• nullspace@lemmy.world
    link
    fedilink
    arrow-up
    14
    ·
    6 hours ago

    Your password must be at least 10 characters long.

    ERROR: INVALID PASSWORD ENTERED!!!

    PASSWORD MUST NOT EXCEED 12 CHARACTERS!

  • shirasho@feddit.online
    link
    fedilink
    English
    arrow-up
    7
    ·
    6 hours ago

    Requiring specific characters reduces the number of permutations. The only thing that makes a password more secure is increasing the minimum length. As the OP suggests, enforcing special characters makes most people just put a special character at the end. What you have effectively done is make the last character so easy to guess that it might as well not exist.

  • CocaineShrimp@sh.itjust.works
    link
    fedilink
    arrow-up
    82
    ·
    12 hours ago

    It’s also a gigantic red flag when sites say there’s a password limit

    Bitch, my password is supposed to be hashed so even if I uploaded the LOTR trilogy extended edition in 4K, it should still come out the same length as any other SHA256 hash

    • Toes♀@ani.social
      link
      fedilink
      arrow-up
      13
      ·
      10 hours ago

      I appreciate the enthusiasm but my load balancer will get sad if I let you send more than 1500 bytes.

      • u/lukmly013 💾 (lemmy.sdf.org)@lemmy.sdf.orgOP
        link
        fedilink
        arrow-up
        4
        arrow-down
        1
        ·
        9 hours ago

        First round of hashing could be done client-side, and then send that to the server.
        Would be cool to also add salt so that the hash couldn’t get re-used across services even with the same source password/file if somehow captured.

        Idea:

        1. Enter username
        2. Server sends salt to client
        3. Enter password or key file
        4. Client computes hash of the password or file with salt added (I have no idea how it’s used. If appended, some hashing functions could truncate the data, losing the salt. If prepended along with truncation, you just made the password even shorter. XOR?)
        5. Client sends hash to server
        6. Server hashes the hash same way as if it was password
        7. If it matches, you’re in

        Basically, the hash is your password. Data can be whatever.
        Most websites already use JavaScript, so why not.

  • gastroglizzy@piefed.social
    link
    fedilink
    English
    arrow-up
    19
    arrow-down
    1
    ·
    10 hours ago

    Fun fact: As an anti-scam measure, if you type your password in a comment, Lemmy will automatically censor it for you.

    Like this:

    ************

    Cool, right?

  • QualifiedKitten@discuss.online
    link
    fedilink
    English
    arrow-up
    7
    ·
    8 hours ago

    My new job has us doing various security trainings every month and they also send out fake phishing emails. I initially ignored the emails prompting me to do the training because they require you to click a personalized link in the email to access the training. Eventually, my manager reached out and asked why I hadn’t done the training, so I explained, but finally clicked through to do it. That month’s training was about how a long passphrase is more secure than a list of character type requirements. Guess whose password requirements are a list of character type requirements?

  • Monument@piefed.world
    link
    fedilink
    English
    arrow-up
    42
    ·
    13 hours ago

    In systems that accept whitespace, “Live, Laugh, Love” is considered a strong password.

    With that being said, “In systems that accept whitespace, “Live, Laugh, Love” is considered a strong password.” is an even stronger password.

    • taiyang@lemmy.world
      link
      fedilink
      arrow-up
      22
      ·
      13 hours ago

      I love systems that accept “With that being said, “In systems that accept whitespace, “Live, Laugh, Love” is considered a strong password.” is an even stronger password.” as my password.

      • otacon239@lemmy.world
        link
        fedilink
        arrow-up
        16
        ·
        12 hours ago

        For those that have full Unicode support, including newline characters and a very high or nonexistent character limit, using:

        For those that have full Unicode support, including newline characters and a very high or nonexistent character limit, using:

        I love systems that accept “With that being said, “In systems that accept whitespace, “Live, Laugh, Love” is considered a strong password.” is an even stronger password.” as my password.

        as your password is an even stronger password.

        as your password is an even stronger password.

        • AllHailTheSheep@sh.itjust.works
          link
          fedilink
          arrow-up
          12
          ·
          12 hours ago

          all fun and games until you find out it strips whitespace/newlines on save without telling you and you gotta go figure out why your passwords not working

  • Cousin Mose@lemmy.hogru.ch
    link
    fedilink
    English
    arrow-up
    5
    ·
    edit-2
    6 hours ago

    The FBI training I’m forced to take at work suggests replacing characters in that manner. “Just use a $ instead of S!”

    But back in like 2006 I brute forced a dump of 20 Windows passwords in that style on my old Dell single core machine in less than two seconds. Every passing year I’m still shocked people continue thinking this is secure.

  • JustPlainDave@lemmy.zip
    link
    fedilink
    arrow-up
    3
    ·
    10 hours ago

    My last job was at AutoZone and our password requirements were stricter and had to be changed twice as often as my password on our secured computer when I was in the Navy.