5 ms·
ME Bank is the best: - Must be all numerals. - Be 7 to 20 digits. - Cannot have the same number three times in a row. - Cannot have four ascending or descen
by JasonFruit 4y ago
ME Bank is the best:
- Must be all numerals.
- Be 7 to 20 digits.
- Cannot have the same number three times in a row.
- Cannot have four ascending or descending numbers.
- Cannot have the same number appear more than five times.
- Cannot have pairs next to each other if the second pair is one number higher.
- Cannot be the same as 8 previous ones.
It would be fun to work out mathematically how much they're limiting the password space with these rules. I'm also not sure what "Cannot have pairs next to each other if the second pair is one number higher"; is that referring to consecutive pairs of numbers, or pairs of consecutive numbers, e.g. 7788 vs 7889.
- baal80spam 4y agoThis reads as if someone was throwing darts at the board with random rules.
- duxup 4y agoMore like they came up with one dumb rule…. and had to make the other rules to cover for it.
- jwestbury 4y agoI saw some similarly obtuse password policies when working in the defense industry. A coworker who had spent much longer than I had in the industry showed me what he called "the waterfall method" of password generation. That is, your password would be something like 1Qaz2Wsx -- a waterfall down the keyboard, if you will. You could always tell when he was typing in his password by the staccato tapping of keys. Just further proof, really, that overly restrictive password policy leads to users adopting insecure password practices. But we've known that for ages -- and, indeed, the password policies we were grappling with at work were in direct defiance of NIST guidelines about password policy.
- leetrout 4y agoVery common password methodology to remember the pattern on the keyboard like that. The NIST guidelines are really good IMO.
- zmgsabst 4y agoThe hard part was always password generation. That we’ve spent decades trying to add abstruse rules and training people to “do it right!” rather than provide a mechanism speaks to the psychology of security people. Buy people a box of tiny dice; have them make a game of a new pass phrase… that they can actually remember. Eg, this box which fits in your palm — and gets ~50bits per shake. https://zmichaelgehlke.com/images/dicebox.jpg https://zmichaelgehlke.com/images/dicebox.jpg
- zamadatix 4y agoPeople don't want the mechanism either because the root problem is the misaligned incentives in that a secure password is always more work to use compared to an insecure password. Recently the push for passwordless authentication has been tackling that.
- postingawayonhn 4y agoI think they mean like 7879.
- mrleinad 4y agoDo they at least tell you which one you're failing to comply with, or do they just let you figure it out on your own?
- duxup 4y agoMost of those rules sound like rules that came about because of the first stupid rule.
- gs17 4y agoAt that point they might as well add some more interesting ones - must be a prime number - digits must sum to a number ending in 7
- elesiuta 4y ago> It would be fun to work out mathematically how much they're limiting the password space with these rules. Alright, you nerd sniped me, but I'm lazy so I just simulated it, this cuts down the password space by ~35%. I didn't take into account passwords with leading 0s in my sampling, but this shouldn't change the result by much. from collections import Counter from random import randint def is_valid(password: str) -> bool: # cannot have the same number 3 times in a row if any(password[i] == password[i + 1] == password[i + 2] for i in range(len(password) - 2)): return False # cannot have 4 ascending numbers if any(all(password[i] == str(int(password[i + j]) - j) for j in range(4)) for i in range(len(password) - 3)): return False # cannot have 4 descending numbers if any(all(password[i] == str(int(password[i + j]) + j) for j in range(4)) for i in range(len(password) - 3)): return False # cannot have the same number appear more than 5 times if max(Counter(password).values()) > 5: return False # cannot have pairs next to each other if the second pair is one number higher if any(int(password[i:i+2]) == int(password[i+2:i+4]) - 1 for i in range(len(password) - 3)): return False return True total_valid = 0 samples = 10**5 for i in range(samples): password = str(randint(10**6, 10**20 - 1)) if is_valid(password): total_valid += 1 print(f"valid passwords: {total_valid}") print(f"valid percentage: {total_valid / samples * 100:.2f}%") valid passwords: 65045 valid percentage: 65.05%
- JasonFruit 4y agoI'm glad I sniped you before I sniped myself! I still question the interpretation of: > cannot have pairs next to each other if the second pair is one number higher But I think the outcome would be the same either way.
- zamadatix 4y agoReally the only place the amount of excluded password space matters is at the minimum length, which is conveniently brute forceable. Without padding 0's that comes to 91.63% valid, with padding 0's 91.42%. Smaller spaces are going to hit the repeat rules less often so the wide difference in percentages should be no surprise.