Live data from Hacker News

I Know What Your Password Was Last Summer

labs.lares.com

1–10 of 103 posts

Re: I Know What Your Password Was Last Summer

#5
Not mentioned in the article, but I bet seasonal/time-related passwords are due to password rotation policies. I work for a company too slow or stupid to have understood how counterproductive such policy is, and all my passwords are an update of the former. Because we humans cannot remember multiple strong passwords.

Re: I Know What Your Password Was Last Summer

#7
Love the recommendation for diceware style passwords.

You can easily remember 4 to 6 random words. You really will be surprised how quickly it is to memorize and type after a day or two. Mixing them up with what separator (if any) that you use, and if you number/special character substitute that adds dozens of possible permutations on a single password. And just using 4-letter words (over 100,000 in the English language) leads to a 100 quintillion possible passwords without any separator or character substitutions.

The next requirement should be no arbitrary changes to passwords. End users should be able to pick a strong 16 character password (based on uniqueness and the other password strength tools they recommend in the article) and only change it if they forgot it or a breach of their account is suspected.

Re: I Know What Your Password Was Last Summer

#8
post #6

I always wonder why employers don't just set passwords for their users and only give them the option to randomize them. Seems like an ideal solution, if using passwords is a requirement.

Maybe it would be fine if it was random 4 words like in the XKCD, but otherwise it would cause people to plaster sticky notes everywhere and hardcode it in their computers, no?

Re: I Know What Your Password Was Last Summer

#9

I crack alot of hashes, people pick really bad passwords. Ive had tools running on raspberry pi's crack client passwords in meetings with them... in minutes...

Is this a sales shtick for security services of some sort that you do to your clients in meetings?

Re: I Know What Your Password Was Last Summer

#10
post #5

Not mentioned in the article, but I bet seasonal/time-related passwords are due to password rotation policies. I work for a company too slow or stupid to have understood how counterproductive such policy is, and all my passwords are an update of the former. Because we humans cannot remember multiple strong passwords.

All of my Bank passwords are variations of Swear Words!
Post reply on HN