Hacker News new | ask | show | jobs
by COil 3445 days ago
Yes indeed. For example they add the current year and month and keep the same "base password" which is unsafe.
1 comments

"Password2017" is a typical "secure" password. Capital and small letters, and number - longer than 8 characters. Passes most "checks" for passwords...
"Password2017!" is even better. It's got a special character!
My favorite "pattern for stupid passphrase requirements" is "1qaz@WSX" - then just move a row to the right with every password change. :)
Funny how most people go for ! as the default special character :)
It adds to the excitement of logging into an application. Instead of "login", you get to "login!".
I think it's a natural outgrowth of how so many people chose "1" when they were forced to add a number to their passwords.