Live data from Hacker News

The Password Game

neal.fun

381–390 of 540 posts

Re: The Password Game

#382

For anyone else who was struggling to make the leap year work with all the other math: 0 is a leap year. For anyone else struggling with how to make the country name work with roman numerals or element names, you can lowercase the country name then it doesn't count as a roman numeral nor element. If your chess move is illegal, make sure you're also notating the effect of the move (Nxe6 for N captures on e6, not just…

I cycled through _so_ many hex colors and youtube videos. I found that searching the length in the youtube search bar led to plenty options. I even chose to exclude 'x' which was _so_ dumb as I had to switch my XXXV to a V and VII, making life much harder for myself. Ultimately I finally got a password with length 211, including the current time, that fit all of the rules! [spoiler] the final step has you re-type you…

Also ended up with exactly 211, maybe the easiest choice. Sad at the ending.

Other hints:

* The eyedropper is a good way to get the hex quickly.

* On Youtube search the time you need and then scroll until you load a metric ton of videos then Cmd+F for the time (e.g. 28:22) since the times are searchable text on screen.

Re: The Password Game

#384

"Congratulations! You have sucessfully chosen a password in 113 characters." This was a horrific abomination, and delightfully evil. My solution (which includes some spoilers, even though each game has somewhat different rules): https://social.joshtriplett.org/@josh/posts/AX8ypcJYS8eSFLUX...

Did you actually manage to re-type that?

Re: The Password Game

#386
post #380
post #359

Earlier quoted context omitted.

> 1. You can have multiple hardware keys or devices bound to an account as a backup of for ease of use. How does that help if someone steals your hardware key, login in with it and then puts it back. You don't even know that it was stolen and your account was messed with. With a good password you know if you tell someone. Granted people could film you typing your password, but stealing your hardware key is much easie…

If using it as a security key (with a password) you don't need to give the device anything but a tap usually. However, if you use a Yubikey or Trezor for example as a Passkey (No Password), you have to enter a pin on either (Yubikey via OS and Trezor on device) before they will fulfil the request and log you in.

> However, if you use a Yubikey or Trezor for example as a Passkey (No Password), you have to enter a pin on either (Yubikey via OS and Trezor on device) before they will fulfil the request and log you in.

Personally I consider a PIN, password or passphrase the same thing, just different rules. It is security based on knowledge. So If I enter a PIN somewhere it is still a password. IMO this is fine.

Re: The Password Game

#387

Earlier quoted context omitted.

I'll copy a comment I made earlier: "00:00 / : " youtube Google that, including the quotes, replace the minutes and seconds with your given time, then look through the results and find a URL which fits the password criteria. Every result should be a video with that duration. If it isn't, check your useragent. I noticed some weirdness with that.

Can you give an example? "replace the minute and seconds" is vague. Do you mean replace the words "minute" and "second"? Or just the numbers? Do you remove the brackets too?

Seems pretty self-explanatory:

> site:youtube.com "00:00 / 16:18"

Or you know you could just try to work it out for yourself.

Re: The Password Game

#388
post #376
post #359

Earlier quoted context omitted.

> 1. You can have multiple hardware keys or devices bound to an account as a backup of for ease of use. How does that help if someone steals your hardware key, login in with it and then puts it back. You don't even know that it was stolen and your account was messed with. With a good password you know if you tell someone. Granted people could film you typing your password, but stealing your hardware key is much easie…

1. If they have the access to steal your hardware key then they also probably have access to replace your usb charging cable with a malicious one, or install a keylogger on your system, or place a microphone or camera near you for acoustic or optical keylogging. All ways your password could be stolen without you knowing. If your yubikey is stolen at least you find out fast and could warn your IT manager to lock you o…

> 1. If they have the access to steal your hardware key then they also probably have access to replace your usb charging cable with a malicious one, or install a keylogger on your system, or place a microphone or camera near you for acoustic or optical keylogging. All ways your password could be stolen without you knowing. If your yubikey is stolen at least you find out fast and could warn your IT manager to lock you out. Still, 99.999% of all threats are online, and for the rare few that have physical theft of keys in their threat model, then you have the option to set a pin on your yubikey with a 3 try lockout. Or you can use touchid, or another platform authenticator built into your laptop. If they can steal your unlocked laptop, then neither passwords or passkeys are going to help so this is moot.

You are jumping around various attack scenarios to make your point. If your child steals your hardware token to shop on amazon and then put it back afterwards is a different and much more likely scenario then some targeted attack by some hacker that is prepared and breaks into your home...

Most online threads are about social engineering, where the person that is attacked actually cooperates with the attacker, AFAIK there is no safeguard against that, other than not trusting people with their own stuff.

I would worry more about someone stealing a locked laptop. If there is no password (or other kind of knowleged based protection), then they have everything they need to unlock it.

> Web passwords should go die in the same fire as SMS 2FA.

So since you limited your argument now to just Web passwords. Does that mean you agree with me that you don't think there is a good solution to replace passwords for encryption or local authentication that works offline and doesn't move the trust away from the user?

Re: The Password Game

#389
post #12

I'm stuck at "iatetomatoesyesterday0265Z#521juneVpepsiVIIxngxcaboutAg[moon emojis]italy2020Bf7+" trying to solve the chess notation puzzle. I especially laughed at the rule "must include today's Worldle" and I'm happy with my solution including every emoji for "must include the current phase of the moon as an emoji." (HackerNews doesn't seem to display emoji. My solution is to paste every moon phase emoji.) Excited t…

The worldle one I found kind of annoying because now I have to go play another game to keep going, one I don't find all that interesting.
Post reply on HN