Poll of the Day > FML, My company is now requiring all passwords be EIGHTEEN DAMN CHARACTERS LONG

Topic List
Page List: 1
hypnox
03/28/22 7:37:25 PM
#1:


PLUS we have the stupid policy of passwords being changed every 90 days.... Looks like I will be one of those people with passwords freaking written down now.

---
http://media.tumblr.com/tumblr_m0ajm6lGqf1qekkfi.gif
... Copied to Clipboard!
Joshs Name
03/28/22 7:40:21 PM
#2:


I prepend the month and year in front of all my passwords and just rotate it every month. easy to remember and it's enough unique characters to stop it getting picked up. it's also good if you come back from like 3 weeks holiday and you only have to remember what month you set your password

ie 0322xxxxxxxxxxxx

idgaf if someone can guess my work pw tbqh so i don't really keep the prepend info a secret

---
So I was standing still at a stationary store...
... Copied to Clipboard!
ReturnOfFa
03/28/22 7:48:13 PM
#3:


welcome to security. just have a notebook, and you'll remember the password quickly enough

---
girls like my fa
... Copied to Clipboard!
slacker03150
03/28/22 7:49:03 PM
#4:


It was the best of timesIt was the worst of times!1

Mr. and Mrs. Dursley of number 4, Privet Drive, were proud to say that they were perfectly normal, thank you very much.

---
I am awesome and so are you.
Lenny gone but not forgotten. - 12/10/2015
... Copied to Clipboard!
jsb0714
03/28/22 7:51:54 PM
#5:


So all of a sudden TC can't remember a phrase? Guess I can't say I'm surprised.
... Copied to Clipboard!
dragon504
03/28/22 7:54:00 PM
#6:


passwordpasswordpassword, there you go, 24 characters long can a random number and uppercase letter to make it more secure

---
http://myanimelist.net/profile/dragon504
http://followmy.tv/u/dragon504/time_wasted
... Copied to Clipboard!
AndyReklaw
03/28/22 8:01:19 PM
#7:


mypasswordis______

And then you only need a 6 character password.

---
This user is awesome!:
https://gamefaqs.gamespot.com/user/gamefaqs-user?account=12351915135
... Copied to Clipboard!
KodyKeir
03/28/22 8:03:53 PM
#8:


hypnox posted...
policy of passwords being changed every 90 days

Only 90 days, that's not too bad, and at eighteen characters it likely keeps all but a state actor from hard cracking it.

Think up a nonsense phrase and replace some of the letters with numbers l33t h4ck3r style, something like:

1und3r5t4ndy0umr45p4r4gus

Also, if you are inconsistent with what letters you replace with numbers, it becomes harder to crack even if someone does find your nonsense phrase.

I no longer have to deal with that but my personal passwords are all generated from a personal pass phrase that creates an unique and indecipherable alphanumeric string at the desired length for each login I use; I don't think I actually know any of my passwords :P

---
Why didn't you DODGE‽‽‽
Quoting me will trigger the profanity filter, Not Joking. I've been Scunthorped! Consider yourself warned.
... Copied to Clipboard!
shadowsword87
03/28/22 8:10:52 PM
#9:


KodyKeir posted...
Only 90 days, that's not too bad, and at eighteen characters it likely keeps all but a state actor from hard cracking it.

Think up a nonsense phrase and replace some of the letters with numbers l33t h4ck3r style, something like:

1und3r5t4ndy0umr45p4r4gus

Also, if you are inconsistent with what letters you replace with numbers, it becomes harder to crack even if someone does find your nonsense phrase.

I no longer have to deal with that but my personal passwords are all generated from a personal pass phrase that creates an unique and indecipherable alphanumeric string at the desired length for each login I use; I don't think I actually know any of my passwords :P

This is stupid.
... Copied to Clipboard!
ParanoidObsessive
03/28/22 8:12:21 PM
#10:


hypnox posted...
My company is now requiring all passwords be EIGHTEEN DAMN CHARACTERS LONG

Most of mine are pretty close to that as-is. The real problem is if they require them to be strings of fully nonsense rather than actual words or things you can use mnemonics for.

