Hacker News new | ask | show | jobs
by function_seven 3475 days ago
> it turns out that users who are forced to change their passwords frequently pick worse passwords

I can vouch for this. My rotating password at work is _______1, followed by _______2, then _______3, and so on. If a year-old hash gets cracked, it won’t take a rocket scientist to know that the password right now is _______4.

2 comments

Everyone I know does some variation of this. I'm currently enumerating gen 1 pokemon.
So one day you'll have "Mew" as a password?
No silly, "MewMewMew" when it's too short.
"M3wM3wM3w*" to satisfy special character requirements
Get a password manager already, and let it just generate random passwords for you. Typing in passwords is so lame. :) If you are on macOS I highly recommend https://github.com/ravenac95/sudolikeaboss (and by extension 1Password).
I use a password manager. The password in question is one I type all the time, in dozens of different contexts, on a computer I don’t own and can’t modify :(.
I can't log into work computers using my password manager.
This would be fantastic if work allowed me to install one. Sadly, some of us work in locked down environments so resort to such silliness to get through the work day.
I'm sorry. that sucks. That's just stupid. I could see employers requiring you to use their password manager, but ugh, not allowing use of one is just gross.

That said, lastpass can work without any modifications to your local machine(i.e. it can work without any browser plugins even) tho it's not very fabulously integrated, it does work... Assuming of course they don't block access to the lastpass website and JS.

Does it work to allow me to log in to my machine or to unlock it? (Serious question. If so, then I will happily use a 16 character blob of entropy)
How do I login to lastpass.com when I need my password to unlock my work computer to get to lastpass.com?