12 ms·
Password Rules
- fiatmoney 14y agoIronically, each of these restrictions reduces the space of possible passwords for a brute-force attack, which is already pretty small given the inane 8-characters-exactly requirement.
- astangl 14y agoI have pointed this out to people before too. It doesn't seem to deter their slavish adherence to what they declare to be "best practices", which seems to correspond to something they read in some magazine or blog.
- jiggy2011 14y agoIs there any reasoning at all behind the thinking that requires passwords such as this? These sorts of rules are so commonplace that there must be some reasoning for it?
- kijin 14y agoTo begin with, preventing SQL injection when passwords are stored in plain text without any escaping. (CHAR(8) field. No special characters allowed.)
- jiggy2011 14y agoThat's an utterly horrible reason but I take the point. I imagine many sites implementing these policies (some banks etc) are hashing their passwords properly and sanitizing SQL though!
- xbryanx 14y agoI am sure operability and not security are the primary factors behind these rules.
- georgefox 14y agoThere is reasoning; it's just not valid reasoning.
- haberman 14y agoAlso: quit the "security questions" thing. I can't count the number of times I've been locked out of my account because I couldn't remember the precise answer I gave to a security question. I bought a house last month, and the biggest thorn in my side throughout all of the financial arrangements was security questions (I'm not even joking). Here's a Facebook status update I posted (I had already been complaining about security questions a bunch): "Just got challenged with a security question, which was "Thank you for your loan application." Wtf, that is not a question. And I've never filled out any security questions for this website, so I have no idea what it's expecting me to enter. "I swear, security questions are out to get me."
- ecoffey 14y agoThis may not have helped your specific case, but I recently bought 1Password, and updated all my security questions with randomly generated 16 character string answers, and just put those strings in the "notes" section of a website. So when they do challenge me I can just copy/paste them in. It's been awesome!
- unfletch 14y agoI've used 1Password generated passwords for years. You're right, it is awesome, but only until you have to relay one of those generated strings to a support person over the phone: "...left curly brace. No, it's like the parenthesis, but squiggly. Are you using a regular keyboard? Hold shift and type the left square bracket. The square one. It's to the right of the P..." Nightmare.
- kijin 14y agoI can't imagine the horror of having to recite any password to an actual human being. What kind of company asks you to tell them your password by phone? "No, the backslash. The one that leans backwards, no, I mean, to the left. Above the Enter key." Surprise, the backslash is not above the Enter key on Canadian bilingual keyboards.
- 14y ago
- homosaur 14y agoWOW. I was expecting something dumb but this is next level dumb. You're basically forcing a 7 character password since I already know one of them is one of those three special characters. Then you've just given me like 5 more rules that limit what the password can be. Any password cracking service would crack this in hours. IT people should understand the basics about security before they are allowed to set policy.
- ot 14y ago> You're basically forcing a 7 character password since I already know one of them is one of those three special characters. Not exactly, because you don't know where the special character is. If the allowed characters are k, the number of 8-character passwords would be k^8. With this rule, even assuming that only one special character is used the number becomes 7^k * (3 * 8) = 7^k * 24, so if k ~= 60 the entropy is reduced by roughly 1 bit. Still, it is an incredibly stupid rule.
- jaybill 14y agoI'm pretty sure the password guesser I wrote to give me passwords on terminals in Fallout 3 would easily give me these passwords.
- hahainternet 14y agoI don't know whether this is cool or sad. Fallout 3 passwords were trivially easy to infer from a single guess. They took extra time to reduce the ambiguity and make it easy once you understood the principle. Were you running a mod?
- jaybill 14y agoI think it's probably more on the side of "sad", considering the way I did it. No mods. I wrote a little android app that you could put the words and number of correct letters each try into and it would shorten the list each time you did. After a while I figured out "the trick" and could do them in my head and didn't need the program anymore. It was a fun little programming exercise, though.
- sunwooz 14y agoIf you had to create a list(or non-list) of requirements a password must pass what would it be? (Ex. Case sensitivity, length, cannot be the same as username etc etc) The bare minimum with the least frustration for the user? I was very surprised by the news-piece that blizzard was using case-insensitive passwords and that got me thinking...
