Live data from Hacker News

Password Rules

portal.cs.oag.state.tx.us

131–140 of 157 posts

Re: Password Rules

#131
post #88

Earlier quoted context omitted.

We've moved on to a fictitious setup. I was so disgusted with my bank and their password policies and authentication measures. They too restrict to 8 characters, but they happen to also offer a SecurID token. This token can be used in conjunction with the initial authentication. I would happily switch to any bank where I can know my data is secure. How do we trust them?

I have a student loan that is limited to 8 character passwords. Thing is, when you go to set your password the first time it will happily take the password and use it, good luck getting in though because the next time you go to enter your password the web form truncates it for you (using JavaScript upon submitting)! Then when you go to reset your password they keep telling you that your password doesn't meet the requ…

> And unfortunately I can't leave them because it is a loan and not just a checking account.

You may be able to refinance the loan through another bank, which would pay off this one and let you go with someone more reasonable.

Re: Password Rules

#132

Earlier quoted context omitted.

Ashamed to admit but I used to "hack" my classmates (girls) hotmail accounts like that when I was young. I tried to recover their password and if I didn't know the answer to their security question (I often did) I just asked... I was curious if they write something about me in their emails, never did...

I could be wrong but I think you're admitting to a felony or multiple felonies.

Part of the problem is thinking that laws are an effective solution.

Re: Password Rules

#133
post #50
post #7

If you had to create a list(or non-list) of requirements a password must pass what would it be? (Ex. Case sensitivity, length, cannot be the same as username etc etc) The bare minimum with the least frustration for the user? I was very surprised by the news-piece that blizzard was using case-insensitive passwords and that got me thinking...

What if we started saying 'passphrase' instead of 'password' and made the minimum be 4 words and 18+ characters. It wouldn't be overwhelming to new users if they had examples of what a memorable passphrase is. You'd likely need to disallow specifically using the example passphrase but other than that, I'd be curious to see how well non-technical users respond to an interface asking them for a phrase.

We also need to get rid of the stupid habit of blanking out the password on the screen as it's typed, which imposes a time penalty exponential in the password length, or at least make it optional and disabled by default.

Re: Password Rules

#134

Earlier quoted context omitted.

Ashamed to admit but I used to "hack" my classmates (girls) hotmail accounts like that when I was young. I tried to recover their password and if I didn't know the answer to their security question (I often did) I just asked... I was curious if they write something about me in their emails, never did...

I could be wrong but I think you're admitting to a felony or multiple felonies.

Depending on the jurisdiction, it's entirely possible that a statute of limitations makes this irrelevant (in a legal sense). Obviously you still don't want future employers etc. to find this post.

Re: Password Rules

#136
post #50

Earlier quoted context omitted.

What if we started saying 'passphrase' instead of 'password' and made the minimum be 4 words and 18+ characters. It wouldn't be overwhelming to new users if they had examples of what a memorable passphrase is. You'd likely need to disallow specifically using the example passphrase but other than that, I'd be curious to see how well non-technical users respond to an interface asking them for a phrase.

We also need to get rid of the stupid habit of blanking out the password on the screen as it's typed, which imposes a time penalty exponential in the password length, or at least make it optional and disabled by default.

Re: this. Just have an option to 'display password' on the field itself somewhere, like you get when entering your WiFi password, or passwords on your phone.

Re: GP. Attackers would just switch to brute-forcing with common phrases. Song lyrics, expressions, etc. Then your passphrase rules will change to accommodate that, and be even more confusing. "The quick brown fox jumps over the lazy dog" and other long, memorable phrases, will be as insecure as "password123".

http://arstechnica.com/business/2012/03/passphrases-only-mar...

Re: Password Rules

#137
post #4

Also: quit the "security questions" thing. I can't count the number of times I've been locked out of my account because I couldn't remember the precise answer I gave to a security question. I bought a house last month, and the biggest thorn in my side throughout all of the financial arrangements was security questions (I'm not even joking). Here's a Facebook status update I posted (I had already been complaining abou…

Plus, you should never answer security questions honestly. Your favorite pet or the street you grew up on or your mother's maiden name are all not secret information. Many of my friends and family know the answers to all of these. So, when faced with a security question, I try to pick a random (but false) security answer, which I then write down in an encrypted file. This is a terrible solution, but it feels foolish…

A long time ago I was unable to answer the security question for my AOL account. The account had been hacked and used for mass spamming. AOL would not close the account, or help me change the password (or stop the spamming) until I answered the question.

"...but the account is being used for malicious purposes." - me

"Sorry, sir but until you tell me what you named your first dog I cannot stop it." - AOL

Re: Password Rules

#138

Earlier quoted context omitted.

Plus, you should never answer security questions honestly. Your favorite pet or the street you grew up on or your mother's maiden name are all not secret information. Many of my friends and family know the answers to all of these. So, when faced with a security question, I try to pick a random (but false) security answer, which I then write down in an encrypted file. This is a terrible solution, but it feels foolish…

I typically take the classic step of choosing "What is my password?" as a custom security question.

I make up additional weird randomness (but stuff which would be hilarious but not incredibly offensive to say to a CSR) and save it in my password manager for each account.

Re: Password Rules

#139
post #4

Also: quit the "security questions" thing. I can't count the number of times I've been locked out of my account because I couldn't remember the precise answer I gave to a security question. I bought a house last month, and the biggest thorn in my side throughout all of the financial arrangements was security questions (I'm not even joking). Here's a Facebook status update I posted (I had already been complaining abou…

Plus, you should never answer security questions honestly. Your favorite pet or the street you grew up on or your mother's maiden name are all not secret information. Many of my friends and family know the answers to all of these. So, when faced with a security question, I try to pick a random (but false) security answer, which I then write down in an encrypted file. This is a terrible solution, but it feels foolish…

I don't worry too much about someone trying to know the name of my first pet (I'm pretty sure anyone who knows what my answer would be to this question is dead). I do worry that there are a bunch of other organizations that I have told that information. If someone hacks one of those they can get access to my other accounts.

One of the worst sites I saw demanded that I select my security question from a list. Sweet gosh, I have absolutely no idea which of your brain-addled security choices I selected.

Re: Password Rules

#140
post #79

I swear one day we will see. "Unfortunately time and again we have come to observe the inability of employees to follow simple rules during password creation. For example, despite our warnings, employees often create a password containing more than one consecutive non-numeral; other employees attempt to createa a password consisting only of numbers, only of letters, or an insecure mix of numbers and letters - e.g. 5:…

> The password must be exactly 8 characters long. This is probably the root cause of bad passwords. In the case of Average Joe, he is now having to choose something memorable which is 8 characters long. 'PassworD'

moreover, at 8 characters, it doesn't really matter what password they choose; 8 characters is simply too short to matter. Even 9 or 10 is a significant improvement at this level.
Post reply on HN