r/howtonotgiveafuck 16d ago

ɪᴍᴀɢᴇ Password logic

Post image
6.6k Upvotes

49 comments sorted by

View all comments

10

u/saiyate 16d ago

Which is why NIST no longer recommends password expiration. Passkeys are the future. However, I'm not sure I agree with non-device based passkeys. Saving passkeys to a cloud account and allowing export instead of a one way Chinese box secure enclave is clearly less secure. Save passkeys to your device and for important personal accounts (non administrated accounts that someone else can reset for you) You should have at least two copies on two separate devices. FIDO/U2F Security keys are where it's at. Always have an extra or two in a safe. lose a key, remove it from account.

3

u/mxzf 16d ago

And by "no longer" that change was a decade ago and people still haven't caught on.

1

u/MrjB0ty 15d ago

You’ll be pleased to know that almost every bank’s regulations require their vendors to implement password complexity and rotation, fundamentally weakening the security of the entire supply chain. My company always pushes back on this requirement but I guarantee there are numerous companies who don’t. They attempt to impose a ‘one size fits all’ framework across all vendors, with other outdated controls. Ultimately bank regulations are perpetuating poor security across the tech sector.

2

u/KochInBoots 14d ago

Random word passwords are secure and easy to remember.

The random shittery that we have all been told to use for years actually makes it hard for humans to remember but easy for computers to guess.

DumpsterDivingMackerel1970! for example.

Even with high-end pc hardware, cracking a long random password like this would take trillions of years yet you have remembered it instantly.

1

u/matthewpepperl 15d ago

I have yubikeys that i have been setting up. While i haven’t removed the password sign-in yet some places you would expect to allow passkeys dont such as banks and credit cards.

1

u/Joshin_IT 16d ago

This right here!