- x1 14y agoI wouldn't, I would apply something like this http://www.passwordmeter.com/ http://www.passwordmeter.com/ and show the user how secure or insecure their password is. Depending on the service they are using maybe only allow passwords at Strong or better but base that off the complexity of the passwords. %09(0m is stronger than minneapolisminnesota
- LinaLauneBaer 14y agoDoesn't the strength of a password also depend on the cardinality of the underlying alphabet? So your example makes only sense when you also say something about the used alphabet or am I missing something here?
- Dove 14y agoSort of. The strength of a password, at the most basic level, is based on the number of passwords it could have been. That is to say, the number of live possibilities in your password-generating algorithm. In theory, large alphabets and long passwords lead to increased password strength because they mean your password could have been many other things. In practice, the vast majority of those other things were never live possibilities, so the password is not that strong even if it is long or the symbol set is large. For example, suppose you choose to base your password on your dog's name, Rover. This is one of maybe half a dozen likely choices for you, so is not a strong password. If you modify it for length and symbol set into Fetch4meRover!, this is still one of maybe a dozen things you would have chosen to do with the name, so is still not that strong in spite of the length and character set. In general, you should not trust yourself to generate random information, and particularly passwords. Use a script to randomly generate a password -- a script with a known large number of live possibilities. This is the only way to ensure those possibilities -- the ones that make a password secure -- were ever actually live.
- healsdata 14y agoOf those ten rules, nearly half of them hurt password strength. The others make it harder for users to remember their passwords which will lead them to frustration and, ultimately, bad passwords. Austin#1 is a perfectly valid password according to those rules. zxcvbn says it'd take 2.508 seconds to crack that.
- deleted 14y ago[deleted]
- njloof 14y agoAfter coming up with a password that obeys all those rules, I recommend writing it down on a yellow sticky note and putting it on your monitor.
- droithomme 14y agoWhich I have seen at secure facilities, as we all have, I think.
- RandallBrown 14y agoIf it's a secure facility, it's probably pretty safe.
- r00fus 14y agoOr the digital (secure) equivalent: a password manager. Seriously, any decently sized organization should strongly recommend or mandate usage of such - they are also great when a transition needs to be made - known external credentials can be exported or passed during knowledge transfer and passwords reset.
- x1 14y agoYeah. As someone who prefers passwords in the 12-24 character length I get really annoyed when a site comes back and tells me my password isn't good enough because it doesn't follow various rules. Oh you really think someone is going to brute force $MILKAndDailyCheeseRe because it doesn't have a number in it?
- darkarmani 14y agoEven worse is when they limit to 12 characters, but don't enforce it in the UI. I couldn't login once because the bank website truncated my password silently to 12 characters. On a whim, i tried the first 12 characters and i was able to login.
- xbryanx 14y agoI've worked with rules like this, and it's even worse when it's some domain password used across multiple crappy systems. Often a 3rd party system that has integrated with this password doesn't accept the $, or has to be 7 characters or something. So the IT folks tell you to follow the rules, but if you use the accounting system, make sure not to put $ in there. #facepalm
- Margh 14y agoWait, what? This isn't a joke?
- pbreit 14y agoStupid password rules is probably the leading source of consternation for this internets user. Has anyone ever analysed if password rules help at all? Aren't most compromises social-based or otherwise accidental? No one breaks in by slamming millions of login attempts at a server, do they?
- sukuriant 14y agoMy Diablo 3 account was hacked because my password was 'abcd1234'. This is no longer the case. So yes, sometimes. And no, I'm not certain why on earth I set that as my password...
- pbreit 14y agoAre you sure it was brute-forced? And the website owner had nothing in place to see that it was getting hit with brute-force password attack?
- PezCuckow 14y agoThis demonstrates what is wrong with what the world expects a password policy to be, very few of these even increase password cracking complexity. They are just dumb rules to annoy your users. Sigh!
- jonamato 14y agoThe sub-password "similarity" rules (#8) mean that it is incredibly unlikely that the system is storing the password history hashed, and basically impossible that they're storing it salted. What could possibly go wrong?
- raldi 14y agoYou don't need unhashed password storage to enforce similarity rules. Presumably, the user has to type in their current password when they set a new password. When processing that request, you have all the information you need to do the similarity check.
- petitmiam 14y agoWhat about the 7 passwords prior?
- charliesome 14y agoI believe the 7 passwords prior aren't checked for similarity, only equality.
