6 ms·
Your password must be between 8 and 12 characters, and must have lowercase, uppercase, numbers, and punctuation. Pick up the can!
by empyrrhicist 8mo ago
Your password must be between 8 and 12 characters, and must have lowercase, uppercase, numbers, and punctuation.
Pick up the can!
- barbazoo 8mo ago> Pick up the can! Gotta admit, this triggered me. I don’t think those are the same thing. If no one had a good password we wouldn’t affect each other negatively. If no one picked up trash, we would. Edit: Sorry folks, didn’t get the reference.
- smlavine 8mo agoIt's a Half-Life 2 reference: https://www.youtube.com/watch?v=nJshjMyg6no https://www.youtube.com/watch?v=nJshjMyg6no
- estebank 8mo agoI'm pretty sure it's referencing Half-Life 2, where an agent of an oppressive regime tells you to pick up a can that they just dropped on the floor as a sadistic display of authority (and to provide world-building and teach the grab mechanics to the player). The GP is equating policies for strong passwords that aren't trivially cracked with authoritarianism. If no one had a good password, we actually would affect each other negatively. If your personal banker can be easily compromised, that means that you could be easily parted with your money. I do agree that they are not the same thing.
- empyrrhicist 8mo ago> The GP is equating policies for strong passwords that aren't trivially cracked with authoritarianism. Incorrect - the requirements I mentioned make passwords less memorable and less secure (maximum length 12???). Obviously that's not as bad as authoritarianism, but I was trying to capture the arbitrary act being forced on us for no real justifiable reason.
- InitialLastName 8mo agoMy favorite is when it must have punctuation, but certain punctuation is silently banned, so I have to keep refreshing my password generator until it gives me an acceptable combination.
- abustamam 8mo agoSomewhat unrelated, is there any technical reason certain punctuation might be banned? I can understand maybe not allowing letters with diacritics or other NON-ASCII chars but why would a system reject an @ sign or bracket > for example?
- GoblinSlayer 8mo agoDepending on the protocol they can be url encoded or even helpfully html encoded; the same password can be used over different protocols. It's the best to not use punctuation by default (length supplies more entropy than charset), I add -0 at the end to make dumb password policies happy.
- InitialLastName 8mo agoOften, the same ones with limited punctuation also have length limits, so maximizing the character options is the only way to maximize entropy.
- abustamam 8mo agoThis is true, but I think the argument is that for maintainers of the system, it's more work to allow more char options when it (should be) more trivial to change MAX_PASS_LENGTH from 12 to 32. Like, if you're gonna add more restrictions, make it the ones that encourage, not block, more secure passwords.
- abustamam 8mo agoSorry I'm a bit lost here. Are you saying requiring a special character and a number are dumb password policies? Wouldn't charset AND length make for exponentially higher entropy? 52 (or 62 for digits) to the length power vs (62+20 special chars) to the length power? Or am I missing something?
- delta_p_delta_x 8mo agoHaving more than just alphanumeric characters widens the domain of the password hash function, and this directly increases the difficulty of brute-force cracking. But having a such a small maximum password length is... puzzling, to say the least. I would accept passwords of up to 1 KiB in length. With rainbow tables, even 11-character simple passwords like 'password123' can be trivially cracked, and as the number of password leaks show, not everyone is great at managing secrets and credentials.
- abustamam 8mo agoI recommend all my friends and family to use a password manager like Bitwarden, and if they can't do that for some reason, at least use a 3-word passphrase separated by a hyphen. The amount of times people have complained to me that this doesn't work because of low max-chars on passwords is insane.
- empyrrhicist 8mo agoOne time I had to reset my password with the power company - they had such a system, and the lady had to read me something like: Uh4zB4DP55WD! Apparently I was a bit salty with the system when I set it. The fact that she shouldn't have even been able to look up the password in the first place due to hashing was lost on her.
- abustamam 8mo agoThat's pretty funny on a few levels, not in the least that they required a "secure" password like that but stored them in plain text.
- raddan 8mo agoI regularly conduct transactions at the branch of my local bank wherein they ask me for no credentials whatsoever. I also once forgot to bring my account number with me and the teller said "no worries, I'll look it up for you." Kind of horrifying.
- abustamam 8mo agoHaha having such a low range of max chars just makes it that much easier to brute force doesn't it? On password length, I once had an account on Aetna that let me put whatever I want for my password, so I used a three-word passphrase that bitwarden generated for me. It ended up being like 20 chars. Then I tried to log in with that password. Whooosies, the password input only allowed max 16 chars! Ended up using a much less secure password because of this.
- empyrrhicist 8mo agoMaximum lengths like this are like a big neon sign that says: "Hey idiot, I'm storing your password in plaintext, don't know anything about password security, and I'm also going to make you pick something you can't remember for 'security'."