• Blue_Morpho@lemmy.world
    link
    fedilink
    arrow-up
    26
    ·
    2 months ago

    Ok, I’ll capitalize the first letter and add an exclamation point to the end. Happy?

    I bet brute force hash checkers assume the first letter is capitalized because of current password policies.

    • anomnom@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      2
      ·
      2 months ago

      I used to capitalize the last 2-3 when I still picked passwords. But now I less my keychain app do it all.

  • Clay_pidgin@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    18
    ·
    2 months ago

    I just hate it when a program or website has a MAXIMUM password length, and despise even more when the password requirements/limits aren’t shown on the page. “Failed to update password” WHY!? WHY DID IT FAIL!? Oh, you think 16 characters is enough? Were my extra 70 bytes of storage space hurting your margins?

    I use a password manager and I’ve twice seen a website not let me in with my saved credentials, and on resetting my account discovering that the maximum password length is now shorter than the password I have been using for months. If you are going to change the password constraints, fine, but you could allow login once and immediately force a password change.

    • JustAnotherKay@lemmy.world
      link
      fedilink
      arrow-up
      10
      ·
      2 months ago

      I’ve seen it one step further. I can’t remember what the service was, but I signed up for it and copy pasted the password into my password manager, then tried to sign in with it. Couldn’t. Went back and forth with the “forgot my password” page about three times before I realized that not only was there a limit to the text length: you auto-truncated my input upon saving with no indication to me

    • Nat997@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      7
      ·
      2 months ago

      Correct me if I’m wrong, but if websites store your password in plain text, that’s already bad enough. As far as I’m aware basic hashing - as in taking the password and transforming it into a fixed length sequence - is (or at least should be) common sense. So if credentials are stored as a hash (or a fixed sequence), then the only logical reason for enforcing a limit on password length should be hash collisions (which are only possible if you’re using a terrible hashing algorithm). I don’t really know what I wanted to say with this, my brain just spontaneously jumped to hashing and the bunch.

      • marcos@lemmy.world
        link
        fedilink
        arrow-up
        4
        ·
        2 months ago

        It’s somewhat common to limit password lengths to avoid DoS attacks that exploit a slow key generation function.

        But that limitation should on some hundreds or a few thousands characters. Sites that use limits like “16” are probably storing them as plain text.

      • Clay_pidgin@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        3
        ·
        2 months ago

        I appreciate your comment anyway! I didn’t know passwords would be hashed to a consistent length - I can see how that would be more secure.

        I don’t think in the cases that I mentioned, that the hash of my entered/saved/extralong password was being compared to the stored hash they had on file, I think what happened is the input field validation was changed and would no longer allow a password that was valid under their previous rules.

  • Grostleton@lemmy.dbzer0.com
    link
    fedilink
    arrow-up
    15
    ·
    2 months ago

    At that point you just slap random letters and numbers without paying attention and then waste an hour+ contacting IT to get it reset because you “forgot” and got locked out.

    Password policy is mostly bullshit anyway since most “hackers” these days are just performing social engineering on morons with no sense in order to get in.

    • ZeDoTelhado@lemmy.world
      link
      fedilink
      arrow-up
      9
      ·
      2 months ago

      There is actually a lot more to this: a lot of people in the it sec crowd have been saying for many years that this habit of the gibberish passwords with symbols capitals and whatnot is actually a net deficit in security. Mostly because for the longest time people had to mostly remember all passwords and the policies for rotation were to aggressive (which lead to “lazy” changes). Nowadays unfortunately we still have people that inherited this thinking and still enforce this, but you also see a lot of people understanding that pass phrases are a lot better (of course should not be a predictable phrase like good morning, but it is possible to make it much better with way less effort)

  • baggachipz@sh.itjust.works
    link
    fedilink
    arrow-up
    3
    ·
    2 months ago

    My company’s password policy requires, among many other things, “no repeating characters”. Like what the Christ. How does all this bullshit make it more secure? I store my login in a password manager with far looser requirements, so fuck yo security

  • Makhno@lemmy.world
    link
    fedilink
    arrow-up
    2
    ·
    2 months ago

    Hahaha Oh Linda! Its always Linda isnt it, folks?

    laugh track to shitty generic joke