Why the fuck do I have to change it every 30 days. You think I can remember that shit? I'm just going to write it down and keep it in my desk now! How safe is that?
And if you use a string of truly random characters, it either bitches that it's not secure enough, or gives a random error because it has some punctuation it doesn't like (even though it demands it).
Case sensitivity, numbers, special symbols, etc. only help against dictionary attacks anyway. Brute forcing treats all characters as the same. Not like that matters much, because data breaches of poorly secured servers and phishing attacks make all passwords a moot point, and those are the primary vectors of stolen passwords nowadays.
Multifactor identification helps a lot, but it can be a hassle.
This shit is what happens when project requirements are worded loosely enough for a developer's project manager to screw an upgrade purchase out of the client.
A great example is if the PROJECT requirement (as applied to the VENDOR) says passwords must be more than 8 characters. Regardless of what the client meant by that, the vendor can satisfy it by making all passwords exactly 9 characters and no more. Boom - project satisfied because 9 is more than 8.
Of course the project should have been worded to require that passwords must be at least 9 and must allow more than 9, where "passwords must be more than 8 characters" is an instruction from the developer to the user.
[ + ] RMGoetbbels
[ - ] RMGoetbbels 4 points 5 monthsDec 6, 2024 09:58:10 ago (+4/-0)
[ + ] Imsickofmakingusernames
[ - ] Imsickofmakingusernames 2 points 5 monthsDec 6, 2024 18:06:45 ago (+2/-0)
[ + ] 3Whuurs
[ - ] 3Whuurs 1 point 5 monthsDec 7, 2024 03:36:08 ago (+1/-0)
Side note.
Are these “1Password” type services worth while?
[ + ] RabbiKinderschtupper
[ - ] RabbiKinderschtupper 2 points 5 monthsDec 6, 2024 11:06:59 ago (+2/-0)
[ + ] 2Drunk
[ - ] 2Drunk 3 points 5 monthsDec 6, 2024 14:51:29 ago (+3/-0)
[ + ] Trope
[ - ] Trope 1 point 5 monthsDec 6, 2024 23:19:20 ago (+1/-0)
[ + ] Prairie
[ - ] Prairie 2 points 5 monthsDec 6, 2024 10:14:53 ago (+2/-0)
[ + ] x0x7
[ - ] x0x7 2 points 5 monthsDec 6, 2024 10:06:50 ago (+2/-0)
Maybe sites should worry more about their end of password management and let users do what they want.
[ + ] Rawrination
[ - ] Rawrination 2 points 5 monthsDec 6, 2024 13:10:04 ago (+2/-0)
[ + ] iSnark
[ - ] iSnark 2 points 5 monthsDec 6, 2024 08:57:23 ago (+2/-0)
[ + ] MuricaPersonified
[ - ] MuricaPersonified 1 point 5 monthsDec 6, 2024 17:52:58 ago (+1/-0)
Multifactor identification helps a lot, but it can be a hassle.
[ + ] Dingo
[ - ] Dingo 1 point 5 monthsDec 6, 2024 17:03:05 ago (+1/-0)
[ + ] SithEmpire
[ - ] SithEmpire 1 point 5 monthsDec 6, 2024 09:49:06 ago (+1/-0)
A great example is if the PROJECT requirement (as applied to the VENDOR) says passwords must be more than 8 characters. Regardless of what the client meant by that, the vendor can satisfy it by making all passwords exactly 9 characters and no more. Boom - project satisfied because 9 is more than 8.
Of course the project should have been worded to require that passwords must be at least 9 and must allow more than 9, where "passwords must be more than 8 characters" is an instruction from the developer to the user.
[ + ] GodsNotDead
[ - ] GodsNotDead 2 points 5 monthsDec 6, 2024 10:56:48 ago (+2/-0)
[ + ] germ22
[ - ] germ22 1 point 5 monthsDec 6, 2024 09:22:02 ago (+1/-0)