Live data from Hacker News

49% of workers, forced to change passwords, reuse same one with minor change

grahamcluley.com

101–110 of 316 posts

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#102

Earlier quoted context omitted.

I agree with all of this except password managers. If you use a lot of different public computers or temporary work laptops they don’t always let you install LastPass, so I frequently ended up being unable to access my accounts.

I access my manager from my phone and type them in. I would never install my LastPass on a public computer even if they let me.

It would be really cool if you could plug your phone in and it appeared as a USB keyboard device and you could "type" the password from the password manager that way without ever giving the computer access to anything except that password.

Maybe some sort of simple USB dongle (like a yubikey) could be fed by the phone via bluetooth or nfc to do this?

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#103

Earlier quoted context omitted.

I access my manager from my phone and type them in. I would never install my LastPass on a public computer even if they let me.

It would be really cool if you could plug your phone in and it appeared as a USB keyboard device and you could "type" the password from the password manager that way without ever giving the computer access to anything except that password. Maybe some sort of simple USB dongle (like a yubikey) could be fed by the phone via bluetooth or nfc to do this?

It would be even cooler if I could open an app on my phone, point it at a QR code on screen, and not have anything else bother me

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#104
post #43

The thing I hate the most is random websites forcing you to use a password with "at least 8 characters, capital letters, numbers, .." I only care about my email account and a couple of other important websites. I want to be able to use the same simple password on other websites. So what if my account on pinterest or my local news website or some random forum is compromised... I don't care. I will either reset my pass…

If you want to feel better about those websites, Provident CU makes you pick a username with the same rules, including capitals and numbers when you register for online banking.

Someone in their IT department is the Grand High Idiot of Cargo Cult Security.

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#106

Earlier quoted context omitted.

It would be really cool if you could plug your phone in and it appeared as a USB keyboard device and you could "type" the password from the password manager that way without ever giving the computer access to anything except that password. Maybe some sort of simple USB dongle (like a yubikey) could be fed by the phone via bluetooth or nfc to do this?

It would be even cooler if I could open an app on my phone, point it at a QR code on screen, and not have anything else bother me

This is (sorta) how SQRL works.

https://www.grc.com/sqrl/sqrl.htm

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#107

The password requirements at my job are, in my opinion, insane. It has to be a specified length (an exact number of characters, no more, no less), can't contain any 3+ character words found in a dictionary, and a few other requirements like at least one capital letter and at least one number. And it has to change every three months. So yes, when I have to change my password I end up changing a single character or dig…

I've heard of banks setting a 8-character limit on password length. If my bank did that, I'd be searching for a new bank. Just just reeks of passwords being stored in plain text.

IBM legacy in action. Nobody ever got fired for buying IBM, but some of them probably should have been.

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#108
post #32

Earlier quoted context omitted.

Bruce Schneier's summarization [0] of NIST's revised recommendations: 1. Stop it with the annoying password complexity rules. They make passwords harder to remember. They increase errors because artificially complex passwords are harder to type in. And they don't help that much. It's better to allow people to use pass phrases. 2. Stop it with password expiration. That was an old idea for an old way we used computers.…

I agree with all of this except password managers. If you use a lot of different public computers or temporary work laptops they don’t always let you install LastPass, so I frequently ended up being unable to access my accounts.

LastPass (like all other good online password managers) has a web UI.

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#109
My single biggest issue is weird complexity requirements... let me simply use a relatively short sentence (15+ characters). If they limited requirement to length only + a breach check, that would be enough and encourage a sentence.

"I really like sour grapes." is easy enough to remember and has plenty of complexity... of course, it gets much harder on a mobile device, this is where passphrase managers come into play though.

Re: 49% of workers, forced to change passwords, reuse same one with minor change

#110

This should not be a surprise, as this supports the NIST's revised recommendations (from June 2017!) that passwords should not expire [0], because it actually leads to less-secure passwords for this exact reason. Furthermore, many corporate systems do not integrate well with password managers, such as when first logging in to your system in the morning. This means that the password is likely to be one of the few that…

> corporate systems do not integrate well with password managers, such as when first logging in to your system in the morning

Depends on the password manager. I use Keepass on my phone with the InputStick[0] plugin, for example, and that works great for Windows logins. Even have a macro set up so I can sign in to Windows with one tap.

[0]: http://www.inputstick.com/

Post reply on HN