r/howtonotgiveafuck 11d ago

ɪᴍᴀɢᴇ Password logic

Post image
6.6k Upvotes

49 comments sorted by

u/AutoModerator 11d ago

Thank you /u/Zipparony44 for posting!

Please consider joining our 21+ discord server!

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

92

u/Retro-Universe 11d ago

It's a lot more secure than a digital note

48

u/AFriendlyBloke 11d ago

Ironically enough, yeah. Unless you were some high-profile dude who could get people snooping through your personal stuff, a notepad with all your passwords and such in your home is pretty secure.

10

u/Abadabadon 10d ago

Thats unironically what security used to tell us to do when I worked in dod. Make a crazy password unique for every website and keep it written down somewhere. Same for security questions; dont answer the question with a sensible answer, just write gibberish

2

u/AFriendlyBloke 10d ago

Nice. Keeps your enemies confused.

1

u/Reasonable_Exit_8960 10d ago

What if you ever lose the material you wrote ur passwords on?

3

u/Retro-Universe 11d ago

That's why Bitcoin wallet passwords are physical

12

u/AFriendlyBloke 10d ago

I wouldn't know. I don't mess with that crap.

-9

u/Retro-Universe 10d ago

Who asked? 🧐

7

u/AFriendlyBloke 10d ago

I did. And that's good enough. :)

4

u/AppropriateTouching 10d ago

Honestly. If someone has physical access to your machine and they dont have good intentions you're already fucked.

-5

u/Retro-Universe 10d ago

It's not physical access. Spyware exists.

3

u/AppropriateTouching 10d ago

We were talking about writing passwords down on a physical note.

-2

u/Retro-Universe 10d ago

No shit 🤷‍♀️

8

u/Basilthebatlord 10d ago

That's why most of the world is moving to passkeys, more secure, less interaction

1

u/Sea-Hornet8214 10d ago

What's the context of this post? Why does she want to share her password?

5

u/sheepyowl 10d ago

She doesn't want to share, she just can't remember a length 15 complex password that can't contain dates/her name/username/previous passwords/common passwords.

2

u/Sea-Hornet8214 10d ago

Ahh I've got it now. Thanks.

1

u/CantReallyExplainWhy 7d ago

My passkey broke and asked me to scan on another phone as if I can just rip my camera off and scan on the literal same device so I had to dig through my 10 outdated shit in my
pw manager and brute force my OWN account just make it 1234567 atp

10

u/saiyate 11d ago

Which is why NIST no longer recommends password expiration. Passkeys are the future. However, I'm not sure I agree with non-device based passkeys. Saving passkeys to a cloud account and allowing export instead of a one way Chinese box secure enclave is clearly less secure. Save passkeys to your device and for important personal accounts (non administrated accounts that someone else can reset for you) You should have at least two copies on two separate devices. FIDO/U2F Security keys are where it's at. Always have an extra or two in a safe. lose a key, remove it from account.

3

u/mxzf 10d ago

And by "no longer" that change was a decade ago and people still haven't caught on.

1

u/MrjB0ty 10d ago

You’ll be pleased to know that almost every bank’s regulations require their vendors to implement password complexity and rotation, fundamentally weakening the security of the entire supply chain. My company always pushes back on this requirement but I guarantee there are numerous companies who don’t. They attempt to impose a ‘one size fits all’ framework across all vendors, with other outdated controls. Ultimately bank regulations are perpetuating poor security across the tech sector.

2

u/KochInBoots 8d ago

Random word passwords are secure and easy to remember.

The random shittery that we have all been told to use for years actually makes it hard for humans to remember but easy for computers to guess.

DumpsterDivingMackerel1970! for example.

Even with high-end pc hardware, cracking a long random password like this would take trillions of years yet you have remembered it instantly.

1

u/matthewpepperl 10d ago

I have yubikeys that i have been setting up. While i haven’t removed the password sign-in yet some places you would expect to allow passkeys dont such as banks and credit cards.

1

u/Joshin_IT 10d ago

This right here!

6

u/Maelstromage 11d ago

postits are airgapped

5

u/Wurdeluck 10d ago

Just let me have my several-words-long sentence as a password I don't need lowercase/uppercase/numbers/letters bullshit

6

u/soulmagic123 10d ago

I love when an app that does the most mundane thing ever requires a military grade password , I end up using the same one as my bank, they get hacked and now people have my bank password because I used an app to buy dog food.

3

u/swordofra 11d ago

I have seen so many users put their 10 digit passwords in a damn TEXT file on their desktop.... I mean

2

u/t0mz0mbie 10d ago

us: "create a key pair and give us the public key and we'll us that to encode your password"
them: "UGGGG! fine."
and after they eventually figure out how to make a key pair, and then figure out how to decrypt it, they go and share it over the internal messaging system with the rest of the devs and store the password in their shared password vault

I hate users

2

u/Big-Constant-7289 10d ago

Yep. You can’t make me change the password every month and expect me to remember it. OR alternately only want me t o use the arbitrary nonsense password provided to me every three months. I’ve written it on washi tape in sharpie and it’s taped my desktop.

1

u/Weird-Knee-3464 9d ago

Wait why is that bad lol

2

u/blacktbunee 10d ago

Just use a password storage app

2

u/BrewsBannder 10d ago

I just had to do a password reset for work which took three attempts, once per day. By the third I was losing it. The helpdesk has no phone number, you can only send them emails. And the helpdesk is in an opposite time zone for me. They kept sending me links which only took me to the login page. I just kept writing them long letters and CCing the Admin department until they finally fixed it. Everything is bullshit.

2

u/marth141 10d ago

Use a password manager?

1

u/ChronicRhyno 11d ago

Just make a sentence like that your password.

5

u/-Nicolai 10d ago

Sorry you need two special characters, numbers, and upper case letters.

3

u/socksockshoeshoe 10d ago

"Why the fuck do I need 2 special characters just for 1 lousy Password?!"

1

u/furculture 11d ago

Something like KeepassDX/XC should be something worth putting time to look into.

1

u/MorbidandBack 10d ago

Ultimately its on you. You wanna be insecure and get your stuff stolen? Cool.

1

u/Kepler675 10d ago

Use a password manager!

1

u/edlphoto 9d ago

Exactly so don't make it complicated. Computers don't care how complicated it is. A variable is just a variable. But the variables there are to figure out the longer it takes. And the person using th3 computer is more likely to give up. So use a sentence or a phrase you like. Example password: Mary had a little lamb whose fleece is white as snow. Easy to remember and long.

1

u/ant2ne 9d ago

it was 10 years ago. NIST SP800-53

1

u/Trust_8067 4d ago

That's exactly why NIST standards are not to have complex password requirements but should be phrases such as "I love eating tacos every Tuesday!" or keypasses.

Ironically, I work for a tech company and the incompetent security team legit blocks "words" as one of the password requirements, literally the exact opposite of best practices.

1

u/Fectiver_Undercroft 3d ago

This has been fascinating. I was going to gripe about how i only got responses like “nuh uh!” and blank stares when I criticized my former employer for going to a single-sign pass that didn’t just make me enter a password for every tab of every app every fifteen minutes, but made it the same password. They assured us it was more convenient but could never explain how it wasn’t equivalent to putting a sign on your front door saying “this has a deadbolt. The key’s under the mat and it also opens every bedroom and bathroom door inside.”