Taking over historically grown IT is hell

  • ouRKaoS@lemmy.today
    link
    fedilink
    arrow-up
    3
    ·
    vor 8 Stunden

    Fun password trick:

    Pick an adjective, a color, an animal, and a cuss word.

    Now pick 2 numbers and a special character, or 2 special characters and a number.

    Separate your 4 words with your other 3 items and, boom! 12+ character password that you already remember.

    Bonus points: lose the numbers and characters and you have a hilarious insult.

    • mirshafie@europe.pub
      link
      fedilink
      arrow-up
      3
      ·
      vor 7 Stunden

      I make up a sentence and then I write it out. Why limit yourself to 12 characters?

      Like the actual phrase

      Why limit yourself to 12 characters?

      is a very strong password, easy to remember, fast to type and has the added benefit of not containing any adjectives.

      • Funkt4st1c@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        vor 4 Stunden

        Length and complexity are the two most valuable things in a password.

        “ThisIsMySuperCoolPasswordNoOneWillEverGuess#2!0” is an insanely good password. “G<7p8*a94;B” is pretty good too but howtf are you gonna type that every time

  • adarza@lemmy.ca
    link
    fedilink
    English
    arrow-up
    6
    ·
    vor 10 Stunden

    hmm. that many letters. ok. 1…2…3… ah 16. cool.

    here we go:

    Input new Password:

    Sixteenpassword!

    ERROR: you must include a number

    there is a number in it you stupid machine.

    • SirSamuel@lemmy.world
      link
      fedilink
      arrow-up
      2
      ·
      vor 6 Stunden

      *ERROR: Your password must have a minimum sixteen characters

      Minimum_16_characters

      *Your password has been accepted

  • Grostleton@lemmy.dbzer0.com
    link
    fedilink
    arrow-up
    66
    ·
    vor 16 Stunden

    I’d happily use a passphrase with multiple unrelated 8-12 character words but for some reason most businesses have upper limits on how many characters can be used…

    • [deleted]@piefed.world
      link
      fedilink
      English
      arrow-up
      56
      ·
      vor 16 Stunden

      That is the character limit on the database field where they store your password in plain text.

      • Carl@anarchist.nexus
        link
        fedilink
        English
        arrow-up
        30
        arrow-down
        1
        ·
        vor 14 Stunden

        Yup.

        For the unaware: modern hash algorithms have character limits, but it’s nothing that would ever interfere with a regular password. Even accounting for the salt that gets appended to the end of your password before it goes into the algorithm. Most of the popular hashes have a 128 character limit, and the site will also store a salt in your user’s database entry. That salt gets appended to your password before it goes into the hash. Basically, even if two users have the same password, the hash for each will see “password{Salt1}” and “password{Salt2}”. So they won’t show as the same hash in the database, even though they’re the same password.

        This salt is to prevent something called a rainbow table attack, where a hacker feeds a bunch of common passwords into a bunch of common hash algorithms, then compares with their stolen database. If they find matches, they now know which algorithm the database was using, and they only need to brute force the database once. So for instance, they feed “{common password}” into several hashing algorithms. One gives the result “1234567890”. They then check their stolen database, and find several users with the hash “1234567890”. They try using {common password} on those user accounts, and they work! Now the hacker knows which hash algorithm was used, and can brute force the entire stolen database at their leisure.

        By appending a salt to each password, “{common password}” actually becomes “{common password}{Salt1}” “{common password}{Salt2}”, etc… So even if the hacker tries to brute force it, they would need to brute force each individual password instead of brute forcing the entire database all at once. It’s still important to use strong passwords, because a weak password will still be broken in only a few seconds. But that will be a few seconds per weak password, instead of a few seconds for every user at the same time. This is why sites tell you to change your password after a breach. The idea is that salting the database makes brute force attacks take a lot longer, and gives most users time to change their passwords before the attackers manage to get anything.

        All of this is to say, you could have a 100 character password limit, and still have plenty of room for a 16-28 character salt. And the hashes will output the same length string regardless of what you feed into it. So longer or shorter passwords won’t matter, because they’ll all turn into a 64 character hash in the end.

        So putting a low character limit on a password is a site admin tattling on themselves, because it means they’re not hashing your password at all. If they were hashing it, the only upper limit on your password would be whatever the algorithm can accept (probably 128 characters) minus 20-30 characters for a salt.

        • safesyrup@feddit.org
          link
          fedilink
          arrow-up
          9
          ·
          vor 14 Stunden

          Almost every hash algorithm does not have a character limit and instead uses chaining. Bcrypt is the odd one out of using only the first 72 bytes of a supplied password, tough you can still supply a longer password even if it does not make a difference.

        • Rai@lemmy.dbzer0.com
          link
          fedilink
          arrow-up
          1
          ·
          vor 9 Stunden

          Damn, this is a fantastic writeup, thank you for educating myself (and others, I’m sure!)

        • AceFuzzLord@lemmy.zip
          link
          fedilink
          arrow-up
          1
          ·
          vor 10 Stunden

          Despite salting passwords, I would personally also like to see a lower character limit, to get people into the habit, combined with said salting. Just in case other sites don’t do password salting, among other potential reasons.

