What's new

Password rant.

ceejtank

No longer a newbie, moving up!
Joined
Sep 28, 2011
Messages
764
Reaction score
118
Location
Weymouth, MA
Can others edit my Photos
Photos NOT OK to edit
Ok,

so I work for a large finance company.. and we obviously work with a lot of vendors. One of the vendors just changed our password for a program I need to access daily. And it went from being a word with some numbers, to looking like a cat fell asleep on a keyboard.

They should let me choose my own password. If I decide to make my password "password" that's my own sh*tty decision and they should let me roll with it.

/rant
 
I worked at a bank while I was in college. I hated that I had to change my password every fricken week.

Sent using PhotoForum
 
Last edited by a moderator:
I worked at a bank while I was in college. I hated that I had to change my password every fricken week.

Sent using PhotoForum

Drives me crazzzzy. I have to change it once every few months for my main PC, but monthly for most programs.
 
Last edited by a moderator:
Does lastpass.com help you out at all?
 
That sucks. I hate the crazy passwords like that. Most secure though.
 
That sucks. I hate the crazy passwords like that. Most secure though.

You'd think, but it's not so. You're more likely to write down a crazy password than one that's easier to remember, and once it's written down you might as well consider the game over.
 
Password winning formula:

pick your favorite 4 digit number; ie 1234
pick your favorite 4 letter word; ie home
capitalize the first letter; ie Home
split them like so:

12Home34

add your favorite special character; ie !@#$%^&*?

final product: 12Home34!

This password algorithm is damn near impossible to crack by standard brute force programs AND it meets 99.9% of all the websites' password requirements (some don't like special characters, some do and require one).

Stick to this algorithm and you should never forget another password again.

And if you do? Keep an excel spreadsheet (unlocked...) and somewhere at the top denote the number and word and character (please don't label them... they are reminders), then list out the websites and just use the word for what password you use and find a way to denote whether or not you use the special character or not (or some other form of reminder/hint system that only YOU can understand without confusing yourself so much!)





As an IT Manager with clients on service contracts, we have hundreds, if not close to the thousands of passwords we use and KNOW BY HEART for our clients because we use this algorithm and we know what standards we use for the numbers/words.
 
Also, that algorithm I gave, is probably one of the most secure ways to set up your passwords, most websites use 256 bit encryption which is near impossible to crack brute force and even if they use 128 bit its still pretty damn hard.

Password brute force is pretty much dead, passwords are often obtained by guessing, social engineering (pretending to be someone your not and having the help desk reset "your" password) or you just don't watch what you are doing and you just give it to them!

Hope this helps some of you out!
 
Lastpass is WIN

I wrote down my master password until I remembered it. Kept it on me. Then shred it.
 
macpro, you realize that you've just made the job of cracking your passwords quite a bit easier, right?
 
My actual passwords are very good and hard to crack.. however i shouldnt need to look up on character map how to type § as part of a password.(didn't literally happen.. hyperbole). The password seriously looks like this ^8273@hsdh&*e
 
Randomly generated passwords are generally pretty good, but impossible the remember. The password safe is the right technology to apply here, but it's just a technological fix to a problem we've invented our own selves, as opposed to a real problem. lastpass.com is a password safe, and quite a good one as far as I know.

The XKCD algorithm is, as the comic points out, vastly harder to crack no matter how you approach the problem. Unfortunately, the XKCD algorithm produces passwords that are not accepted by anything, because we have overpaid monkeys instead of professionals designing standards for this sort of thing.
 
They should let me choose my own password. If I decide to make my password "password" that's my own sh*tty decision and they should let me roll with it.

For email and general day to day I agree with you, but you stated that you work for a finance company, that means the things you access could have a potential detrimental effect on more than just yourself. The number one weakest link in any computer security chain is the users.

I would actually take what Macpro said a step further and convert letters to numbers if possible and move the special character to midway through the passphrase. Using his example I would go with 12H0m3!34 (changed o for zero and e for 3).
 

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

New Topics

Back
Top Bottom