Author Topic: short password = bad; long passphrase = good  (Read 4151 times)

0 Members and 1 Guest are viewing this topic.

Offline niffiwan

  • 211
  • Eluder Class
Re: short password = bad; long passphrase = good
Two factor auth is good & I recommend using it where you can, but it's still fallible unfortunately.  And I believe (although I can't find a link at the moment) that it's possible to intercept SMS's, or use social engineering on your Telco to transfer your number to a new SIM.
Creating a fs2_open.log | Red Alert Bug = Hex Edit | MediaVPs 2014: Bigger HUD gauges | 32bit libs for 64bit Ubuntu
----
Debian Packages (testing/unstable): Freespace2 | wxLauncher
----
m|m: I think I'm suffering from Stockholm syndrome. Bmpman is starting to make sense and it's actually written reasonably well...

 

Offline Klaustrophobia

  • 210
  • the REAL Nuke of HLP
    • North Carolina Tigers
Re: short password = bad; long passphrase = good
greeted by the following new asinine password requirements when logging in to check my pay stub today

The PASSWORD MUST:

    be 15 to 30 characters in length
    contain at least two uppercase letters (A-Z)
    contain at least two lowercase letters (a-z)
    contain at least two numbers (0-9)
    contain at least two of the following special characters: # @ $ % ^ ! * + = _
    change at least four characters from your previous password

The PASSWORD CANNOT:

    contain spaces
    be one of your last ten previous passwords

The PASSWORD will expire in 60 days.


the government is ****ing retarded.  thank you for guaranteeing i have to write down my password.  oh, and these are a completely DIFFERENT set of requirements from the four or five other various government websites i have to use regularly.
I like to stare at the sun.

 

Offline deathfun

  • 210
  • Hey man. Peace. *Car hits them* Frakking hippies
Re: short password = bad; long passphrase = good
What in the actual ****
All they're forgetting is security questions you have to answer each time you log on
Oh, and those also expire every 60 days
"No"

 

Offline niffiwan

  • 211
  • Eluder Class
Re: short password = bad; long passphrase = good
I've worked with (not at thankfully) companies that set the password expiry time to 30 days  :rolleyes:
Creating a fs2_open.log | Red Alert Bug = Hex Edit | MediaVPs 2014: Bigger HUD gauges | 32bit libs for 64bit Ubuntu
----
Debian Packages (testing/unstable): Freespace2 | wxLauncher
----
m|m: I think I'm suffering from Stockholm syndrome. Bmpman is starting to make sense and it's actually written reasonably well...

 

Offline Nuke

  • Ka-Boom!
  • 212
  • Mutants Worship Me
Re: short password = bad; long passphrase = good
twofactor can burn in hell with the rest of the internet. obligatory nuke all the things.

greeted by the following new asinine password requirements when logging in to check my pay stub today

The PASSWORD MUST:

    be 15 to 30 characters in length
    contain at least two uppercase letters (A-Z)
    contain at least two lowercase letters (a-z)
    contain at least two numbers (0-9)
    contain at least two of the following special characters: # @ $ % ^ ! * + = _
    change at least four characters from your previous password

The PASSWORD CANNOT:

    contain spaces
    be one of your last ten previous passwords

The PASSWORD will expire in 60 days.


the government is ****ing retarded.  thank you for guaranteeing i have to write down my password.  oh, and these are a completely DIFFERENT set of requirements from the four or five other various government websites i have to use regularly.

government websites in general suck. as a result i deal with the government entirely in paper. i like to use totally unreadable fonts, to match my equally unreadable penmanship. the best thing is no ****ing passwords. i particularly hate alaska's fish and game website. it never works. i have filled out my deer harvest reoprt for last year 3 times now, it says it goes through fine, but they still send be the yellow cards that say i didnt file it. only reason i didnt send paper was because i lost the form and couldnt find the pdf on the internet. so bomb the **** out of bureaucrats with actual bureaucracy.
« Last Edit: September 13, 2013, 07:43:41 am by Nuke »
I can no longer sit back and allow communist infiltration, communist indoctrination, communist subversion, and the international communist conspiracy to sap and impurify all of our precious bodily fluids.

Nuke's Scripting SVN

 

Offline The E

  • He's Ebeneezer Goode
  • 213
  • Nothing personal, just tech support.
    • Steam
    • Twitter
Re: short password = bad; long passphrase = good
The PASSWORD MUST:

    be 15 to 30 characters in length
okay

Quote
    contain at least two uppercase letters (A-Z)
okay
Quote
    contain at least two lowercase letters (a-z)
right
Quote
    contain at least two numbers (0-9)
makes sense
Quote
    contain at least two of the following special characters: # @ $ % ^ ! * + = _
I suppose
Quote
    change at least four characters from your previous password
wat

This raises so many questions regarding the implementation of the password query....
If they're using a sane system, said system must (not can, MUST) be unable to make that determination. So assuming they do, this is a requirement that humans have to execute, and can thus circumvent.
If they don't, if their password storage is so bad that this kind of thing can be verified automatically, well, you (and they) are ****ed, cos there's a hole in the security a mile wide.

Quote
The PASSWORD CANNOT:
    contain spaces
    be one of your last ten previous passwords

Again with the what. Must be unique across x iterations I can sort of understand, but cannot contain spaces? What kind of bull**** input routines are they using?

Quote
The PASSWORD will expire in 60 days.

Riiiiight
If I'm just aching this can't go on
I came from chasing dreams to feel alone
There must be changes, miss to feel strong
I really need lifе to touch me
--Evergrey, Where August Mourns

  

Offline Klaustrophobia

  • 210
  • the REAL Nuke of HLP
    • North Carolina Tigers
Re: short password = bad; long passphrase = good
---------- thought better of posting -----------

suffice it to say that the alternate logon method completely undermines the PW system anyway (but saves my ass from having to use it).  but i don't really need to go sharing details of that on the open internet.  :nervous:
I like to stare at the sun.