- NelsonMinar 14y agoEveryone's making fun of this, and it is dumb. But really this is just an example about how passwords are a stupid form of authentication. Not just this site, all passworded sites. We really need something better. I favor OpenID or something like it. Single strong form of authentication, delegate login authority from that to non-critical sites like Hacker News. OpenID has enough of a bad reputation now it's probably a non-starter. BrowserID has some promise: https://browserid.org/ https://browserid.org/
- steve-howard 14y agoI don't know that passwords are all bad. For an alternative approach to complex rules, see: http://xkcd.com/936/ http://xkcd.com/936/ The last time I changed a password for a service I set it to a phrase that I can easily remember but which no human or current machine will easily guess. I'd say that the only good rule is "Make it at least 9 characters" (which is at least long enough to disallow "password").
- amalcon 14y ago11 is also a sane minimum, to disallow 1234567890.
- jtheory 14y agoOr you could just disallow "1234567890".
- unimpressive 14y agoCharacter minimums hurt your entropy too. Stripping the entire search space up to nine characters isn't really a good idea. In my opinion it'd be better to just find a list of the top 10K passwords and disallow them. One out of 50 people use one of the top 20 passwords. [0] I'd bet that over half of passwords used are in the top ten thousand. [0]: http://xato.net/passwords/how-i-collect-passwords http://xato.net/passwords/how-i-collect-passwords
- 14y ago
- DaNmarner 14y agoI bet this has something to do with some mighty Oracle DBA.
- its_so_on 14y agoI swear one day we will see. "Unfortunately time and again we have come to observe the inability of employees to follow simple rules during password creation. For example, despite our warnings, employees often create a password containing more than one consecutive non-numeral; other employees attempt to createa a password consisting only of numbers, only of letters, or an insecure mix of numbers and letters - e.g. 5:1 - with no special characters. This is unacceptable. Henceforth, new passwords must be one of the following five possibilities, as described below: s$sVC!{IV{wG:|9 (Employees with last name beginning with A-F) bE#40,$&T@V}266 (Employees with last name beginning with G-L) U>~7nw*,55{][%H (Employees with last name beginning with M-R) EL8$v{4#L8482 5 (Employees with last name beginning with S-X) or 1^_4s"x&T3pB,%% (All other employees). You may not use a password you have ever used previously. In two weeks, the new possibilities will be posted to the web site, and you must change your password immediately to one of the new possibilities. You have brought this on yourselves, and if you begin to show an ability to use secure passwords, you may get to pick your own in the future. Until then, they will be assigned to you. HR."
- dekz 14y ago> The password must be exactly 8 characters long. This is probably the root cause of bad passwords. In the case of Average Joe, he is now having to choose something memorable which is 8 characters long. 'PassworD'
- Terretta 14y agoSorry, "PassworD" doesn't validate. You're missing a symbol, and you have a character repeated. Try "P@s5w0rd" instead. Or, better yet, "abc#1234" as suggested in the examples.
- dekz 14y agoWe've moved on to a fictitious setup. I was so disgusted with my bank and their password policies and authentication measures. They too restrict to 8 characters, but they happen to also offer a SecurID token. This token can be used in conjunction with the initial authentication. I would happily switch to any bank where I can know my data is secure. How do we trust them?
- unimpressive 14y agoOf course this is totally ridiculous, and shoots their entropy with a shotgun. But my heart goes out to whoever was logging into the child support page at the texas attorney general website. That sucks.
- valuegram 14y agoI was the one who posted this. It's the same login used to report new hires to the attorney general... Luckily no child support issues here.
- angry-hacker 14y agoI wonder how many possible variation of passwords with these rules there can be... 8 chars, no same letters next to each other etc.. brute force hacking might be fun..
- Achshar 14y agoBanking passwords are always fun. Mine has to be changed every 30 days, cannot be same as last 3, must contain at least one number, special character, capital, lowercase. I essentially end up where i have to store password in plain text (!) in a password protected file. ridiculous but there is no way around it. People really have go understand that such things don't help at all, they increase user frustration if anything. I have never understood the number/uppercase requirement, if someone somehow put a key logger it won't matter or if some one is using brute force, it wont matter either.
- taylorbuley 14y agoExcept whereas those rules sound like they would enhance your personal security, following these rules work against it ("must be exactly 8 characters"?!)
