The Password Game
371–380 of 540 posts
Re: The Password Game
#372This was a horrific abomination, and delightfully evil.
My solution (which includes some spoilers, even though each game has somewhat different rules): https://social.joshtriplett.org/@josh/posts/AX8ypcJYS8eSFLUX...
Re: The Password Game
#373A warning to future players: I got to rule 16 and was given an egg named paul that I had to keep safe. Then on rule 18 a fire (of emojis) broke out in my password, killing paul and ending the game. Dont be like me, keep Paul safe.
Not even surrounding Paul with water emojis could stop the fire.
Re: The Password Game
#374[dead]
Re: The Password Game
#375For anyone else who was struggling to make the leap year work with all the other math: 0 is a leap year. For anyone else struggling with how to make the country name work with roman numerals or element names, you can lowercase the country name then it doesn't count as a roman numeral nor element. If your chess move is illegal, make sure you're also notating the effect of the move (Nxe6 for N captures on e6, not just…
> For anyone else struggling with how to make the country name work with roman numerals or element names, you can lowercase the country name then it doesn't count as a roman numeral nor element. Unfortunately, "country name" and "all the vowels in your password must be bold" are fundamentally incompatible, since it doesn't recognize country names unless they have unbolded vowels. EDIT: Gah. I tried every Unicode "bol…
Re: The Password Game
#376Earlier quoted context omitted.
1. You can have multiple hardware keys or devices bound to an account as a backup of for ease of use. 2. Passkeys allow you to pick a backup solution of your choosing. Could be your own nextcloud server in the corner. This is no different than giving someone a choice of cloud-synced password manager Both solutions avoid phishing, password re-use, keylogging, or people picking weak passwords. There is no excuse for an…
> 1. You can have multiple hardware keys or devices bound to an account as a backup of for ease of use. How does that help if someone steals your hardware key, login in with it and then puts it back. You don't even know that it was stolen and your account was messed with. With a good password you know if you tell someone. Granted people could film you typing your password, but stealing your hardware key is much easie…
2. Fido2 lets you decide who to trust. A non technical user can use google or apple or a hosted nextcloud instance as a backup. A technical user is more likely to enroll the TEEs built into their phones and laptops, with a yubikey in a safety deposit box as a backup.
Passkeys and FIDO2 offer a massive reduction in attack surface and are superior to passwords in every way for every threat model I have ever heard of.
You have all the same options for managing a fido2/passkey/webauthn key as you do an ssh key.
Web passwords should go die in the same fire as SMS 2FA.
Re: The Password Game
#377Re: The Password Game
#378I gave up after having to include a leap year (Rule 15), I don't know if this is a spoiler but I ended up with January99Pepsi?XXXVggd7maboutZrJapan (there was an emoji in there for the current moon phase but HN stripped it out) Looking at the code it should be possible to get a lot further, in theory. Wonder how Paul is doing!
Re: The Password Game
#379Re: The Password Game
#380Earlier quoted context omitted.
1. You can have multiple hardware keys or devices bound to an account as a backup of for ease of use. 2. Passkeys allow you to pick a backup solution of your choosing. Could be your own nextcloud server in the corner. This is no different than giving someone a choice of cloud-synced password manager Both solutions avoid phishing, password re-use, keylogging, or people picking weak passwords. There is no excuse for an…
> 1. You can have multiple hardware keys or devices bound to an account as a backup of for ease of use. How does that help if someone steals your hardware key, login in with it and then puts it back. You don't even know that it was stolen and your account was messed with. With a good password you know if you tell someone. Granted people could film you typing your password, but stealing your hardware key is much easie…
However, if you use a Yubikey or Trezor for example as a Passkey (No Password), you have to enter a pin on either (Yubikey via OS and Trezor on device) before they will fulfil the request and log you in.