Live data from Hacker News

49% of workers, forced to change passwords, reuse same one with minor change

grahamcluley.com

91–100 of 316 posts

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#92

Earlier quoted context omitted.

I agree with all of this except password managers. If you use a lot of different public computers or temporary work laptops they don’t always let you install LastPass, so I frequently ended up being unable to access my accounts.

I access my manager from my phone and type them in. I would never install my LastPass on a public computer even if they let me.

They used to have a mobile page you could login to. It was really plain but it did what it did best: provide an easy and clean way to access your passwords when you are somewhere. It was something like https://lastpass.com/mobile ...

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#93
From Microsoft in May 2019 (https://blogs.technet.microsoft.com/secguide/2019/05/23/secu...) talking about how their new policy is not to recommend regular password changes:

> When humans are forced to change their passwords, too often they’ll make a small and predictable alteration to their existing passwords, and/or forget their new passwords.

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#94
post #70

Of course we do. My password manager does not work for the Windows login and I need to change it every 3 months. I can remember 1 large complicate pass-sentence, but not a different one every three months.

For cases like these I semi-seriously suggest using a keyboard with programmable macros. Usually people laugh it off but I think it's not the worst idea. Almost no one I know would know how to find and execute a macro on my keyboard, if they even considered looking for a password there.

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#95
post #73

Earlier quoted context omitted.

If you have malware on your machine you already lose everything.

This is not true. If malware runs on your machine and there is no password manager storing 1400 passwords, the malware cannot pivot to 1400 destinations. However, if there is a password manager on the device that the malware gains access to and it would indeed store 1400 passwords in one place, then all 1400 assets are compromised at once. I think that's what the previous commenter wanted to highlight. In the end it'…

You'll presumably access those services eventually. And for the huge majority of people if they are memorizing a password for a infrequently used service means using a shitty password.

"Even though the malware has access to my email, which I presumably login to with frequency, and therefore can perform password resets for many services, I might notice it and reformat my machine before I login to some other important service" is not exactly a compelling threat model.

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#96

Earlier quoted context omitted.

I access my manager from my phone and type them in. I would never install my LastPass on a public computer even if they let me.

And then you've got your phone open, displaying your password to shoulder surfers, for as long as it takes to type in your password.

I have a hard enough time typing 4mfkD.Q.27cC8,'@eG}a4{\* , I am very much not worried about a "shoulder surfer" either seeing the cleartext password on my tiny phone screen, or watching all of those keystrokes without me noticing them.

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#97
post #51
post #11

Earlier quoted context omitted.

please memorize: ZBkhTG1mchw7tr5bdKqknGGqFifuGDi7

Zaphod Beeblebrox's kite harasses Tuscon. Great, one more collapsing home. Why? 7 termites risk 5 bad days. Knight's queen kills narcs; Good Game queen. Fighting inside futons upends Greater Detroit in 7. But that's because you forced the choice on me, and I'm only willing to work so hard for a Hacker News post. Ideally, you turn it into one coherent story. If I can choose my password, and I usually can after all: Za…

To me, there's an irony in that "Zaphod Beeblebrox's kite harasses Tuscon." is not only _more_ memorable on it's own, but is probably a _better_ password than "ZBw3hHg1tFWdhdt?Hoh2hXcrZmn"

Stop using passwords, just use a "pass sentence."

My last few passwords at my previous employer:

"Tim, bring me chicken #15" "Mary, stop looking at me!" "Nothing you can do about 2!" "The coffee here is gross."

Seriously.

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#98
post #94
post #70

Of course we do. My password manager does not work for the Windows login and I need to change it every 3 months. I can remember 1 large complicate pass-sentence, but not a different one every three months.

For cases like these I semi-seriously suggest using a keyboard with programmable macros. Usually people laugh it off but I think it's not the worst idea. Almost no one I know would know how to find and execute a macro on my keyboard, if they even considered looking for a password there.

One better: a password generator in keyboard.

You give it a master key and a short code, it derives a password from those two.

Doesn't work in organizations that don't let you bring your own custom hardware though :C

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#99

Earlier quoted context omitted.

And yet, you're also making it impractical for them to actually use a unique password, see what the GP said.

Nothing stops them from using a unique passphrase. I am subjected to the same password requirements and use a unique passphrase every time. I see harvested passwords as a larger threat than bruteforcing, so some kind of expiry is important. Some users might use good, unique passwords, but most will not.

I frequently have perfectly adequate strong passwords rejected because it doesn't have the anointed mix of special characters, or more infuriating, has ASCII printable characters that aren't accepted, like caps, digits, or symbols. The latter systems are 100% guaranteed to be storing unhashed passwords.

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#100
post #11

Earlier quoted context omitted.

please memorize: ZBkhTG1mchw7tr5bdKqknGGqFifuGDi7

> writes it down in his phone, protected by a 4 digit pin code

In fairness, if you have a good password manager on that phone, that password will be protected by not just the device's unlock PIN but the password vault's master password as well, along with potentially other layers of added protection as well (a second factor to unlock the password vault, biometric authentication to unlock the vault or the device, etc.)

But almost nobody uses a good password manager, so... yeah.

Post reply on HN