49% of workers, forced to change passwords, reuse same one with minor change
91–100 of 316 posts
Re: 49% of workers, forced to change passwords, reuse same one with minor change
#92Earlier quoted context omitted.
I agree with all of this except password managers. If you use a lot of different public computers or temporary work laptops they don’t always let you install LastPass, so I frequently ended up being unable to access my accounts.
I access my manager from my phone and type them in. I would never install my LastPass on a public computer even if they let me.
Re: 49% of workers, forced to change passwords, reuse same one with minor change
#93> When humans are forced to change their passwords, too often they’ll make a small and predictable alteration to their existing passwords, and/or forget their new passwords.
Re: 49% of workers, forced to change passwords, reuse same one with minor change
#94Of course we do. My password manager does not work for the Windows login and I need to change it every 3 months. I can remember 1 large complicate pass-sentence, but not a different one every three months.
Re: 49% of workers, forced to change passwords, reuse same one with minor change
#95Earlier quoted context omitted.
If you have malware on your machine you already lose everything.
This is not true. If malware runs on your machine and there is no password manager storing 1400 passwords, the malware cannot pivot to 1400 destinations. However, if there is a password manager on the device that the malware gains access to and it would indeed store 1400 passwords in one place, then all 1400 assets are compromised at once. I think that's what the previous commenter wanted to highlight. In the end it'…
"Even though the malware has access to my email, which I presumably login to with frequency, and therefore can perform password resets for many services, I might notice it and reformat my machine before I login to some other important service" is not exactly a compelling threat model.
Re: 49% of workers, forced to change passwords, reuse same one with minor change
#96Earlier quoted context omitted.
I access my manager from my phone and type them in. I would never install my LastPass on a public computer even if they let me.
And then you've got your phone open, displaying your password to shoulder surfers, for as long as it takes to type in your password.
Re: 49% of workers, forced to change passwords, reuse same one with minor change
#97Earlier quoted context omitted.
please memorize: ZBkhTG1mchw7tr5bdKqknGGqFifuGDi7
Zaphod Beeblebrox's kite harasses Tuscon. Great, one more collapsing home. Why? 7 termites risk 5 bad days. Knight's queen kills narcs; Good Game queen. Fighting inside futons upends Greater Detroit in 7. But that's because you forced the choice on me, and I'm only willing to work so hard for a Hacker News post. Ideally, you turn it into one coherent story. If I can choose my password, and I usually can after all: Za…
Stop using passwords, just use a "pass sentence."
My last few passwords at my previous employer:
"Tim, bring me chicken #15" "Mary, stop looking at me!" "Nothing you can do about 2!" "The coffee here is gross."
Seriously.
Re: 49% of workers, forced to change passwords, reuse same one with minor change
#98Of course we do. My password manager does not work for the Windows login and I need to change it every 3 months. I can remember 1 large complicate pass-sentence, but not a different one every three months.
For cases like these I semi-seriously suggest using a keyboard with programmable macros. Usually people laugh it off but I think it's not the worst idea. Almost no one I know would know how to find and execute a macro on my keyboard, if they even considered looking for a password there.
You give it a master key and a short code, it derives a password from those two.
Doesn't work in organizations that don't let you bring your own custom hardware though :C
Re: 49% of workers, forced to change passwords, reuse same one with minor change
#99Earlier quoted context omitted.
And yet, you're also making it impractical for them to actually use a unique password, see what the GP said.
Nothing stops them from using a unique passphrase. I am subjected to the same password requirements and use a unique passphrase every time. I see harvested passwords as a larger threat than bruteforcing, so some kind of expiry is important. Some users might use good, unique passwords, but most will not.
Re: 49% of workers, forced to change passwords, reuse same one with minor change
#100Earlier quoted context omitted.
please memorize: ZBkhTG1mchw7tr5bdKqknGGqFifuGDi7
> writes it down in his phone, protected by a 4 digit pin code
But almost nobody uses a good password manager, so... yeah.