Like, say, using the Ring verse from Tolkien (Three Rings for the Elven-kings under the sky, Seven for the Dwarf-lords in their halls of stone...), and then turning that into "TRftEkunsSftDlithos". That's a pretty complex password, but also one that's relatively easy to remember as long as you remember what the "key" is.



hypnox posted...
PLUS we have the stupid policy of passwords being changed every 90 days.... Looks like I will be one of those people with passwords freaking written down now.

The irony, of course, being that when you write your password down, it increases the risk that someone else can physically find it, steal it, or copy it (or you can just lose it), thus compromising security more than just having an easy to remember one.

That being said, a lot of this depends on just how important access to your work account is. I'd rather have rigorous security for someone working in a major bank, maybe less so for someone doing stock management data-entry for Wal-Mart or something.

---
"Wall of Text'D!" --- oldskoolplayr76
"POwned again." --- blight family
... Copied to Clipboard!
HornedLion
03/28/22 8:19:13 PM
#11:


Aintnobodygottimeforthat69!

---
Century: Age Of Ashes is the greatest dragon riding game to ever exist and it's FREE.
... Copied to Clipboard!
Dikitain
03/28/22 8:27:30 PM
#12:


Changing password every 3 months has been a standard at my company for years now (although we only require 15 characters). However, they only require one character difference and the password only has to be different then the last 10 passwords, so just +1 a random digit in the password and you are good to go.

Also, the password is used for every account, including our "password vault" that randomly generates a 40 character password you use for database access every 24 hours.

---
After 16 years, I have decided my signature will NOT be about my job! But I still don't know what to put here so...yea...
... Copied to Clipboard!
Metalsonic66
03/28/22 8:39:58 PM
#13:


Use a phrase from a song you love

---
PSN/Steam ID: Metalsonic_69
Big bombs go kabang.
... Copied to Clipboard!
Sahuagin
03/28/22 9:23:00 PM
#14:


correct horse battery staple

---
The truth basks in scrutiny.
http://i.imgur.com/GMouTGs.jpg http://projecteuler.net/profile/Sahuagin.png
... Copied to Clipboard!
LinkPizza
03/28/22 9:34:54 PM
#15:


Im the military, wed use:

!QA@WS#ED1qa2ws3ed

For the next 90 days, you could either do:

1qa2ws3ed!QA@WS#ED

Or

@WS#ED$RF2ws3ed4rf

Whatever floats your boat

---
Official King of Kings
Switch FC: 7216-4417-4511 Add Me because I'll probably add you. I'm probably the LinkPizza you'll see around.
... Copied to Clipboard!
Judgmenl
03/28/22 9:50:43 PM
#16:


I don't see why this is an issue in the era of auto-generated passwords.

---
You're a regular Jack Kerouac
Not removing this until I've left March 2020.
... Copied to Clipboard!
joemodda
03/28/22 9:53:53 PM
#17:


My password is out of the ___

---
It's not genocide... it's pesticide...
... Copied to Clipboard!
Joshs Name
03/28/22 11:01:28 PM
#18:


Judgmenl posted...
I don't see why this is an issue in the era of auto-generated passwords.

The 1st problem would likely be trying to unlock or cold boot your work PC for the first time and you can't log in because you need a password. auto-generated password doesn't help with this problem and creates a new one of trying to copy it from your phone or somewhere else.

---
So I was standing still at a stationary store...
... Copied to Clipboard!
KodyKeir
03/28/22 11:27:14 PM
#20:


Joshs Name posted...
cold boot your work PC for the first time

Back when I worked at the phone company, we had keyboards with built in chip readers, just slide your employee id in and you were logged in. I don't think anyone actually used the function though...