    • mercano@lemmy.world
      link
      fedilink
      arrow-up
      8
      ·
      vor 13 Stunden

      Some sites require special characters in their passwords, other websites don’t even allow them. I use a password manager, but still have to tweak the password generation rule for some sites.

    • Thrawn@lemmy.dbzer0.com
      link
      fedilink
      arrow-up
      6
      ·
      vor 15 Stunden

      Oh there has to be an upper limit for things like buffer overflow or just plain RAM capacity limits. But even with allowing the max possible range of characters you are still looking at something like 100,000 in a single 1mb size and I’m sure they could manage to do that and still pass it along to a high quality hashing function.

      If you try putting in a password longer than that yes reject it.

  • bugbear@lemmy.sdf.org
    link
    fedilink
    arrow-up
    3
    ·
    vor 10 Stunden

    The Plague: Someone didn’t bother reading my carefully prepared memo on commonly-used passwords. Now, then, as I so meticulously pointed out, the four most-used passwords are: love, sex, secret, and…

    Margo: [glares at The Plague]

    The Plague: god. So, would your holiness care to change her password?

    (Hackers 1995)

  • gnufuu@lemmy.ca
    link
    fedilink
    arrow-up
    19
    ·
    vor 16 Stunden

    Keep them on their toes. After hunting down the last of them it’s time to introduce multi-factor.

      • thebestaquaman@lemmy.world
        link
        fedilink
        arrow-up
        4
        arrow-down
        1
        ·
        vor 11 Stunden

        Why would you do such things? Just let me log in using some trusted authenticator please. If you can’t do that, you may as well replace everything with a confirmation mail every time I log in, cause you bet I’m going to click “forgot my password” Every Single Time and get in via the reset-email anyway.

        You forcing me to change my password all the time just adds extra overhead to the inevitability that you’ll let me in after mailing me a confirmation code.

    • gegil@sopuli.xyz
      link
      fedilink
      arrow-up
      9
      arrow-down
      1
      ·
      vor 15 Stunden

      One one hand, password manager is useful to log-in into random ass web service which i use once a year to get one random file or whatever and forget.

      On the other hand, i need to authenticate every time i use my computer, and i need to just know the password, not pasting it from password manager every time.

      • floquant@lemmy.dbzer0.com
        link
        fedilink
        arrow-up
        7
        ·
        vor 14 Stunden

        Most password managers stay open for a configurable amount of time, plus you can use hardware tokens for more convenient/secure unlocking. And having to remember the master password without it being stored anywhere but your brain is kinda the whole point

          • myyass@lemmy.world
            link
            fedilink
            arrow-up
            1
            ·
            vor 10 Stunden

            Yo dawg you got good memory. I can remember a lot of things but passwords aren’t one. When I had to make a GSA level password, after trying for two hours to make one. I gave up, mashed some shit in and wrote it on a piece of paper. I could be tortured and all I can say here are all the restrictions and try to make one yourself.

            • Axolotl.cpp@lemmy.dbzer0.com
              link
              fedilink
              arrow-up
              1
              ·
              vor 2 Stunden

              Yo dawg you got good memory

              Dw, i’il forget about it if i don’t use it for more than 3 days which is why i have a copy of the password on a piece of paper i carry around

  • [object Object]@lemmy.ca
    link
    fedilink
    arrow-up
    9
    ·
    vor 16 Stunden

    This is topical because I just got one of these emails.

    Nobody is going to bother guessing that I would be stupid enough to use a four character password. It’s good enough for my bank and my phone, so it’s good enough for my computer. (/s)

    At least now they recommend pass phrases instead of words, but the examples were contradictory and they wrote all the words in 13375p34k

    • BlindPenguin@piefed.socialOP
      link
      fedilink
      English
      arrow-up
      5
      ·
      vor 15 Stunden

      I let the users choose whether they want pass phrases or classic cryptic passwords. So far nobody wanted passphrases, because apparently they can’t do 10 finger system typing. Next step will be self-service passwords & MFA once we fixed the major issues around here.

  • DudeImMacGyver@kbin.earth
    link
    fedilink
    arrow-up
    2
    ·
    vor 13 Stunden

    scrambles their password

    “Rules is rules, reset your password if you want to work here. You can run if you want but it’ll be to the fucking unemployment line.”

      • bacon_pdp@lemmy.world
        link
        fedilink
        arrow-up
        0
        ·
        vor 10 Stunden

        Servers and storage is not free. Nor is the time spent by administrators doing updates, security patching or basic account management activities necessary to properly secure credentials.

        • trxxruraxvr@lemmy.world
          link
          fedilink
          arrow-up
          1
          ·
          vor 10 Stunden

          Besides the account management, it would be less than $10 and 20 minutes per month after the initial setup, unless you have an organization with thousands of employees.

          • bacon_pdp@lemmy.world
            link
            fedilink
            arrow-up
            0
            ·
            vor 8 Stunden

            A secured server which isn’t going to result in total credential breach is going to cost a great deal more than $10 a month. Even if you just paid for rack space it would cost more than that in secured cage.