Lemmy devs still haven’t figured this out.
I have 5-6 apps I log into for work that all have different password requirements and are on different expiration periods. One of them is so crazy that I have to take 3-4 spins on a password generator before I get one it will accept. We also don’t have a password manager that’s approved to install. So, the result of all this is that I store my passwords in onenote. Very secure. Great job everyone. At least for the less severe ones I can just put whatever number I’m tagging on the end of the usual password I use.
Your password must be at least 10 characters long.
ERROR: INVALID PASSWORD ENTERED!!!
PASSWORD MUST NOT EXCEED 12 CHARACTERS!
Requiring specific characters reduces the number of permutations. The only thing that makes a password more secure is increasing the minimum length. As the OP suggests, enforcing special characters makes most people just put a special character at the end. What you have effectively done is make the last character so easy to guess that it might as well not exist.
It’s also a gigantic red flag when sites say there’s a password limit
Bitch, my password is supposed to be hashed so even if I uploaded the LOTR trilogy extended edition in 4K, it should still come out the same length as any other SHA256 hash
I appreciate the enthusiasm but my load balancer will get sad if I let you send more than 1500 bytes.
First round of hashing could be done client-side, and then send that to the server.
Would be cool to also add salt so that the hash couldn’t get re-used across services even with the same source password/file if somehow captured.Idea:
- Enter username
- Server sends salt to client
- Enter password or key file
- Client computes hash of the password or file with salt added (I have no idea how it’s used. If appended, some hashing functions could truncate the data, losing the salt. If prepended along with truncation, you just made the password even shorter. XOR?)
- Client sends hash to server
- Server hashes the hash same way as if it was password
- If it matches, you’re in
Basically, the hash is your password. Data can be whatever.
Most websites already use JavaScript, so why not.I’d rather not make the client do anything like that, you cannot trust a client, EVER; what if some script kiddie tries to send the clear passwd by modifyng the request? Ofc it’s a very minir problem but still…
I make my passwords complex phrases with spaces and punctuation included. e.g. “Correct, horse battery staple!”
(obligatory that’s not my password)
Yeah, no way someone can brute force that
Clearly you have undiscovered SHA256 collisions that you want to attack the website with.
Must be 8 to 14 characters 😡
alphanumeric characters only, and maybe an underscore if we’re feeling extra generous
My new job has us doing various security trainings every month and they also send out fake phishing emails. I initially ignored the emails prompting me to do the training because they require you to click a personalized link in the email to access the training. Eventually, my manager reached out and asked why I hadn’t done the training, so I explained, but finally clicked through to do it. That month’s training was about how a long passphrase is more secure than a list of character type requirements. Guess whose password requirements are a list of character type requirements?
Fun fact: As an anti-scam measure, if you type your password in a comment, Lemmy will automatically censor it for you.
Like this:
************
Cool, right?
11 year old me fell for this on runescape
How does mine look?
Hunter2
I just see *'s.
This is just a css trick. Your full password text is still there in the html.
Really the same weak ass jokes from reddit huh?
Reddit? My boy, this meme predates reddit.
This joke is older than Reddit, youngling.
I felt like a celebrity when my old IRC handle popped up on bash.org for one line. I didn’t even say anything funny, just the “what?” that set up someone else’s joke, but it was cool to see me there.
The internet was so much better when it was just, like, ten people.
It’s a bash.org original. Unfortunately no longer online, but you can visit bash.rip now with the same quotes
This joke has been circulating around since the IRC days.
Calm down, Satan.
In systems that accept whitespace, “Live, Laugh, Love” is considered a strong password.
With that being said, “In systems that accept whitespace, “Live, Laugh, Love” is considered a strong password.” is an even stronger password.
I love systems that accept “With that being said, “In systems that accept whitespace, “Live, Laugh, Love” is considered a strong password.” is an even stronger password.” as my password.
For those that have full Unicode support, including newline characters and a very high or nonexistent character limit, using:
For those that have full Unicode support, including newline characters and a very high or nonexistent character limit, using:
I love systems that accept “With that being said, “In systems that accept whitespace, “Live, Laugh, Love” is considered a strong password.” is an even stronger password.” as my password.
as your password is an even stronger password.
as your password is an even stronger password.
all fun and games until you find out it strips whitespace/newlines on save without telling you and you gotta go figure out why your passwords not working
correct horse battery staple
The FBI training I’m forced to take at work suggests replacing characters in that manner. “Just use a $ instead of S!”
But back in like 2006 I brute forced a dump of 20 Windows passwords in that style on my old Dell single core machine in less than two seconds. Every passing year I’m still shocked people continue thinking this is secure.
for real, why is it so hard to count entropy?
I guess it’s too chaotic.
The new recommendation is 30 character or more passphrases with some noise.
My last job was at AutoZone and our password requirements were stricter and had to be changed twice as often as my password on our secured computer when I was in the Navy.
You never know when them O’reily boys will try and hack you. You gotta be prepared!