---
Why didn't you DODGE‽‽‽
Quoting me will trigger the profanity filter, Not Joking. I've been Scunthorped! Consider yourself warned.
... Copied to Clipboard!
hypnox
03/28/22 11:31:23 PM
#21:


KodyKeir posted...
Back when I worked at the phone company, we had keyboards with built in chip readers, just slide your employee id in and you were logged in. I don't think anyone actually used the function though...

My last job had biometric scanners. Loved that so much.

---
http://media.tumblr.com/tumblr_m0ajm6lGqf1qekkfi.gif
... Copied to Clipboard!
KodyKeir
03/28/22 11:41:13 PM
#22:


hypnox posted...
My last job had biometric scanners. Loved that so much.

My current laptop is government surplus so it has that option, was great at first but I find I have to clean the sensor constantly and even then it's still a little wonky but I chalk that up to it being an early gen model.

---
Why didn't you DODGE‽‽‽
Quoting me will trigger the profanity filter, Not Joking. I've been Scunthorped! Consider yourself warned.
... Copied to Clipboard!
Karovorak
03/29/22 3:07:17 AM
#23:


Just to explain why some security guys think this is usefull:

The biggest threat is always using the same password.

You used your mail and password for cheapsite.com and cheapsite.com got hacked and didn't secure the password as it should? good job, your combination of mail + password is now totally insecure, no matter how strong the password was.

Happend to me too, using my spam mail (for sites I don't give a f) and most used password (for sites I don't give a f) on a site, and it got hacked. Years later, I created a Ubisoft account because I needed one for some game and...

It got hacked in under 2 hours. Because the mail+password in clear text was leaked and part of some hacker database, automatically attacking everything 24/7.

So, IT security wants to make sure that people don't use their company passwords multiple times in private use.

Sadly, the approach is always long passwords and changing it every time. That ensures that you will never use this password privatly. But the result is usually pretty lazy passwords, or passwords writen down next to the desk, INCREASING the risks.

In my old company, we had to change the password every month.

I swear, I'm sure you could hack 10% of all employees with trying "January2022" or similar passwords.
... Copied to Clipboard!
Judgmenl
03/29/22 5:10:24 AM
#24:


Joshs Name posted...
The 1st problem would likely be trying to unlock or cold boot your work PC for the first time and you can't log in because you need a password. auto-generated password doesn't help with this problem and creates a new one of trying to copy it from your phone or somewhere else.
Well this is solved by not using company-provided hardware.
Actually, my work laptop runs Linux as well.
But yes, my post was kinda lame and didn't consider the obvious that most companies are entirely entrenched in the Microsoft environment and have actual IT departments and whatnot.

---
You're a regular Jack Kerouac
Not removing this until I've left March 2020.
... Copied to Clipboard!
captpackrat
03/29/22 5:40:40 AM
#25:


Qwertyuiop!@#$%^01

Assuming you need upper & lower case letters, numbers, and symbols. And every time you have to change your password you just increment the number. Qwertyuiop!@#$%^02, Qwertyuiop!@#$%^03, etc

---
Minutus cantorum, minutus balorum,
Minutus carborata descendum pantorum.
... Copied to Clipboard!
captpackrat
03/29/22 5:52:16 AM
#26:


Back when I worked at the phone company, we had keyboards with built in chip readers, just slide your employee id in and you were logged in. I don't think anyone actually used the function though...
I liked the way they did it at the Corps of Engineers. You insert your CAC (Common Access Card) into the slot on the laptop or the keyboard, then type in a PIN. Boom, two-factor authentication! Can't log in without the card, can't use the card without the PIN.

Just be careful, entering the wrong PIN just 3 times locks the CAC and it can only be unlocked by going to a RAPIDS office and submitting all kinds of ID & fingerprints.

---
Minutus cantorum, minutus balorum,
Minutus carborata descendum pantorum.
... Copied to Clipboard!
Gaawa_chan
03/29/22 5:52:17 AM
#27:


I often pick a piece of media that has recently been announced or come out around the time I need to change my password and then pick a date and then put an exclamation point on the end or something. Most video game titles, for example, have both capital and lowercase letters and sometimes numbers in them.

