• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

It suprises me how often people forget their passwords

Page 3 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.
I have approx 30 different personal accounts with 8 different passwords due to different requirements.

I have 10 different work related passwords, all different due to different requirements and frequency of change. Not to mention 4 tokens, 2 of which have PIN requirements.

My system is I have a "code" to break down my password and I write it down with the primer in my head so I know what it is for my personal PWs. But for the work passwords, yea, I fucking write them down.
 
Six systems, one-month password life, all out of synch = new password every 5 days. I don't care how smart your system is for coming up with secure, memorable passwords, that rapidly becomes a PITA.

(Worst of all though is when password parsers complain that your password is too long! I can touch type plenty fast, its not particularly long, and you're a computer, if its not too long for me it shouldn't be too long for you!)
 
Easy to create one that is secure

Jack be nimble, Jack be quick = JbeN#jbq1
Use an expression inspired by the name of a city:
I love Paris in the springtime = 1LpntST!
Chicago is my kind of town = C1mYK0t
Use lines from a song:
You can't always get what you want = uC4n+agwUw!

To bad the phrases the passwords come from are far more secure then what they are creating.
Oh and this seems really appropriate.
password_strength.png
 
To bad the phrases the passwords come from are far more secure then what they are creating.
Oh and this seems really appropriate.
password_strength.png

It's just a example on how to create a secure one. Unless a numpty go out and use the examples but who is that stupid?

12 random digits brute force that quickly
 
Some requirements are just ridiculous. And the password history requirement sucks, bad. We have a citrix system I log into that never lets you use the same password twice, and has the following requirements: at least 1 letter, 1 number, 1 special char, 1 capital and 8 digits long. It can't contain any word from the english language, have a common name in it, and it expires every 30 days.

I feel like a kid writing l33t when I create all my passwords on that server. Yup, I forget them.
 
Last edited:
The lockout for the network password is five attempts. I have been told that the password change was mandatory once we received a couple of government contracts - but I am hearing that third hand.
That explains a lot. 🙂

Precisely. 🙂

hamburger = 9 characters
cheeseburger = 12 characters

Before attempting an aa ab ac ad ae af... aaaab! aaaac! aaaad! aaaae! etc. attack, I'd probably run a dictionary attack first; also a dictionary attack with a number appended to the end of the the word. i.e. hamburger, hamburger1, hamburger2, ironically, if I chose a dictionary of values as a simple common dictionary, I'd get get to cheeseburger before I got to hamburger. 🙂 Unless things have changed, at least in the online world without specific requirements, that would succeed with a good 70% of all passwords. There were a few common sites that didn't lock people out after x-number of attempts, and sooooo many people use the same password on many different sites. Heck, there's an easier way - not all sites encrypt their passwords (they weren't encrypted in Fusetalk, if I recall correctly.) And, if I recall correctly, wasn't a major problem with some of the game sites being hacked last year that the unencrypted passwords may have been accessed? (Giving the hackers access to the emails, etc., of many of the users.)

edit: since no one else has mentioned it,
*surprise*, not suprise
 
Password requirements are fucking retarded these days. Up here, it has to be at least 24 characters long, at least 1 upper case letter, 1 lower case letter, 1 number, 1 special character and can't be similar to your past 24 passwords. Has to be changed every 2 months. And that's just one of at least 8 different "systems" we have to memorize username/passwords for.

Yeah fuck that, of course people are going to write em down.
 
Back
Top