5 ms·
> These policies drive users to very predictable passwords I used to do a lot of contract work for the Clarke County School District in Athens, GA. For "securi
by robbyking 5y ago
> These policies drive users to very predictable passwords
I used to do a lot of contract work for the Clarke County School District in Athens, GA. For "security" reasons they weren't able to create domain accounts for people who weren't full time employees, so I'd often have to track down the IT manager to gain access to servers I was working on.
He eventually got sick of having to drop what he was doing a dozen times a day, so one day he just gave me his password: a dictionary word followed by the number 23. Eventually the password failed, and he gave me his new password: that same dictionary word followed by a 24.
Fast forward a few years and I'm back installing some updates, and before I get to work he hands me a slip of paper, on which he had written Dictionaryword29.
- ifdefdebug 5y agoDid you just give away very predictable credentials from a very predictable person with full access to very predictable IT equipment?
- moron4hire 5y agoWith passwords that simple, it's crackable almost instantaneously without any preknowledge of the password format. That, coupled with the fact that systems get randomly attacked all the time, I doubt it's really that big of a deal. Attackers don't need hints on passwords, they don't need hints on targets. They just target everyone, and try all easy passwords.
- hsbauauvhabzb 5y agoIt depends on the context, if I have a hash it’s trivial to crack dictionaryword29, if I’m brute forcing a VPN/RDP endpoint, generally fail2ban are hard enough to block mass attempts (an AD default, iirc), the latter is usually solved by phishing which has the added benefit of MFA capture also. Pentester here, to clear any dubious assumptions.
- ivalm 5y agoBut if the password is salted is it still easy to crack?
- hansvm 5y agoYes, definitely. The salt just means you have to compute a few hashes yourself rather than relying on a lookup table.
- tracker1 5y agoYes... there are lists that are generally used for common variants of passphrases and can generally crack a simple passphrase like ggp in less than a day easily, faster or slower depending on hardware in use, concurrency and order. 4-5 dictionary words with proper sentence structure is a lot safer for the most part. Random safer still, but much harder to remember... my current password for work in a sentence with 24 characters. spaces, capitals and punctuation. Other than my OS and password manager, I really don't remember any other passwords I use, and the majority are random generated at this point. I also use a wildcard mail forwarder, so most new sites I've used in the past year or two are all unique emails as well.
- OJFord 5y agoIf you're relying on all former colleagues not inadvertently (or otherwise) giving away details that may (slightly aid in the) comprise (of) your systems...
- csomar 5y agoIt might be a good idea to omit the school's name.
- gregmac 5y ago> a dictionary word followed by the number 23. Eventually the password failed, and he gave me his new password: that same dictionary word followed by a 24. In a similar vein, over the past few years whenever I've got in a discussion with IT people who defend mandatory password change policies, I ask them to give me the last password they were using before changing it. No one has ever taken me up on that.
- Causality1 5y agoMost of the people I know use some kind password they can derive if they forget it. Like their password for Company A will be the city the company was founded, city the founder was born, and the month/day it was founded. The ones who have to change it because of policy pick something iterative, like the first line of a song, then the second, etc.
- cmeacham98 5y agoMost of the people you know are well outside the normal then. In my experience the average password consists of 1-3 words with some meaning to the user, sometimes either in 1337speak or followed by numbers/symbols if the password policy requires them.
- KeepFlying 5y agoI'm with you on this. I know very few people who generate passwords like that and most people I know use some simple "special word with special number" pattern. Often it's kids names, a random word they picked as a password years ago and have been reusing, and some part of their pin number.
- dunham 5y agoIn the past, I used a grid of random characters (a tabula recta) that I keep in my wallet, plus an algorithm for pulling passwords out of it. This system broke down when I was forced to change passwords on various sites.
- tialaramex 5y ago
- smoe 5y agoThere was a talk I saw some years ago of someone that analyzed enterprise passwords and the most common pattern they found was: Dictionary word with first letter uppercase, followed by two-digit number, followed by exclamation mark. With the overall length exactly being the minimum length of the policy.
- Aeolun 5y agoMy first password is always secure. The second one less so, but by the third time you make me change my password it turns into easily predictable dictionary words.
- p_l 5y agoA former coworker of mine used to track how long he was working with certain client by the amount of dots after their actual password. I simply disabled password rotation policy on my account ノ(ジ)ー'