"…encourage your users to enter stronger passwords."
nakedpassword.com
nakedpassword.com
However, the concept of incentivizing the password entry field has inspired me. Instead of something risqué like nudity, how about offering a coupon off your first order (works for a commerce or service based site). Ie, as they type, gradually increase a % from 1 to 5 (or higher, what ever you're willing to offer).
IE, a progression like:
|asdf |
|asdf12 | %1 off first order coupon
|asdf12KL | %2 off first order coupon
|asdf12KL.!| %5 off first order couponYou're statement is a little confusing. All our passwords are munged with encryption, they all look like hash garbage. How could they differentiate?
My only guess is that perhaps you've interpreted my comment as a database entry, rather than a UI progression--and you think that "%1 off coupon" is stored with the login table. That clearly wasn't what I was saying--thats a poor design. I'm saying simply offer a coupon code to users if their password validates certain levels of difficulty. It doesn't need to be tied to the account in anyway.
Also, I think that at the point of my database being in the wild, I'd think hackers will be less focusing on cracking a stored password and more interested in trying to restore the encrypted payment details?
Ah, my assumption was that the entire DB was in the wild, and that every user had a unique discount code they could use once.
And why are you storing payment details, anyway?
(Good idea though)
What is with HN recently? I just do not understand why the uber-creep factor is out in force.
Even if the image set is replaceable and you dont' have to use a naked lady, that is the default demo, and the stated objective of the site is Strong Password == Naked Lady.
Aside from the blatant sexist targeting, this is trying to take advantage of entirely the wrong impulse. Associating a strong password with the human drive for porn doesn't actually encourage any better understanding of strong passwords or why they should be used.
If this were to be something like 'pwnyourpassword', and demonstrate how easy it'd be to crack your password w/ a dictionary attack, then this wouldn't be either as exploitative or crass.
Instead, the mechanism is, lets distribute pixel art of naked ladies to incentivize instead of teaching/demonstrating.
Yeah, that's the society i want to live in. :|
"betterpassword" -> "This password would take 15 seconds to crack"
"S89&;al(l_2z0Z¨" -> "This password would take 56 years to crack"
Security by fear?
Personally, I would make a list of the top 1k or 10k most common passwords and assign a very low number to them. Say, a few seconds max.
For any password that is not on the list, get the subset of characters used (upper+lower case, lower case+numbers, symbols+numbers, etc); raise it to the power of the password length to get number of possibilities; multiply by a random number (<= 100) and divide it by the FLOPS of a retail computer. Don't forget to display it at the nearest time unit (seconds, weeks, years).
Absolutely naive and a bit too rough around the edges, but good enough to send the message.
So, yes, "2tcUKstR" (which I've just generated with `openssl rand -base64 6`) is considered less secure than "Aa1!!".
Well, the good thing that they're just suggesting about password's quality, not enforcing it. It really pissed me off when one site declined to accept password and said it was "insecure" just because I was using base64, and (by chance) password did not contain any non-alphanumeric characters. I've also seen another site which rejected "/" in passwords, insisting on /^[A-Za-z0-9]$/ only.
Do you take offense at the fake "flies" they stick into urinals to focus men's attention?
I suspect the "naked lady" (which looks nothing like the real deal - I know, I have a kid) isn't so much the point here as the ability of a changing graphic to play the role of the aforementioned fly. I prefer the "discounts" idea raised elsewhere in the thread though.. a discount's more use to me than a heavily pixellated "babe" ;-)
Flagged.
72 ^ 5 = 1,934,917,632
Good luck brute-forcing that. 5 characters is plenty secure.
and yet:
clothed to naked with just "1!aAA" :|
so you clearly spent some time trying to get it to display the naked lady even after you knew what it was. creep.
Oh yes, there's a lovely false equivalency.
Figuring out what the mechanism for identifying strong passwords is != coding and posting the tool above.
I'm afraid I found this a bit confusing -- my initial thought was that more nakedness might be associated with vulnerability/exposure, and therefore indicate password weakness.
And aside from any sexism, making strong passwords NSFW might not have the desired effect.
Thomas nods.
"She gets up, grabs the bathroom key, and heads into the disabled/family bathroom. The one where you can get a lot of privacy. I use it to check on my Ashley Madison afilliate income. Anyhow, she stops at the door and gives me an unmistakable look. So I slip my laptop into my bag and follow her in."
Thomas licks his lips. George continues.
"The door closes. She pulls her shirt up over her head and I can see her breasts are bursting out of a lacy bra. She looks me straight in the eye and says the magic words: 'Take what you want.' So I did."
Thomas whistles in appreciation. "Good choice, the tee shirt was probably too small. So, have you got Parallels running on it yet?"
Can someone please explain what this is supposed to be...?
Sure, your shell account, bank website, ebay/amazon password should be very secure, secure to the point of not needing to be prompted, but does every site on the net, ie your blog, twitter, etc, need to have a min of 8 characters w/at least one number and one capital?
Oh, agree with everyone here on the creepiness factor here...
I really doubt they understood the possible consequences. Restricting is inacceptable, but warning against using seemingly-insecure password should be perfectly fine.
Correction: some punctuation does, but most don't.