- Firehed 14y agoFirst, get 1Password or something similar. Second, the mixed case alphanumeric definitely aids against brute force attacks, particularly in the case of an online attack (for an offline attack, there are probably hundreds of thousands of attempts per second so the only effective protection is a slow hashing function that limits attack speed)
- Tichy 14y agoWell the "not the same as last 3" rule is easy to circumvent: Just add a number at the end, password1, password2, password3...
- darkarmani 14y agoSo schemes notice the incrementing value, so I ended up doing !,@,#,... which is equivalent to 1,2,3... The bonus is that I could still track how many quarters I worked for that place before leaving (lasted into the 6 quarter).
- runn1ng 14y ago" Characters in the first, second, and third positions cannot be identical. " Any reason for that? Using pretty similar passwords with minor differences is how I manage to remember passwords for all those fifty different services I have to know password for...
- JWhiteaker 14y agoHaving overly restrictive password rules like this, combined with requiring a new password every x months, just leads to more users writing down the passwords on notes stuck to their monitor.
- mathattack 14y agoIf this weren't a US government website, I'd swear it was a hoax!
- goatslacker 14y agoWhomever thought this was a good idea needs to be kicked in the groin.
- DanBC2 14y agoAnyone who knows anything know that most people also chose stupid passwords. They know that the stupid password will be used across multiple sites. Those sites might well store the password in plain text or with broken hashing. But those people also know that rule-lists like this one are stupid. Users get frustrated and confused and have to rapidly create a compliant password, which leads to weak passwords that get written down in silly places. We know all this. We've known all this for many many years. ID theft (grabbing the first number from a search engine) costs "£2.7 billion per year". Why are we stuck with dumb archaic authentication systems? Why isn't this space being disrupted?
- jaybill 14y agoI get annoyed when I can't use spaces, because my general password strategy is to click my link bar shortcut to Random Wikipedia Page, pick five or six words and use that as my password. Easy to remember, hard to guess, even harder to brute force. Thanks XKCD! I use Keepass to store passwords for the various things I use, and even though my hive is stored on a web server (uses SSL and requires a password, of course) for convenience, it has a well chosen, rotated password and a key file that I carry on a USB stick with my keys. I keep a backup of the key file in a safe physical location. No two passwords are the same and none is less than 16 characters. One nice thing about Keepass is that you can also store URLs and other arbitrary information in the hive. Should anything ever happen to me, my wife will automatically receive instructions on how to locate and access the hive. (automatic email, dead man switch) Keepass also lets you set reminders so you can regularly change passwords.
- epistasis 14y agoThis is a terrible way to choose passwords, and in no way equivalent to the XKCD method. It's not equivalent because additional length in your password is very predictable rather than random. To brute force your password, all somebody has to do is choose a starting word in Wikipedia and some number of consecutive words. This is log2(size of Wikipedia) + log2(entropy of your "5 or 6" distribution). This is less than 32 bits of entropy, or about a six character password in a 64 character alphabet, i.e. it's trivial to brute force this password if you have the hash.
- 16s 14y agoThere needs to be an ISO standard for passwords. Things like this are ridiculous.
- asciident 14y agoWhat I want to know is whether there is a subset of passwords that will be valid against almost all password rules. Like if I make a password that has 12 characters, one symbol and one number, will that fit in 99.9% of cases?
- jklp 14y agoI always wondered about these arcane rules, where passwords are easy for computers to hack, but hard for humans to remember. See obligatory xkcd comic: http://xkcd.com/936/ http://xkcd.com/936/
- neotek 14y agoI work for a major bank in Australia and I'd be ecstatic to have requirements as (comparatively) simple as this.
- philip1209 14y agoNeed . . . public key . . . access
- kbronson 14y agoPassword Sucks
- DeepDuh 14y agoThis reminds me of an anecdote from "The Codebook" from Simon Singh (highly recommended book btw.). One of the reasons, why the British could crack the Enigma code, was that German officers introduced rules on how to use the system. For the Enigma machines they had to choose three out of five cylinders in different positions. The officers thought it would be more secure if they impose a rule "never use the same cylinder in the same position the next day".
- CurtMonash 14y agoIf a system has sufficiently crazy password rules, I'm sure to forget the password, and default to the password reset system.
- pbreit 14y agoCan someone convince me that password requirements add _any_ value to the matter?