6 ms·
> It is unclear why generating a one-time password for the user is bad but if we call the password a "recovery code" it is suddenly sufficient. The OTP is usua
by wepple 2y ago
> It is unclear why generating a one-time password for the user is bad but if we call the password a "recovery code" it is suddenly sufficient.
The OTP is usually very long, highly randomized (you don’t get to choose Summer2024!), and designed to be stored offline somewhere as a break glass. Passwords typically follow none of those rules.
- tomsmeding 2y ago> highly randomized (you don’t get to choose Summer2024!) Sure. > designed to be stored offline somewhere as a break glass. That's fair. > The OTP is usually very long, No, 10 digits is not very long, that's just 10^10 (about 2^33). The xkcd password ( https://xkcd.com/936/ https://xkcd.com/936/ ) is better than that. It's better than Summer2024 perhaps, but not all that much better.
- smcnally 2y agoThe xkcd password requires the use of spaces as legal characters. For some reason, this is still an issue with the majority of orgs with complex password requirements.
- Feathercrown 2y agocorrecthorsebatterystaple isn't much worse
- hinkley 2y agoI practically see red when they tell me I can’t use spaces in my password. What kind of clown car are you idiots running over there?
- bigfatkitten 2y agoI worked for a government agency who banned @, because it would SQLi and break their Oracle-based LOB apps when you logged on and when they synced your password in the clear.
- wepple 2y agoSorry, when I said OTP I mean the recovery code OTP. They’re often 16 hex, so 16^16
- semiquaver 2y ago> Summer2024! wait, how do you know my pw?
- Ferret7446 2y agoAlso, recovery codes can only be used once, and every usage triggers a notification to the user and potentially a signal for internal risk analysis systems.