5 ms·
This may not have helped your specific case, but I recently bought 1Password, and updated all my security questions with randomly generated 16 character string
by ecoffey 14y ago
This may not have helped your specific case, but I recently bought 1Password, and updated all my security questions with randomly generated 16 character string answers, and just put those strings in the "notes" section of a website. So when they do challenge me I can just copy/paste them in. It's been awesome!
- unfletch 14y agoI've used 1Password generated passwords for years. You're right, it is awesome, but only until you have to relay one of those generated strings to a support person over the phone: "...left curly brace. No, it's like the parenthesis, but squiggly. Are you using a regular keyboard? Hold shift and type the left square bracket. The square one. It's to the right of the P..." Nightmare.
- kijin 14y agoI can't imagine the horror of having to recite any password to an actual human being. What kind of company asks you to tell them your password by phone? "No, the backslash. The one that leans backwards, no, I mean, to the left. Above the Enter key." Surprise, the backslash is not above the Enter key on Canadian bilingual keyboards.
- georgefox 14y agoI assume the support person is asking the security question, but the user entered his mother's maiden name as -K$%3{Tm,fsj$k8L or something similar.
- prawn 14y agoNo surprise to learn that she was quite keen to marry and be rid of it.
- unfletch 14y agoWhat kind of company asks you to tell them your password by phone? I don't remember for sure. I think it was a utility company.
- ecoffey 14y agoHeh, yeah luckily I haven't had to do that, but I have chosen some obscene answers to them, and then later had to recite, and spell them out to a horrified Indian call center worker.
- namityadav 14y agoI see why you had to mention that the call center worker was "Indian". If you hadn't, your entire statement wouldn't have made any sense. Right?
- shard 14y agoWell, the implied ethnicity of the poster is non-Indian, so in addition to the embarrassment of having to spell out obscene words, there's the cultural gap as well. The poster can't judge how offended the call center worker was, and probably feels like he's poorly representing his culture. I've had many similar experiences, especially since I've been living in Korea recently, and it's very uncomfortable not knowing exactly how big of a faux pas you committed.
- ecoffey 14y agoYes I'm non-Indian, and that was just a way to indirectly reference my culture and language gap with him.
- namityadav 14y agoMakes sense. Thanks to both of you for taking the time to clarify.
- prodigal_erik 14y agoIndian culture is pretty uptight in certain ways, and knowing that would make me feel a lot more guilty about making them uncomfortable. http://news.bbc.co.uk/2/hi/7871304.stm http://news.bbc.co.uk/2/hi/7871304.stm
- ecoffey 14y ago
- For_Iconoclasm 14y agoI use LastPass, but also use generated passwords to answer security questions. For these questions, one can enable the options for only using alphanumeric, unambiguous characters.
- r00fus 14y agoIt's a good point towards passphrases instead. 1Password gladly generates "pronounceable" passwords (e.g. "thax-lers-ponc-werv"). I usually think a bit about whether digits or symbols are required (some services and websites - Skype notably) don't like them. A 20-char passphrase with spaces, dashes, or character-based (e.g. "S") word-boundary delimiter is often good enough to provide excellent (80+ bits) entropy.
- aidenn0 14y agoEven better is to generate real words. I took a "1000 most common english words" list and reduced it manually to 256 that don't rhyme with other common words and now use that to generate pass-phrases. It's my best solution for English since phonetic spelling isn't a feature of English.
- TylerE 14y agoOr how about everybody that uses these fucking inane rules just do something sensible - like lock an account out if there are more than 5 failed logins in a row. Using a setup like that even "4321" is probably secure enough. Obviously use a secure hash on the backend as well.
- yuliyp 14y agoOK, let's do that. How long do you lock it for? What if it's a common email address? How can the real owner unlock it?
- jtheory 14y agoThat's the trouble... the "sensible" options aren't so sensible when you really sit down and think about how they can be dodged, broken or abused. Imagine I'm trying to crack into your site, and you lock any account after 5 failed logins in a row. If I have access to (or can guess) a few thousand usernames, I can try the 4 most common passwords on all of those with no problems. I'll probably get some hits, no? Or heck, I can try the 5 most common passwords, and not only will I have a few hits, I'll also have plenty of time to dig around without any attention from you, because you'll be struggling with a massive customer service nightmare, as thousands of your customers find themselves all locked out the same morning.
- dvhh 14y agoThe point being : you shouldn't transmit your password to anyone in any way possible ( especially on the phone ). for more relevant info google "hunter2"