Man who made passwords hard regrets rules that 'drive people crazy'
cbc.ca
cbc.ca
One requires a symbol, another doesn't allow symbols. A third requires 12 characters, a fourth only allows 8.
And they only tell you the rules when you're creating a password. They could at least remind us of the rules so we could remember how we had to mangle the password to match.
And of course, why would the site tell the user of its obscure symbol requirements before the user tries to enter their brand new password? No, I guess they think it's better to leave it at "a symbol is required" and then reject symbols users use one-by-one.
1Password and LastPass et. al. could read this rule and then adjust the password generator accordingly.
It doesn't make sense to limit special characters, etc. Especially as everyone should be using a password manager anyways. I suspect most of these odd requirements are a result of design by committee and pointy haired bosses. Maybe requirements from legal departments?
As long as the annoying requirements are in place, we might as well try and get password mangers to work with them. LastPass has a generator which can be manually configured, but making the step automated would be helpful.
What does "very high" mean here? And why would you need it? Usually, you just have a maximum request size in the web server, and people are never going to hit that with actual passwords.
I just generate a long alphanumeric password and then manually throw in a few symbols.
India's pension system (kind of similar to 401k, you contribute monthly, you get pension monthly after 60) (eNPS (national pension system))[https://cra-nsdl.com/CRA/] does this. At initial signup, it helpfully tells max length is 14 chars. You need to change password every 3 months. So, i added a 1 behind keepass generated password. It said success. Error at login. Somehow i tried with earlier password. It went in, but said change password as its 3months old.
If you are randomly generating the password anyways, I'm pretty sure allowing full UTF-8 will decrease the entropy since there are more wasted bits. I could be wrong, and I am too lazy to run the computation at the moment. Moreover, a randomly generated UTF-8 password will almost certainly contain characters that are difficult for the user to type.
For example, on Mac I can easily enter Unicode from the keyboard by enabling hex unicode input (at least for Unicode up to U+FFFF...have to use surrogates to get past the BMP).
On my Windows desktop there is a similar option, with one annoying limitation: it requires using the numeric keypad. That's fine on my desktop system. It has a keyboard with a numeric keypad. It sucks on my Surface Pro 4. Both the real and the virtual keyboards there lack a numeric keypad. There are other options for Unicode on the SP4, but they are quite annoying.
If the site is an audio or video streaming site or a social media site or a photo sharing site then they might also be worried about people who will want to use them from their TV, A/V receiver, cable box, DVR, or Blu-ray player, all of which nowadays often provide network access and apps for various media services and social media sites. I don't think any of mine have a way to enter arbitrary Unicode from their clunky on-screen keyboards.
Speaking of TVs, cable boxes, etc., I wish sites would think more about those when setting password requirements. It is often cumbersome and slow to switch between lower case and upper case, or between letters and punctuation, or between alpha and numeric when using an onscreen keyboard via a remote control when all you've got is up/down/right/left for navigation.
I'd rather use a 21 character password using [a-z] or a 29 character password using [0-9] than use a 16 character password using, say, [a-zA-Z0-9!@#$%^&+:;].
Best, though, is to make it so you don't need to enter passwords on these devices to pair them with your services. I don't remember which service it was but I've seen one that handled it something like this.
1. You go to the website for their service and log in. On the website you can tell it you want to enable your account for their app on your device, and you give the device model and serial number. The website gives you a temporary PIN.
2. You go to the device and tell their app you want to enable your account. The app asks for the PIN then talks to the web service. The app and the web service can then set up everything for you.
As a software developer, I'm okay with that being criminal negligence.
I am still curious if this would be a criminal offense for the person that did the SQL injection attack.
Explaining to interrogating officers that you hated password forms and wanted revenge would be 1 to 5 years in federal prison (better than state). Explaining to interrogating officers that you accidentally copy pasted wrong - the case would be dropped. This is why you need see a lawyer always before answering questions you will be mislead.
"intentionally accesses a computer without authorization or exceeds authorized access" [1] https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act
Microsoft online service incl (based still on the decades old 1997's Hotmail login system is archaic) has an upper limit of 8 (or so) chars. (Office365/Outlook.com/etc)
I thought it was used because 7-bit ASCII had only 128 code points in which to fit all teletype controls, letters, numbers, and punctuation marks and symbols. They had to use each code point efficiently, and the ASCII double quote can be used as open quotes, close quotes, seconds, inches ... they also needed to support some European alphabets and therefore some punctuation marks, such as the single quote, double as accents when overtyped (using teletype control code points) on a letter.
I distinctly recall seeing somebody post a comment a few years ago -- I think it was here on HN, though I'm not sure -- to the effect that they had used a line from an obscure poem in Afrikaans as a password, and it was cracked. -- Oh! HN Search comes through for me: here's a recent HN comment [0] by someone who also recalled it, with a link to the original [1].
[0] https://news.ycombinator.com/item?id=14781311
[1] https://www.reddit.com/r/Bitcoin/comments/1ptuf3/brain_walle...
Tonight I was dealing with Wells Fargo for a password reset. They have a max of 14 characters and a generally awful interface. I took screenshots of the process to use as a guide of things to avoid.
Doesn't even have to be strong, could be one word from the top 10k English words. Require reset after 5 failed attempts.
Would there be anything wrong with this approach (besides being sort of user-hostile), or have I misunderstood the website account security threat model?
It's caused our most common passwords to be things like Summer17 and half the employees that actually use what they think are hard random passwords end up writing them down.
If you look under the keyboard if 100 workstations you'll probably find 10 passwords on post-its.
It makes little sense too because if we're compromising for 3 months we're probably going to be just as fucked as if we were compromised for 4.
The best policy we have is locking people out after 3 wrong attempts.
In general, every two random characters is worth as much as one random word. I personally find it as easy to remember three random characters as a word, so I get better mileage out of random characters.
Rotation is great if it's implemented correctly. The problem is that it's too much of a burden on users, therefore they implement it poorly, and then it's less useful or a weakness.
The rules, if used properly, work perfectly. But using them properly is burdensome, which means most people get lazy and the result is insecure passwords.
There are about 95 letters, numbers, and punctuation marks and symbols. If you choose a 12 character random password, it's uncrackable by brute force. The problem is, few people want to choose and remember a 12 character random password, and fewer will do that for each of the dozens of passwords they must use, so they choose insecure, non-random passwords.
edit: for those who down-voted, one of the most famous comedians in the US at the moment is also named Bill Burr.