Do I really need a password like this?

Users Who Are Viewing This Thread (Total: 1, Members: 0, Guests: 1)

Roggio

Active Member
View Badges
Joined
Dec 13, 2011
Messages
360
Reaction score
367
Location
Orlando
Rating - 0%
0   0   0
This is excessive IMO

Screen Shot 2018-01-16 at 7.30.15 PM.png
 

chipmunkofdoom2

Always Making Something
View Badges
Joined
Jun 6, 2017
Messages
2,417
Reaction score
4,497
Location
Baltimore, MD
Rating - 0%
0   0   0
From someone who works in IT, it does seem a bit excessive, especially when shorter, more complex passwords are not more secure. A much better solution would be longer passwords. Or enabling 2FA, such as an authenticator app or text to your phone when you try to log in.
 

Abraham Gonzalez

Community Member
View Badges
Joined
Nov 28, 2016
Messages
87
Reaction score
27
Rating - 0%
0   0   0
From someone who works in IT, it does seem a bit excessive, especially when shorter, more complex passwords are not more secure. A much better solution would be longer passwords. Or enabling 2FA, such as an authenticator app or text to your phone when you try to log in.

While I completely agree with you concerning two-factor authentication (2FA) or longer passwords as opposed to shorter complex passwords the default security complexity requirements in most servers were placed there to deter passwords such as (password, monkey, nameofindividual, etc). I have worked in IT for many years as well and when given the opportunity many end-users will go for ease of use over even the simplest of security any chance they are given.
 

Mandelstam

Well-Known Member
View Badges
Joined
Oct 29, 2017
Messages
688
Reaction score
1,117
Location
Malmö, Sweden
Rating - 0%
0   0   0
Worst idea my IT department have is to force everyone to change their password every 90 days. That DEFINITELY forces people to use very simple passwords like name of family member plus a number that you just raise by one every time you change it. No way in hell I'm going to spend time coming up with a long and complex pw and then memorize it just to be forced to change it after 90 days...
 

tastyfish

Well-Known Member
View Badges
Joined
Sep 7, 2017
Messages
525
Reaction score
446
Location
Hampshire
Rating - 0%
0   0   0
Having worked in cyber security for 20 years, yes, minimum password complexity is needed as passwords such as "letmein", "password" and "password1" are still in the top 5 used. :(

Changing corporate passwords every 90 is a minimum, but user frustration and forgetting the mass of passwords we now have is a real problem.

Personally I insist on multifactor authentication on sites which hold sensitive data/services, but I have a simple password system for non critical sites where my money can't be spent/information on me held.
 
OP
OP
Roggio

Roggio

Active Member
View Badges
Joined
Dec 13, 2011
Messages
360
Reaction score
367
Location
Orlando
Rating - 0%
0   0   0
This is accessing testing results on my home aquarium. I’m not accessing the pentagon remotely. Also I had the email authorization sent and it never showed. There’s no option to have them re send it so i’m stuck using another email I didn’t want to (yes I checked my junk folder). I’m greatful we have this testing now but there’s also other options. This is enough for me to at least shop around next time.
 

chipmunkofdoom2

Always Making Something
View Badges
Joined
Jun 6, 2017
Messages
2,417
Reaction score
4,497
Location
Baltimore, MD
Rating - 0%
0   0   0
While I completely agree with you concerning two-factor authentication (2FA) or longer passwords as opposed to shorter complex passwords the default security complexity requirements in most servers were placed there to deter passwords such as (password, monkey, nameofindividual, etc). I have worked in IT for many years as well and when given the opportunity many end-users will go for ease of use over even the simplest of security any chance they are given.

Right, I understand why password rules exist. I also understand why password, monkey and nameofindividual are all terrible passwords. My point was not that there should be no password restrictions at all. My point was that the type of password many sites and enterprises generally recognize as safe, a short password with a few special characters, is largely ineffective today. With the availability of hashed password databases and very cheap computing time, a standard "secure" enterprise password is trivial to crack. My first job in corporate IT was desktop support. There were only a handful of users who did NOT have their current password, along with their last few, written down somewhere. It doesn't really matter how resistant your company's passwords are to bruteforce cracking: if the janitor can log into the computer just by walking in and steal your company's trade secrets, your password policy has failed.

Corporate IT security has had a pretty bad track record over the past decade or so. If you want proof, look no further than all the data breaches of high-profile corporations who should know better. We need a different approach to password security and hygiene. Short and complex passwords are not the answer, and I think people are getting tired of the security theater.
 

Mark Derail

Active Member
View Badges
Joined
Sep 27, 2017
Messages
250
Reaction score
218
Location
Montreal
Rating - 0%
0   0   0
Passwords ideally should be three characters !!! But no length limits.

Example of 3 characters password:

MickeyMouseMinnieMouseDonaldDuck

The above password is superior to: Mickey!2009

Tada
 

RobertP

Active Member
View Badges
Joined
Jan 10, 2017
Messages
342
Reaction score
335
Location
Frelsburg, TX
Rating - 0%
0   0   0
I work in IT as well and the longer more complex passwords are the best. The best advice I can give is to make up a phrase similar to what Mark shows using upper and lower case.

