4 ms·
> 3. Create a method to combine the complex password and the simple password. So what happens when a site / service limits the length? Do you truncate your com
by anonred 8y ago
> 3. Create a method to combine the complex password and the simple password.
So what happens when a site / service limits the length? Do you truncate your complex password? And what about cases where only a certain subset of characters is accepted? Do you now need to memorize multiple variations of the complex password?
I used to do something similar to your proposed method, but the number of exceptional cases and work simply made if not worth the effort compared to a real password manager.
- freehunter 8y agoI found the same problem. I found too many places where passwords change far too often and are forced to be far too unique for a standard template to be replicable. Even something like HNspring2018 for my HN password, if I had to change it and did HNfall2018 I've seen sites kick it back saying it's not unique enough, or I can't use the date or year. Many won't let you use full dictionary words, even when paired with more complex stuff. My work password needs to be changed every 60 days, must be longer than 16 characters, can't repeat three characters in a row over two password iterations, and passwords have to be unique for two years before you can repeat them. I write that password down on paper every time. I hope we've reached peak ridiculousness when it comes to passwords and this is as bad as it gets before something better comes along.
- tobiasSoftware 8y agoHaving a complex password that I use for everything allows it to be nonsensical. Mine is actually based off of a phrase (an idea inspired by XKCD) but the words have some dropped characters and it includes a name (so instead of correcthorsebatterystaple, think crrctChampbttrystple). I avoid making the simple password actual words as well, but it's simple enough that if I want to use the password at work but store it at home, I can memorize it easily for a day. I agree that we've hit peak ridiculousness though.
- user5994461 8y agoThat's completely insane requirements. I don't get how anyone could remember any password like that.
- wwweston 8y agoHow often are you running into length-limited password fields these days? I usually take it an organization is not attentive to or is outright uninterested in security, and either I shouldn't use their service (if it's optional), or I should publicly shame them.
- andrewflnr 8y agoPasswords with character restrictions are still pretty common, AFAICT. Yahoo, for instance.
- anonred 8y agoOff the top of my head: - PayPal - Rent payment portal - University account - Target (etc...)
- bklaasen 8y agoOffice365 maxes out at sixteen characters.
- tobiasSoftware 8y agoI haven't hit a length issue, it's not super long though. If I need to do a variation, I write it down with the simple password. The main two variations are that it requires a number (which I don't have in the complex password), so I just add a number to the simple password, or that it can't use special symbols (which I do have in the complex password), so I use the corresponding number (for example 1 instead of !) and write down that I used a number instead of a symbol.
- umvi 8y ago>So what happens when a site / service limits the length? Do you truncate your complex password? And what about cases where only a certain subset of characters is accepted? Do you now need to memorize multiple variations of the complex password? For that I just keep a Google doc with site password restrictions and other public information mostly useless to a cracker. My password has rules for adapting to said site restrictions so I just lookup the site in Google docs and adapt my password accordingly