---
Hi
... Copied to Clipboard!
11110111011
03/29/22 5:58:32 AM
#28:


I DGAF anymore. I have my passwords in a text file in my user directory storage. Not only do I have to change passwords, they have to be 16 characters with a letter, number & special character, but I can't use the last 6 passwords. I don't remember that far back anymore, so I just keep a log and rotate through them.

If anyone saw it they would have a heart attack - but after a day of forgetting my password after I changed it - it just isn't that important anymore in my eyes.
... Copied to Clipboard!
#29
Post #29 was unavailable or deleted.
Solid Sonic
03/29/22 7:04:43 AM
#30:


Yeesh. I have a rotating password that's 17 characters long but that wouldn't even work.

I think at that point your company should consider alternative verification methods than simple password complexity (such as 2FA).

---
Sometimes it's necessary to make people miserable, even if that means making yourself miserable in the process.
... Copied to Clipboard!
Lynyrd_Skynyrd
03/29/22 7:39:32 AM
#31:


AndyReklaw posted...
mypasswordis______

And then you only need a 6 character password.
You're an absolute genius
... Copied to Clipboard!
MechaKirby
03/29/22 8:15:03 AM
#32:


PolloftheDayhypnox

18 characters

---
GTag/PSN: MechaknightX [] Switch ID: SirMecha [][]
'Cloud, this isn't a normal reactor! It's the Chemical Plant Zone'
... Copied to Clipboard!
Joshs Name
03/29/22 5:31:41 PM
#33:


Judgmenl posted...
Well this is solved by not using company-provided hardware.
Actually, my work laptop runs Linux as well.
But yes, my post was kinda lame and didn't consider the obvious that most companies are entirely entrenched in the Microsoft environment and have actual IT departments and whatnot.

Super agree. I only remember vividly because my last company was locked down like this. 2mfa, 18 character rotating password, every time you even locked your pc.

---
So I was standing still at a stationary store...
... Copied to Clipboard!
LinkPizza
03/29/22 6:01:58 PM
#34:


captpackrat posted...
I liked the way they did it at the Corps of Engineers. You insert your CAC (Common Access Card) into the slot on the laptop or the keyboard, then type in a PIN. Boom, two-factor authentication! Can't log in without the card, can't use the card without the PIN.

Its not bad Until youre locked out on an off shift. Some bases have personnel 24/7, and some had a person in squadron who could do it My base has neither So, if youre locked out on an off shift, youre just screwed That said, so many people had other peoples pins that it was almost pointless to have them. Haha.

---
Official King of Kings
Switch FC: 7216-4417-4511 Add Me because I'll probably add you. I'm probably the LinkPizza you'll see around.
... Copied to Clipboard!
Jen0125
03/29/22 6:20:18 PM
#35:


Make it literally say eighteencharacters
... Copied to Clipboard!
Revelation34
03/31/22 12:07:56 PM
#36:


I remember one website telling me my password was too long.

---
Gamertag: Kegfarms, BF code: 2033480226, Treasure Cruise code 318,374,355, Steam: Kegfarms
... Copied to Clipboard!
badjay
03/31/22 12:21:38 PM
#37:


shadowsword87 posted...


This is stupid.

https://gamefaqs.gamespot.com/a/user_image/7/6/1/AABn_6AADFc5.png

Seems like they follow this method, which isn't TOO bad. The only part is the inconsistent leet code changes. That'll make it probably in the realm of hard to remember rather than easy. The point is to prevent brute force hacking, not social engineering hacking, where someone makes assumptions how people change letters into leet language.

---
[05:45:34] I bought an American L and it was like a tent
... Copied to Clipboard!
The_Viscount
03/31/22 4:18:35 PM
#38:


I use phrases at times but they're original combinations and, honestly, I frequently forget them.

---
Woken LLC
... Copied to Clipboard!
Topic List
Page List: 1