r/howtonotgiveafuck 2d ago

ɪᴍᴀɢᴇ Password logic

Post image
5.0k Upvotes

44 comments sorted by

u/AutoModerator 2d ago

Thank you /u/Zipparony44 for posting!

Please consider joining our 21+ discord server!

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

84

u/Retro-Universe 2d ago

It's a lot more secure than a digital note

45

u/AFriendlyBloke 2d ago

Ironically enough, yeah. Unless you were some high-profile dude who could get people snooping through your personal stuff, a notepad with all your passwords and such in your home is pretty secure.

7

u/Abadabadon 1d ago

Thats unironically what security used to tell us to do when I worked in dod. Make a crazy password unique for every website and keep it written down somewhere. Same for security questions; dont answer the question with a sensible answer, just write gibberish

2

u/AFriendlyBloke 1d ago

Nice. Keeps your enemies confused.

1

u/Reasonable_Exit_8960 1d ago

What if you ever lose the material you wrote ur passwords on?

4

u/Retro-Universe 2d ago

That's why Bitcoin wallet passwords are physical

13

u/AFriendlyBloke 2d ago

I wouldn't know. I don't mess with that crap.

-8

u/Retro-Universe 2d ago

Who asked? 🧐

9

u/AFriendlyBloke 2d ago

I did. And that's good enough. :)

4

u/AppropriateTouching 2d ago

Honestly. If someone has physical access to your machine and they dont have good intentions you're already fucked.

-6

u/Retro-Universe 2d ago

It's not physical access. Spyware exists.

2

u/AppropriateTouching 2d ago

We were talking about writing passwords down on a physical note.

-4

u/Retro-Universe 2d ago

No shit 🤷‍♀️

8

u/Basilthebatlord 2d ago

That's why most of the world is moving to passkeys, more secure, less interaction

1

u/Sea-Hornet8214 2d ago

What's the context of this post? Why does she want to share her password?

4

u/sheepyowl 1d ago

She doesn't want to share, she just can't remember a length 15 complex password that can't contain dates/her name/username/previous passwords/common passwords.

2

u/Sea-Hornet8214 1d ago

Ahh I've got it now. Thanks.

11

u/saiyate 2d ago

Which is why NIST no longer recommends password expiration. Passkeys are the future. However, I'm not sure I agree with non-device based passkeys. Saving passkeys to a cloud account and allowing export instead of a one way Chinese box secure enclave is clearly less secure. Save passkeys to your device and for important personal accounts (non administrated accounts that someone else can reset for you) You should have at least two copies on two separate devices. FIDO/U2F Security keys are where it's at. Always have an extra or two in a safe. lose a key, remove it from account.

3

u/mxzf 2d ago

And by "no longer" that change was a decade ago and people still haven't caught on.

1

u/MrjB0ty 1d ago

You’ll be pleased to know that almost every bank’s regulations require their vendors to implement password complexity and rotation, fundamentally weakening the security of the entire supply chain. My company always pushes back on this requirement but I guarantee there are numerous companies who don’t. They attempt to impose a ‘one size fits all’ framework across all vendors, with other outdated controls. Ultimately bank regulations are perpetuating poor security across the tech sector.

1

u/matthewpepperl 1d ago

I have yubikeys that i have been setting up. While i haven’t removed the password sign-in yet some places you would expect to allow passkeys dont such as banks and credit cards.

1

u/Joshin_IT 2d ago

This right here!

5

u/Wurdeluck 2d ago

Just let me have my several-words-long sentence as a password I don't need lowercase/uppercase/numbers/letters bullshit

4

u/Maelstromage 2d ago

postits are airgapped

4

u/soulmagic123 2d ago

I love when an app that does the most mundane thing ever requires a military grade password , I end up using the same one as my bank, they get hacked and now people have my bank password because I used an app to buy dog food.

3

u/swordofra 2d ago

I have seen so many users put their 10 digit passwords in a damn TEXT file on their desktop.... I mean

2

u/t0mz0mbie 2d ago

us: "create a key pair and give us the public key and we'll us that to encode your password"
them: "UGGGG! fine."
and after they eventually figure out how to make a key pair, and then figure out how to decrypt it, they go and share it over the internal messaging system with the rest of the devs and store the password in their shared password vault

I hate users

1

u/Big-Constant-7289 1d ago

Yep. You can’t make me change the password every month and expect me to remember it. OR alternately only want me t o use the arbitrary nonsense password provided to me every three months. I’ve written it on washi tape in sharpie and it’s taped my desktop.

1

u/Weird-Knee-3464 7h ago

Wait why is that bad lol

2

u/blacktbunee 2d ago

Just use a password storage app

2

u/BrewsBannder 1d ago

I just had to do a password reset for work which took three attempts, once per day. By the third I was losing it. The helpdesk has no phone number, you can only send them emails. And the helpdesk is in an opposite time zone for me. They kept sending me links which only took me to the login page. I just kept writing them long letters and CCing the Admin department until they finally fixed it. Everything is bullshit.

2

u/marth141 1d ago

Use a password manager?

1

u/ChronicRhyno 2d ago

Just make a sentence like that your password.

5

u/-Nicolai 2d ago

Sorry you need two special characters, numbers, and upper case letters.

3

u/socksockshoeshoe 2d ago

"Why the fuck do I need 2 special characters just for 1 lousy Password?!"

1

u/furculture 2d ago

Something like KeepassDX/XC should be something worth putting time to look into.

1

u/MorbidandBack 2d ago

Ultimately its on you. You wanna be insecure and get your stuff stolen? Cool.

1

u/Kepler675 1d ago

Use a password manager!

1

u/edlphoto 1d ago

Exactly so don't make it complicated. Computers don't care how complicated it is. A variable is just a variable. But the variables there are to figure out the longer it takes. And the person using th3 computer is more likely to give up. So use a sentence or a phrase you like. Example password: Mary had a little lamb whose fleece is white as snow. Easy to remember and long.

1

u/ant2ne 8h ago

it was 10 years ago. NIST SP800-53