Live data from Hacker News

I hate password rules

schneier.com

221–230 of 447 posts

Re: I hate password rules

#221

I also hate when they force you to change passwords from time to time and forbid you to set one of your previous passwords. One particular offender is russian website HeadHunter [1]. I hope such people will go to very special hell after they die. [1]: https://hh.ru

Extra fun with organizations that use single sign on. Change your pc login and now your phone has the wrong wifi credentials. Let it attempt to connect too many times and your account is disabled.

Re: I hate password rules

#222

Earlier quoted context omitted.

Wait, what? That never happened to me. How do you go and find out your password then? Trial and error?

That happened to me many years ago with Microsoft logins. They were truncating passwords to 12 characters and my generated 16-character passwords never worked. I kept resetting them over and over until I did a Google search for Microsoft password requirements and found out that they were being truncated. That was likely fixed a long time ago, but I'm still wary of increasing my Microsoft passwords past 12 characters.

FWIW I use 30 character password with recently created skype account, and relogins work.

Re: I hate password rules

#223
For the vast majority of websites password rules are unnecessary. I only care about icloud and gmail, amazon and paypal. I don’t care if my reddit account is “hacked”. Or HN. Or random webshops or whatever. I hate being forced to use strong passwords for accounts I don’t care about.

Re: I hate password rules

#224
post #214

Earlier quoted context omitted.

I'm not sure why anyone uses banks like BoA, Wells Fargo, First Niagara, etc. Fidelity is a superior experience in nearly every way - just categorically. I'm not sure if people just don't know that you can use Fidelity this way? The only downsides are no local branches, but that's hardly an issue unless you need a cashiers check. In those rare cases you can spin up an account at shitty bank, get the check, then close…

In what way? I'd be curious to understand what it is you value about them, but your post reads more like marketing than a satisfied customer story.

No fees, also a brokerage, free checks, free atm, free wires, can trivially spin up IRA, move money between accounts, etc.

Phone call support has been surprisingly good whenever I’ve needed it.

When I used standard banks they often forced me to go in at difficult hours to do basic things and it took forever. They also had lots of fees (and as suggested in the parent comment, bad software)

Re: I hate password rules

#225

Earlier quoted context omitted.

I have a pretty complex financial situation, but Fidelity can just do all of it more easily than retail banks. Is there something banks like BoA do better that I'm missing? When I've asked people I know this I haven't gotten any good answers. I'm genuinely asking. My impression is that BoA, Wells Fargo, etc. mostly take advantage of customers that don't know better options exist.

Your impression may come from the fact that many people don't talk openly about their finances to random people on the internet. For me, Fidelity is a non-starter, for reasons that are none of your business. It's nice that you like Fidelity. But it's a good idea to recognize that your finances and life situation are unique to you.

Cool - so a non-answer and condescending dismissal of genuine questions.

Lots of people talk about finances online. See r/personalfinance or r/financialindependence. It’s a good way to learn.

Re: I hate password rules

#226
post #215

Earlier quoted context omitted.

That heavily depends on where you travel. Even here in Southern California there are populated areas with little to no mobile internet service (like Big Bear Lake, Anza Borrego, or Joshua Tree areas for example)

And they still have internet available to travelers?

I've had wifi at the hotel/motel/lodge but no cell service before.

Re: I hate password rules

#227
post #223

For the vast majority of websites password rules are unnecessary. I only care about icloud and gmail, amazon and paypal. I don’t care if my reddit account is “hacked”. Or HN. Or random webshops or whatever. I hate being forced to use strong passwords for accounts I don’t care about.

What cannot be ignored is the fact that many people will attempt to use the same password for multiple sites if given the chance.

Furthermore, some of those shops may contain identifiable information which could be problematic.

Personally, i take a slightly different approach: i don't care about almost any of my passwords... because they're randomly generated!

KeePass gives you very nice choices in regards to this, when i write down a new account into the password protected DB for a site that I'm about to use, it allows me to both generate a random password for it, as well as specify additional generation rules if needed (e.g. longer or shorter).

That way every password is unique and reasonably secure. In combination with Nextcloud and regular backups to another HDD (and manual ones to SD cards) the password safe is also persisted across my own devices and other mediums, whilst having an even longer password of its own, the only one that i need to memorize (and write down on a piece of paper that i could optionally give to someone I trust, since i once forgot my phone's lock screen pattern years ago).

Here's more info about KeePass: https://keepass.info/

This, when coupled with separate e-mail accounts (e.g. one for professional matters, a few for increasingly more spammy or throwaway purposes) and something like uBlock Origin and a VPN does make my online browsing experience a bit more tolerable and secure.

Re: I hate password rules

#228

Earlier quoted context omitted.

I guess you assume that everyone protects their stored hashes.

Not really. Even if you're worried about that, (36 alphanumeric + 10 symbols)^10 is roughly 4E16. Even at 2B checks/second/CPU (which is incredibly generous if the web developer has any competence) that's around 10M CPU-seconds, i.e. 115 CPU-days. For cracking one single password . An ASIC will speed it up, but again, remember this is one single password, and it can be an overestimate by like a factor of > 1 million…

If you don't let users use their preferred password structure, they'll have to use a shitty password like hunter2, letmein or dragon. Those can be recovered with a few attempts, even online. If you really want a 10 character password, you can hash the user's password, then imagine the first 10 bytes of the hash are the user's password, then do whatever you want with them.

Re: I hate password rules

#229
post #199

I had a 16 character password which I used in an PC online-banking application. After an update the password was unable to unlock the database. So I started creating new databases with different passwords to see what was going on, and it turned out that all passwords longer than 10 characters were failing. So I truncated my old password to 10 characters and then it worked. No hint, no nothing in the release notes.

yikes? that means they knew your password therefore able to truncate it to 10 characters?!

I assume it was like iso1631 commented, that before the upgrade they truncated it before hashing it. In any case, using a password (=encrypting database) was optional, so my reaction to this experience was to remove the password and move the entire application into a VeraCrypt container.

Re: I hate password rules

#230

Earlier quoted context omitted.

Your impression may come from the fact that many people don't talk openly about their finances to random people on the internet. For me, Fidelity is a non-starter, for reasons that are none of your business. It's nice that you like Fidelity. But it's a good idea to recognize that your finances and life situation are unique to you.

Cool - so a non-answer and condescending dismissal of genuine questions. Lots of people talk about finances online. See r/personalfinance or r/financialindependence. It’s a good way to learn.

I am not "lots of people." I have no interest in being "lots of people," or in proving myself to strangers on the internet.

I cannot convey 50 years of my financial life, experience, and history into what fits in an internet post. Anyone who can probably has a very narrow view of finance. I can say that I know how to manage my finances, and my accountant agrees with my methods and track record.

But if you think Reddit is the route to financial literacy, I can understand why you don't understand.

Post reply on HN