4 ms·
It is fascinating how many passwords are available ... I wonder why websites don't stop one from using these common passwords during account setup?
by normalfaults 14y ago
It is fascinating how many passwords are available ... I wonder why websites don't stop one from using these common passwords during account setup?
- rrreese 14y agoI suspect that any sort of password enforcement would decrease sign ups in relation to its strictness. It would be an interesting thing to AB test.
- wglb 14y agoSome do, with rules about complexity: minimum length, mixture of different classes of characters (lower, upper, numeric, special). Beyond that, I am not aware of websites looking through something like his considerable list of passwords to rule out choices.
- TazeTSchnitzel 14y agoTwitter does. They banned (IIRC) the 123 most common passwords. They have a list, too.
- chrisacky 14y agoBecause it's intrusive. There are lots of opinions on how far a website should go to ensure their users select strong passwords, but I implement a strawman password roster. If some of the throwaway sites and forums that I sign up to once started forcing me to select a more secure password it would be extremely annoying and I wouldn't sign up. I'm perfectly happy with my 6 letter a-z password for one time forums, that I use anonymously, and that I might occassionally log back into twice. Incidentally, the password I use is "openit". This password means nothing to me. If you did some detective work on me I'm 100% sure that you would be able to get access to some sites that I use by entering that password. Not having to use symbols, capitals, and strong passwords for these throwaway sites, means that I can effectively maintain about 10 different password sets, where my most important "tier 1" passwords are reserved for my SSH keys and email.
- pavel_lishin 14y agoI'd be curious how many 'throwaway' passwords are "sesame".
- patio11 14y agocough $250 in sales from folks who chose "password" in 2011. I suppose I could tell them "Wait wait, put your credit card back for a second and listen to a complicated instruction designed to solve a problem you don't have.". Doesn't seem to be a huge upside, though.
- trin_ 14y agoand you know that because: a) you store cleartext passwords b) you use a static salt and have memorized the hash of the password+your salt ... or c) ???
- patio11 14y agoBecause even bcrypt doesn't make testing one candidate password against 1,500 users all that hard.
- deleted 14y ago[deleted]
- mkjones 14y agoFacebook does - we have a blacklist of common passwords, and you cannot register an account with them or change your password to them. That being said, I think with sufficient protections against brute forcing, password complexity requirements are largely a waste of time. The percent of users' accounts you can get into with the number of attempts allowed before locking you out is so small that it's not cost-effective, and the majority of people trying to break into accounts are doing so at scale for financial gain.
- m8urn 14y agoHas Facebook ever shared that list?
- mkjones 14y agoIt's comprised in part of what we observed as the top hundred or so user passwords, so I'm hesitant to share it. I hope to do a more in-depth post about some stats we're able to run on password usage - I'll see if it makes sense to disclose (part of) our blacklist in there.