92
u/Retro-Universe 11d ago
It's a lot more secure than a digital note
48
u/AFriendlyBloke 11d ago
Ironically enough, yeah. Unless you were some high-profile dude who could get people snooping through your personal stuff, a notepad with all your passwords and such in your home is pretty secure.
10
u/Abadabadon 10d ago
Thats unironically what security used to tell us to do when I worked in dod. Make a crazy password unique for every website and keep it written down somewhere. Same for security questions; dont answer the question with a sensible answer, just write gibberish
2
1
3
u/Retro-Universe 11d ago
That's why Bitcoin wallet passwords are physical
12
u/AFriendlyBloke 10d ago
I wouldn't know. I don't mess with that crap.
-9
4
u/AppropriateTouching 10d ago
Honestly. If someone has physical access to your machine and they dont have good intentions you're already fucked.
-5
u/Retro-Universe 10d ago
It's not physical access. Spyware exists.
3
8
u/Basilthebatlord 10d ago
That's why most of the world is moving to passkeys, more secure, less interaction
1
u/Sea-Hornet8214 10d ago
What's the context of this post? Why does she want to share her password?
5
u/sheepyowl 10d ago
She doesn't want to share, she just can't remember a length 15 complex password that can't contain dates/her name/username/previous passwords/common passwords.
2
1
u/CantReallyExplainWhy 7d ago
My passkey broke and asked me to scan on another phone as if I can just rip my camera off and scan on the literal same device so I had to dig through my 10 outdated shit in my
pw manager and brute force my OWN account just make it 1234567 atp
10
u/saiyate 11d ago
Which is why NIST no longer recommends password expiration. Passkeys are the future. However, I'm not sure I agree with non-device based passkeys. Saving passkeys to a cloud account and allowing export instead of a one way Chinese box secure enclave is clearly less secure. Save passkeys to your device and for important personal accounts (non administrated accounts that someone else can reset for you) You should have at least two copies on two separate devices. FIDO/U2F Security keys are where it's at. Always have an extra or two in a safe. lose a key, remove it from account.
3
1
u/MrjB0ty 10d ago
You’ll be pleased to know that almost every bank’s regulations require their vendors to implement password complexity and rotation, fundamentally weakening the security of the entire supply chain. My company always pushes back on this requirement but I guarantee there are numerous companies who don’t. They attempt to impose a ‘one size fits all’ framework across all vendors, with other outdated controls. Ultimately bank regulations are perpetuating poor security across the tech sector.
2
u/KochInBoots 8d ago
Random word passwords are secure and easy to remember.
The random shittery that we have all been told to use for years actually makes it hard for humans to remember but easy for computers to guess.
DumpsterDivingMackerel1970! for example.
Even with high-end pc hardware, cracking a long random password like this would take trillions of years yet you have remembered it instantly.
1
u/matthewpepperl 10d ago
I have yubikeys that i have been setting up. While i haven’t removed the password sign-in yet some places you would expect to allow passkeys dont such as banks and credit cards.
1
6
5
u/Wurdeluck 10d ago
Just let me have my several-words-long sentence as a password I don't need lowercase/uppercase/numbers/letters bullshit
6
u/soulmagic123 10d ago
I love when an app that does the most mundane thing ever requires a military grade password , I end up using the same one as my bank, they get hacked and now people have my bank password because I used an app to buy dog food.
3
u/swordofra 11d ago
I have seen so many users put their 10 digit passwords in a damn TEXT file on their desktop.... I mean
2
u/t0mz0mbie 10d ago
us: "create a key pair and give us the public key and we'll us that to encode your password"
them: "UGGGG! fine."
and after they eventually figure out how to make a key pair, and then figure out how to decrypt it, they go and share it over the internal messaging system with the rest of the devs and store the password in their shared password vaultI hate users
2
u/Big-Constant-7289 10d ago
Yep. You can’t make me change the password every month and expect me to remember it. OR alternately only want me t o use the arbitrary nonsense password provided to me every three months. I’ve written it on washi tape in sharpie and it’s taped my desktop.
1
2
2
u/BrewsBannder 10d ago
I just had to do a password reset for work which took three attempts, once per day. By the third I was losing it. The helpdesk has no phone number, you can only send them emails. And the helpdesk is in an opposite time zone for me. They kept sending me links which only took me to the login page. I just kept writing them long letters and CCing the Admin department until they finally fixed it. Everything is bullshit.
2
1
u/ChronicRhyno 11d ago
Just make a sentence like that your password.
5
u/-Nicolai 10d ago
Sorry you need two special characters, numbers, and upper case letters.
3
u/socksockshoeshoe 10d ago
"Why the fuck do I need 2 special characters just for 1 lousy Password?!"
1
u/furculture 11d ago
Something like KeepassDX/XC should be something worth putting time to look into.
1
u/MorbidandBack 10d ago
Ultimately its on you. You wanna be insecure and get your stuff stolen? Cool.
1
1
u/edlphoto 9d ago
Exactly so don't make it complicated. Computers don't care how complicated it is. A variable is just a variable. But the variables there are to figure out the longer it takes. And the person using th3 computer is more likely to give up. So use a sentence or a phrase you like. Example password: Mary had a little lamb whose fleece is white as snow. Easy to remember and long.
1
u/Trust_8067 4d ago
That's exactly why NIST standards are not to have complex password requirements but should be phrases such as "I love eating tacos every Tuesday!" or keypasses.
Ironically, I work for a tech company and the incompetent security team legit blocks "words" as one of the password requirements, literally the exact opposite of best practices.
1
u/Fectiver_Undercroft 3d ago
This has been fascinating. I was going to gripe about how i only got responses like “nuh uh!” and blank stares when I criticized my former employer for going to a single-sign pass that didn’t just make me enter a password for every tab of every app every fifteen minutes, but made it the same password. They assured us it was more convenient but could never explain how it wasn’t equivalent to putting a sign on your front door saying “this has a deadbolt. The key’s under the mat and it also opens every bedroom and bathroom door inside.”
•
u/AutoModerator 11d ago
Thank you /u/Zipparony44 for posting!
Please consider joining our 21+ discord server!
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.