITM'd creds in an outdated Windows environment tend to be big technical pain points. Most companies, especially outside of tech, aren't in a position to remove password expiration yet.
Post reply on HN