Live data from Hacker News

49% of workers, forced to change passwords, reuse same one with minor change

grahamcluley.com

11–20 of 316 posts

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#11

This should not be a surprise, as this supports the NIST's revised recommendations (from June 2017!) that passwords should not expire [0], because it actually leads to less-secure passwords for this exact reason. Furthermore, many corporate systems do not integrate well with password managers, such as when first logging in to your system in the morning. This means that the password is likely to be one of the few that…

please memorize: ZBkhTG1mchw7tr5bdKqknGGqFifuGDi7

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#13
The password requirements at my job are, in my opinion, insane. It has to be a specified length (an exact number of characters, no more, no less), can't contain any 3+ character words found in a dictionary, and a few other requirements like at least one capital letter and at least one number. And it has to change every three months. So yes, when I have to change my password I end up changing a single character or digit and calling it a day.

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#14
post #12

> I have over 1400 passwords, stored securely in a password manager. Is the password manager not a single point of failure in this model?

Yes but you can protect your password manager with one incredibly secure password. For example, 20 characters.

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#15
post #11

This should not be a surprise, as this supports the NIST's revised recommendations (from June 2017!) that passwords should not expire [0], because it actually leads to less-secure passwords for this exact reason. Furthermore, many corporate systems do not integrate well with password managers, such as when first logging in to your system in the morning. This means that the password is likely to be one of the few that…

please memorize: ZBkhTG1mchw7tr5bdKqknGGqFifuGDi7

Sorry, I've already been asked to memorize a 32-character string, so the slot has been filled. Coincidentally, it also starts with Z.

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#16

The company I work for requires a password change every 60 days and a history of 9 passwords. Every other password I have in my 1Password so its ultra strong and secure (I use a 5 word passphrase). For my login password I just change the last digit in a loop between 0 and 9.

Pro tip: With a history of 9 passwords, change your password 10 times every time you change it until you loop back to the original. That way you can use the same password indefinitely.

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#17
Yes and sites that force such changes deserve to get shit passwords, get hacked, and go the fuck out of business. If they are too stupid to understand security, they shouldn't run a website. That includes companies like Microsoft and Amazon that force people to change pw through systems that generally don't work, fail randomly, and have different criteria for what constitutes a good pw (depending which m$ server you get, it'll allow proper long passwords or not). If people are using pw managers changing pw is never necessary. If they are not it's useless. Either way, it's a nuisance that exists only because of idiots implementing stupid shit they are too dumb to understand and forcing the rest of us to jump through their dumb rituals to get LESS security than if they didn't do any of this stupidity in the first place!

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#18
post #11

This should not be a surprise, as this supports the NIST's revised recommendations (from June 2017!) that passwords should not expire [0], because it actually leads to less-secure passwords for this exact reason. Furthermore, many corporate systems do not integrate well with password managers, such as when first logging in to your system in the morning. This means that the password is likely to be one of the few that…

please memorize: ZBkhTG1mchw7tr5bdKqknGGqFifuGDi7

It's not just memorizing it, it's typing it every single time for every transaction that you want to do, if the administrators require it. The recommendation on one system I use is to force ssh and auth with username/pw for every git transaction. Because Security!

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#19
post #11

Earlier quoted context omitted.

please memorize: ZBkhTG1mchw7tr5bdKqknGGqFifuGDi7

Sorry, I've already been asked to memorize a 32-character string, so the slot has been filled. Coincidentally, it also starts with Z.

Joke's on you! You just cut my brute force attack time in half! Only 1 billion years left!
Post reply on HN