One thing I recommend is a program called KeyPass. It is a program that holds your usernames and passwords. You need to remember a complex password to get into it but then you can house all your usernames and passwords for various websites. Best part is it gives you simple copy features to copy the username and paste it into your website. It will even generate long complex passwords for you.
 

dstienmann

Active Member
View Badges
Joined
Jun 9, 2015
Messages
147
Reaction score
61
Location
St Louis
Rating - 0%
0   0   0
Worst idea my IT department have is to force everyone to change their password every 90 days. That DEFINITELY forces people to use very simple passwords like name of family member plus a number that you just raise by one every time you change it. No way in hell I'm going to spend time coming up with a long and complex pw and then memorize it just to be forced to change it after 90 days...

This

Im the Sysadmin for a Aerospace Co we have these same password requirements from the DOD and they just make it worse, yes everyone has the easiest password and just ups it by 1 or the really smart ones will write it under their keyboard :rolleyes:
 

Abraham Gonzalez

Community Member
View Badges
Joined
Nov 28, 2016
Messages
87
Reaction score
27
Rating - 0%
0   0   0
Right, I understand why password rules exist. I also understand why password, monkey and nameofindividual are all terrible passwords. My point was not that there should be no password restrictions at all. My point was that the type of password many sites and enterprises generally recognize as safe, a short password with a few special characters, is largely ineffective today. With the availability of hashed password databases and very cheap computing time, a standard "secure" enterprise password is trivial to crack. My first job in corporate IT was desktop support. There were only a handful of users who did NOT have their current password, along with their last few, written down somewhere. It doesn't really matter how resistant your company's passwords are to bruteforce cracking: if the janitor can log into the computer just by walking in and steal your company's trade secrets, your password policy has failed.

Corporate IT security has had a pretty bad track record over the past decade or so. If you want proof, look no further than all the data breaches of high-profile corporations who should know better. We need a different approach to password security and hygiene. Short and complex passwords are not the answer, and I think people are getting tired of the security theater.


I understand your stance and I agree with you completely two-factor authentication and passphrases (longer passwords) are a much better way to execute security in an IT environment. I was only making a statement as to why these now antiquated security requirements were implemented and that many older machines are still restricted to these requirements. I believe a password "vault" such as Keepass as suggested by RobertP would help in managing the many passwords that our modern environment requires.
 

EmdeReef

2500 Club Member
View Badges
Joined
Dec 2, 2017
Messages
3,133
Reaction score
5,035
Location
New York, NY
Rating - 0%
0   0   0
I use a PW manager ( lastpass, it's free) but many other on the market. Integrates well in the browser on laptops and phones/ipads. Can even change your passwords automatically. The downside is that I don't know ANY of my passwords anymore :)
 

Titus

Active Member
View Badges
Joined
Aug 30, 2012
Messages
226
Reaction score
10
Location
Dallas, TX
Rating - 0%
0   0   0
I use LastPass password vault and love it. It's password generator is great, and it will auto-populate the password on both my computer and phone browsers.
upload_2018-1-23_10-48-8.png
 

ioarnunz

New Member
View Badges
Joined
Oct 18, 2020
Messages
4
Reaction score
1
Location
US
Rating - 0%
0   0   0
When using secure methods to ensure the reliable operation of your business, I use two-factor authentication of users with the generation of one-time passwords through universal security tokens. subsequently, roundcube email provides additional reliability and makes this approach very convenient for users of any level.
 

K7BMG

Valuable Member
View Badges
Joined
Mar 13, 2018
Messages
1,981
Reaction score
1,898
Rating - 0%
0   0   0
My passwords are not intelligible.
I create passwords by turning my keyboard upside down and randomly typing at least 12 characters.
I will then choose various letters and capitalize them and add the special character if needed.
Of course this is only for sites and systems that must be secure.
The rest I have a generic PW.
 

gray808

Active Member
View Badges
Joined
Sep 13, 2019
Messages
263
Reaction score
164
Location
Seattle & Ashland, OR
Rating - 0%
0   0   0
It depends on what the site that has the password is.
Does it have any valuable information stored? Credit card info, etc?
If it's just a forum... yes, it's excessive.

But.

Use a password manager (I use LastPass, and can recommend it), and use it for everything. It will make a password as complicated as the site needs, and all you need to do is remember the main password manager password. I use it for everything that needs a password, except super high-risk things like my bank login. For those, I have my own, strong, complex password.

--Gray
 

BeanAnimal

2500 Club Member
View Badges
Joined
Jul 16, 2009
Messages
3,183
Reaction score
4,820
Rating - 0%
0   0   0
This is excessive IMO

Screen Shot 2018-01-16 at 7.30.15 PM.png
Insanely silly... As are most similar requirements. They make passwords harder to remember and beg for serialization every time you are forced to change it.

2 or 3 dictionary words with a number or special care in between one or two is easier to remember and has just as much (or more) entropy.
 

Reefing threads: Do you wear gear from reef brands?

  • I wear reef gear everywhere.

    Votes: 19 14.2%
  • I wear reef gear primarily at fish events and my LFS.

    Votes: 9 6.7%
  • I wear reef gear primarily for water changes and tank maintenance.

    Votes: 1 0.7%
  • I wear reef gear primarily to relax where I live.

    Votes: 21 15.7%
  • I don’t wear gear from reef brands.

    Votes: 75 56.0%
  • Other.

    Votes: 9 6.7%
Back
Top