Live data from Hacker News

I hate password rules

schneier.com

341–350 of 447 posts

Re: I hate password rules

#341

> I Hate Password Rules I hate passwords altogether. In this day and age, nearly all instances of password usage can be replaced by public key cryptography for a vastly improved user experience. And, of course, for a net gain in security.

> for a vastly improved user experience.

Assuming for a moment that you live in the US, do you count Fifth Amendment issues into that experience?

Re: I hate password rules

#342

Earlier quoted context omitted.

I spent half a year being charged monthly by Microsoft because Google considers my email address the same whether or not it has a period in it but Microsoft had somehow split my account into two based on that difference.

I'm missing something, why would they charge you monthly for that?

Xbox Live Gold. I'd call, give them my account details, and the rep would tell me it was canceled. Three months later, another bill. Called my bank and had my card replaced, three months later somehow again another bill on my new card. After that I figured out what was going on and managed to cancel the account. I was a teenager at the time.

Re: I hate password rules

#343

Earlier quoted context omitted.

This level of negligence should be criminal.

The software industry is full of should-be-criminal forms of negligence. Things are already horrendously bad. Basically every American's identity could stolen at this point. If any nation state or other actor decided to operationalize any of the big leaks -- eg OPM or EquiFax -- the ramifications would be catastrophic. Imagine millions of people losing their retirement accounts and all their savings. Even if you coul…

I really like that term “Cyber 9/11”. Is that something you made up or is that a term people use describing a bad attack?

Re: I hate password rules

#344
If I have an alphabet of size x and a password of length n there are x^n possibilities. What results in a larger set -- adding 1 more character to the alphabet or adding one to the length; i.e. which is bigger (x + 1)^n or x^(n+1)?

Re: I hate password rules

#345
post #242

A few years back, not too long ago, I started working on a new contract assignment at a medium size aerospace manufacturer. I show up and check in with IT department. The system administrator shows me to my desk, and hands me a post it note with my password. Well pass phrase is more like it. It was something like “sliding down the tall building”. I was quite impressed that they encouraged the use of long pass phrases…

Wow I know that password expiration is on its way out [1] but this is crazy.

[1] - https://www.sans.org/blog/time-for-password-expiration-to-di...

Re: I hate password rules

#346

Earlier quoted context omitted.

The software industry is full of should-be-criminal forms of negligence. Things are already horrendously bad. Basically every American's identity could stolen at this point. If any nation state or other actor decided to operationalize any of the big leaks -- eg OPM or EquiFax -- the ramifications would be catastrophic. Imagine millions of people losing their retirement accounts and all their savings. Even if you coul…

Eh I think you went into hyperbolic assertations here. Might want to walk it back. It's bad but it's not as bad as you say.

Suppose NK or some non-state actor has access to EquiFax or OPM data. Or just a conglomeration of various other data leaks, some of which are probably still unknown or at least unannounced. Suppose that actor launched a plan with trivial lead-time and resources -- say, 1-3 years with 10-50 trusted primaries and however many in-the-dark "contractors".

Do you really think the result wouldn't be turmoil for at least weeks, if not months, and take a year+ to unwind? Serious question. If so: please explain.

Re: I hate password rules

#347

NIST best practice recommendations state: * Require more than 8 characters * Don't require special characters * Don't force the user to reset their password * Do check for compromised passwords * Require MFA * ... All very sensible. https://auth0.com/blog/dont-pass-on-the-new-nist-password-gu...

It's also interesting because NIST doesn't generally follow these rules, since they don't use passwords (at least for most things).

Re: I hate password rules

#348
post #289

Earlier quoted context omitted.

The software industry is full of should-be-criminal forms of negligence. Things are already horrendously bad. Basically every American's identity could stolen at this point. If any nation state or other actor decided to operationalize any of the big leaks -- eg OPM or EquiFax -- the ramifications would be catastrophic. Imagine millions of people losing their retirement accounts and all their savings. Even if you coul…

So you’re saying that is a gigantic target for China and Russia to go after lol. It would mean some change for the which might not be bad but that’s kinda like arguing for terrorism, which would be illegal and actually have enforcement behind it.

No, it's far too large and undivisive a target for China or Russia. They're both too smart for that. They fuck shit up in ways that are partisan and divisive.

This is more of an NK/non-state-actor "burn it all down" move.

Re: I hate password rules

#349
post #326

Earlier quoted context omitted.

Yeah, my bank does that too. Asks for my birthday for "security" reasons. They also kill their website's usability by forbidding physical keyboards and forcing users to use a virtual keyboard with randomized key layouts in order to type passwords in a feeble attempt to defeat keyloggers. Some banks even make it extra annoying by generating ambiguous keys like "1 or 7" or "2 or 3". The saddest thing is banks can't be…

I imagine it also disables autofill from password managers (since it's not actually a form field)? I would literally close out my account in that very moment if my bank did that. Not only because that's horribly inconvenient and I would never put up with it, but it also shows they have no idea what are sane security measures or not .

> I imagine it also disables autofill from password managers (since it's not actually a form field)?

Yes.

They also force users to install literal malware into their computers masquerading as a "security module". Not only is it invasive, it slows down everything to a crawl. I tried to reverse engineer one such module and caught it intercepting every single network connection. It also used to force install itself into browsers as an extension, no doubt in order to intercept data.

> I would literally close out my account in that very moment if my bank did that.

That's exactly what I did. Chose a smaller bank that somehow didn't use this malware. The least bad option.

Re: I hate password rules

#350

Earlier quoted context omitted.

The software industry is full of should-be-criminal forms of negligence. Things are already horrendously bad. Basically every American's identity could stolen at this point. If any nation state or other actor decided to operationalize any of the big leaks -- eg OPM or EquiFax -- the ramifications would be catastrophic. Imagine millions of people losing their retirement accounts and all their savings. Even if you coul…

if that were to happen it would be a "to big to fail" event. the gov would bail everyone out and mandate a reset to what ever it was believed to be before. bank accounts, retirement accounts etc would be reimbursed up to the FDIC limit. credit reports would be rolled back to the last known good value. it would probably fuck things up short term but long term it would lead to better security of consumer data

Completed agreed. But the short term fall-out would be incredible, and I think the backlash against tech unprofessionalism would be merciless.
Post reply on HN