3 ms·
Except it's not going to work, because of the bank who doesn't allow '(' as a special character, or the ticket website that requires at least 3 digits, or the f
by samspot 12y ago
Except it's not going to work, because of the bank who doesn't allow '(' as a special character, or the ticket website that requires at least 3 digits, or the financial firm who only allows 8 character passwords. As soon as you have a few sites with 'rogue' password policies, the system breaks down.
- gravedave 12y agoThere are ways around it: using the code for the key directly north-west of the problematic character, and if that's a bad character go further, maybe wrap around, or try to follow through the problem character (a/& -> &/| -> |/f, thus f would be the code for a) etc. As for remembering which sites have what restrictions, I can keep that stuff in my head (looking at you Microsoft), but I guess you may have more accounts than me. Then again, when a password fails, then all you'd have to do is retry with a safer version (and maybe only have two password kinds, for convenience - full-blown char support, and minimalistic lowercase-letters only, so you'd only have to retry a single time after the first failed login). Personally, my biggest problem with this card is that it doesn't provide enough value.
- cplease 12y ago> Then again, when a password fails, then all you'd have to do is retry with a safer version And after three or five failed login attempts you get locked out and have to call the bank for a password reset, and throw away the damn card in frustration. > (and maybe only have two password kinds, for convenience - full-blown char support, and minimalistic lowercase-letters only, so you'd only have to retry a single time after the first failed login). If you're authenticating with more than HN and Reddit, you'll encounter much more than two mutually exclusive password policies.
- danjayh 12y agoI tried going to a similar algorithm of my own invention some years ago, and ran into this exact problem. Mostly sites that don't allow certain characters (which is asinine). Now I have a few different algorithms that I use that are friendly to common password requirements, and I keep a list of which algorithm I used on each website, rather than just a list of the passwords. Since the algorithms only exist in my head, I think it's secure enough for most purposes.
- benmarks 12y agoYou are not alone in this strategy. I just wish we could have a password standard.
- bigbugbag 12y agoNah man, don't sweat it this case is thoroughly covered in their faq: you can petition those firms by tweeting them with #strongpasswords hashtag and @qwertycards. Yeah, qwerty card are badly thought out, they know of the shortcomings and they don't care much as they're in this business for the money.