Hacker News new | ask | show | jobs
by HappyTypist 3448 days ago
Is it really impossible for a human to follow?

"Shiny C0rrect H0rse Battery Staple!"

4 comments

That's a good long term solution but when policies force you to change your password every 45 days, it falls apart.

In my experience, overly restrictive password policies force users to choose passwords that are less secure and easier to remember.

The good news is that the practice is going away NIST revised it's guidance/recommendation for password cycling.
You can tell a company has this policy when every monitor has a sticky note on it with the numbers 1 to N on it, where 1 to N-1 are crossed out.
Yes indeed. For example they add the current year and month and keep the same "base password" which is unsafe.
"Password2017" is a typical "secure" password. Capital and small letters, and number - longer than 8 characters. Passes most "checks" for passwords...
"Password2017!" is even better. It's got a special character!
My favorite "pattern for stupid passphrase requirements" is "1qaz@WSX" - then just move a row to the right with every password change. :)
Funny how most people go for ! as the default special character :)
It adds to the excitement of logging into an application. Instead of "login", you get to "login!".
I think it's a natural outgrowth of how so many people chose "1" when they were forced to add a number to their passwords.
Embedding special characters only makes it harder to remember correctly yet has little benefit. Your example is the same used in the xkcd where they explain this (except you've added an additional word at the beginning) so you've probably seen it already but I'll link it anyways. https://xkcd.com/936/
At work I constantly deal with people who can't remember passwords as short as 8 characters, you have to remember we're not representative of the average person.
you should ask them what they prefer - remembering 8 random characters or 4 random words
For one specific site, no. But if you have 100-200 different passwords to remember, it's impossible for most people.