Earlier quoted context omitted.
I agree with all of this except password managers. If you use a lot of different public computers or temporary work laptops they don’t always let you install LastPass, so I frequently ended up being unable to access my accounts.
I access my manager from my phone and type them in. I would never install my LastPass on a public computer even if they let me.
49% of workers, forced to change passwords, reuse same one with minor change
71–80 of 316 posts
Re: 49% of workers, forced to change passwords, reuse same one with minor change
#72Wonder how many % use the password reset as an effective one-time password (unless cached) as they can't be arsed to remember the password complexity rules for every single site thwarting their simple password variations scheme.
For systems with automated password resets sent to email, what even is the point of a password at all? It literally accomplishes nothing. Just get rid of the password entirely and make checking email officially a part of the login.
Re: 49% of workers, forced to change passwords, reuse same one with minor change
#73Earlier quoted context omitted.
yes but if you get keylogged while using a pw manager, you lose everything, as compared to losing one (or a few, depending on how egregious your passowrd reuse is)
If you have malware on your machine you already lose everything.
I think that's what the previous commenter wanted to highlight.
In the end it's about managing risks, I would use different locations for storing passwords depending on value. Like really important ones go elsewhere and are not on the device I use everyday for browsing the Internet or reading email.
Re: 49% of workers, forced to change passwords, reuse same one with minor change
#74The password requirements at my job are, in my opinion, insane. It has to be a specified length (an exact number of characters, no more, no less), can't contain any 3+ character words found in a dictionary, and a few other requirements like at least one capital letter and at least one number. And it has to change every three months. So yes, when I have to change my password I end up changing a single character or dig…
If my bank did that, I'd be searching for a new bank. Just just reeks of passwords being stored in plain text.
Re: 49% of workers, forced to change passwords, reuse same one with minor change
#75The thing I hate the most is random websites forcing you to use a password with "at least 8 characters, capital letters, numbers, .." I only care about my email account and a couple of other important websites. I want to be able to use the same simple password on other websites. So what if my account on pinterest or my local news website or some random forum is compromised... I don't care. I will either reset my pass…
You can come up with a simple and easy-to-remember phrase for those. If it expresses your irritation with those rules and annoying mandatory logins, it's easier to remember. For example, FuckOff1234!
Re: 49% of workers, forced to change passwords, reuse same one with minor change
#76Of course we do. My password manager does not work for the Windows login and I need to change it every 3 months. I can remember 1 large complicate pass-sentence, but not a different one every three months.
Re: 49% of workers, forced to change passwords, reuse same one with minor change
#77I think they should go with fingerprints. I have to change my password every three months so I reuse the same password with a few numbers incremented. For a while I created completely new passwords but constantly memorizing them got really annoying. That’s the problem with a lot of security recommendations. Often they are very inconvenient.
Fingerprints are probably the least secure method of authentication possible. Picking up your fingerprint off of something you touched and fooling a fingerprint reader is pretty trivial. And worst, it's not something you can change, so once your fingerprint is copied, it's compromised permanently.
Fingerprints should never be considered a security feature. At most they're a convenience feature.
Re: 49% of workers, forced to change passwords, reuse same one with minor change
#78Of course we do. My password manager does not work for the Windows login and I need to change it every 3 months. I can remember 1 large complicate pass-sentence, but not a different one every three months.
Re: 49% of workers, forced to change passwords, reuse same one with minor change
#79Of course we do. My password manager does not work for the Windows login and I need to change it every 3 months. I can remember 1 large complicate pass-sentence, but not a different one every three months.
The answer here is to use a Windows Hello PIN along with a very complicated password (stored in your password manager) that is almost never used.
Re: 49% of workers, forced to change passwords, reuse same one with minor change
#80Earlier quoted context omitted.
Are you saying NIST and Schneier are wrong about this?
Schneier says "don't make people change their passwords unless there's indication of compromise" I make the assumption that the longer a password exists, the more likely it's reused and compromised. I don't have insight into every password dump, but I know my users reuse passwords a lot. I think a long expiry is the best balance in my environment.
You require new passwords every year, done Require symbols, done lower and uppercase, done numbers, done