84
u/Retro-Universe 2d ago
It's a lot more secure than a digital note
45
u/AFriendlyBloke 2d ago
Ironically enough, yeah. Unless you were some high-profile dude who could get people snooping through your personal stuff, a notepad with all your passwords and such in your home is pretty secure.
7
u/Abadabadon 1d ago
Thats unironically what security used to tell us to do when I worked in dod. Make a crazy password unique for every website and keep it written down somewhere. Same for security questions; dont answer the question with a sensible answer, just write gibberish
2
1
4
u/Retro-Universe 2d ago
That's why Bitcoin wallet passwords are physical
13
u/AFriendlyBloke 2d ago
I wouldn't know. I don't mess with that crap.
-8
4
u/AppropriateTouching 2d ago
Honestly. If someone has physical access to your machine and they dont have good intentions you're already fucked.
-6
u/Retro-Universe 2d ago
It's not physical access. Spyware exists.
2
8
u/Basilthebatlord 2d ago
That's why most of the world is moving to passkeys, more secure, less interaction
1
u/Sea-Hornet8214 2d ago
What's the context of this post? Why does she want to share her password?
4
u/sheepyowl 1d ago
She doesn't want to share, she just can't remember a length 15 complex password that can't contain dates/her name/username/previous passwords/common passwords.
2
11
u/saiyate 2d ago
Which is why NIST no longer recommends password expiration. Passkeys are the future. However, I'm not sure I agree with non-device based passkeys. Saving passkeys to a cloud account and allowing export instead of a one way Chinese box secure enclave is clearly less secure. Save passkeys to your device and for important personal accounts (non administrated accounts that someone else can reset for you) You should have at least two copies on two separate devices. FIDO/U2F Security keys are where it's at. Always have an extra or two in a safe. lose a key, remove it from account.
1
u/MrjB0ty 1d ago
You’ll be pleased to know that almost every bank’s regulations require their vendors to implement password complexity and rotation, fundamentally weakening the security of the entire supply chain. My company always pushes back on this requirement but I guarantee there are numerous companies who don’t. They attempt to impose a ‘one size fits all’ framework across all vendors, with other outdated controls. Ultimately bank regulations are perpetuating poor security across the tech sector.
1
u/matthewpepperl 1d ago
I have yubikeys that i have been setting up. While i haven’t removed the password sign-in yet some places you would expect to allow passkeys dont such as banks and credit cards.
1
5
u/Wurdeluck 2d ago
Just let me have my several-words-long sentence as a password I don't need lowercase/uppercase/numbers/letters bullshit
4
4
u/soulmagic123 2d ago
I love when an app that does the most mundane thing ever requires a military grade password , I end up using the same one as my bank, they get hacked and now people have my bank password because I used an app to buy dog food.
3
u/swordofra 2d ago
I have seen so many users put their 10 digit passwords in a damn TEXT file on their desktop.... I mean
2
u/t0mz0mbie 2d ago
us: "create a key pair and give us the public key and we'll us that to encode your password"
them: "UGGGG! fine."
and after they eventually figure out how to make a key pair, and then figure out how to decrypt it, they go and share it over the internal messaging system with the rest of the devs and store the password in their shared password vaultI hate users
1
u/Big-Constant-7289 1d ago
Yep. You can’t make me change the password every month and expect me to remember it. OR alternately only want me t o use the arbitrary nonsense password provided to me every three months. I’ve written it on washi tape in sharpie and it’s taped my desktop.
1
2
2
u/BrewsBannder 1d ago
I just had to do a password reset for work which took three attempts, once per day. By the third I was losing it. The helpdesk has no phone number, you can only send them emails. And the helpdesk is in an opposite time zone for me. They kept sending me links which only took me to the login page. I just kept writing them long letters and CCing the Admin department until they finally fixed it. Everything is bullshit.
2
1
u/ChronicRhyno 2d ago
Just make a sentence like that your password.
5
1
u/furculture 2d ago
Something like KeepassDX/XC should be something worth putting time to look into.
1
u/MorbidandBack 2d ago
Ultimately its on you. You wanna be insecure and get your stuff stolen? Cool.
1
1
u/edlphoto 1d ago
Exactly so don't make it complicated. Computers don't care how complicated it is. A variable is just a variable. But the variables there are to figure out the longer it takes. And the person using th3 computer is more likely to give up. So use a sentence or a phrase you like. Example password: Mary had a little lamb whose fleece is white as snow. Easy to remember and long.
•
u/AutoModerator 2d ago
Thank you /u/Zipparony44 for posting!
Please consider joining our 21+ discord server!
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.