RANT: Sites with ridiculous password policies...

Argo

Lifer
Apr 8, 2000
10,045
0
0
2 rants actually:

Site 1: Requires a password that is at least 8 characters long, has 1 capital, 1 digit and one punctuation sign and cannot ressemble any word. The site falls into the category of sites that has financial data but that I access fairly seldomly. So of course I don't want to write down the password, and of course I forget it. To top it all off their "forgot my password" functionality appears to be unavailable. When I try it I litterally get a message saying "This functionality is not available, please try again later".

Site 2: Requires you to change your password once every 3 months. You CANNOT use any passwords that you used in the past. It wouldn't be so bad, it this wasn't another one of those financial data sites that I access once every 2 or 3 months. So of course I constantly keep forgetting the password, causing me to go through the stupid reset password functionality.

Really, the only thing these stupid policies cause is for people to start writing their passwords and sticking them onto a monitor. Btw, both sites are personal financial sites from major institutions.
 

Exterous

Super Moderator
Jun 20, 2006
20,569
3,762
126
I hate sites that make you choose off the wall security questions:
"Whats your favorite dinner food?"
"Who was your father's friends third wife's maiden name?"
 

wyvrn

Lifer
Feb 15, 2000
10,074
0
0
Use Word 2007 to encrypt a document and keep your passwords there. Or use Winzip and do the same thing.

If you every forget a password, you can look it up.

Alternately, setup a partition on your hard disk and use true crypt on it. Store your passwords there.
 
Dec 10, 2005
28,832
14,042
136
Originally posted by: Exterous
I hate sites that make you choose off the wall security questions:
"Whats your favorite dinner food?"
"Who was your father's friends third wife's maiden name?"

Not just off the wall questions, but questions that have variable answers and could easily change over time, like "what's your favorite movie?"
 

frostedflakes

Diamond Member
Mar 1, 2005
7,925
1
81
I wouldn't consider either of those to be ridiculous. Both are good policies, at least for something as important as financial info.

Really, though, I'd assume phishing/keylogging/etc. is a much bigger problem with sites like this than people trying to brute-force passwords.

As others mentioned, write down your passwords. And you can use the password manager in your browser to remember your login info so you don't even have to type them in.
 

Leros

Lifer
Jul 11, 2004
21,867
7
81
Originally posted by: Brainonska511
Originally posted by: Exterous
I hate sites that make you choose off the wall security questions:
"Whats your favorite dinner food?"
"Who was your father's friends third wife's maiden name?"

Not just off the wall questions, but questions that have variable answers and could easily change over time, like "what's your favorite movie?"

I could not get into a bank account I opened 6 years ago because the question was "What is your favorite book?"
 

Farang

Lifer
Jul 7, 2003
10,913
3
0
Originally posted by: Brainonska511
Originally posted by: Exterous
I hate sites that make you choose off the wall security questions:
"Whats your favorite dinner food?"
"Who was your father's friends third wife's maiden name?"

Not just off the wall questions, but questions that have variable answers and could easily change over time, like "what's your favorite movie?"

I hate that and how it is so widespread. It is usually not a problem because I can find at least one choice that will have a constant answer, but lately I ran into a couple that were all questions like that and so I'm screwed if I ever have to answer them.
 

Locut0s

Lifer
Nov 28, 2001
22,205
44
91
A similar question:

Do you feel that company policies that force one to change their login password every x days actually promote insecurity? Most people in such companies probably don't use their computer for much of anything that is very sensitive for the company and most don't understand the reason behind such a rule which is to protect the data of the few who do handle the sensitive stuff. It's best to have a blanket policy since it's hard to say who will be working with sensitive data when and where. However most of the people who are just using MS word and email don't get it and probably end up using some variation of a VERY insecure password like PASSWORD(#++).
 

Sentrosi2121

Platinum Member
Aug 8, 2004
2,567
2
81
Try having to run a data center where you're watching about 10 different agency mainframes and each agency has a different password scheme.
 

FP

Diamond Member
Feb 24, 2005
4,568
0
0
KeePass ftw

I don't know any of my passwords. I simply copy/paste from KeePass. I backup my encrypted password file remotely and have it on a couple of USB keys.
 

nsafreak

Diamond Member
Oct 16, 2001
7,093
3
81
What I'd like to see is more sites having the option of using that Verisign dongle that generates a password on each login. Very secure and all you have to do is to make sure you keep the dongle handy.
 

imported_Devine

Golden Member
Oct 10, 2006
1,293
0
0
ID cards that have encrypted data that can only be unlocked with a 6 digit number. We use it to log on, sign and encrypt emails, and have certs on there to log into secure websites. It's one thing the DoD has done well.
 

Snapster

Diamond Member
Oct 14, 2001
3,916
0
0
Originally posted by: Argo
2 rants actually:

Site 1: Requires a password that is at least 8 characters long, has 1 capital, 1 digit and one punctuation sign and cannot ressemble any word. The site falls into the category of sites that has financial data but that I access fairly seldomly. So of course I don't want to write down the password, and of course I forget it. To top it all off their "forgot my password" functionality appears to be unavailable. When I try it I litterally get a message saying "This functionality is not available, please try again later".

Site 2: Requires you to change your password once every 3 months. You CANNOT use any passwords that you used in the past. It wouldn't be so bad, it this wasn't another one of those financial data sites that I access once every 2 or 3 months. So of course I constantly keep forgetting the password, causing me to go through the stupid reset password functionality.

Really, the only thing these stupid policies cause is for people to start writing their passwords and sticking them onto a monitor. Btw, both sites are personal financial sites from major institutions.

Pretty similar for working in an IT environment, although it's annoying to remember for loads of sites hence I try use the same password. Having a password list helps greatly (see below).

Originally posted by: FP
KeePass ftw

I don't know any of my passwords. I simply copy/paste from KeePass. I backup my encrypted password file remotely and have it on a couple of USB keys.

Agreed
 

Pepsei

Lifer
Dec 14, 2001
12,895
1
0
Q1nitrusa for anandtech
Q1nitrusw for wachovia
Q1nitrusc for citibank

very easy to remember.... create your own scheme
 

smack Down

Diamond Member
Sep 10, 2005
4,507
0
0
Plus it is frigging retard.
Enter a password it most have 37 Characters no more then two characters can be of the same group in a row.

Enter you magic password recover answer. 4 Letter words are accepted and once you type in the word you get to set a new password.

Can anyone tell me the logic behind that.
 

ElFenix

Elite Member
Super Moderator
Mar 20, 2000
102,402
8,574
126
i just l33tsp34|< normal words to come up with passwords. very easy to remember
 

LS21

Banned
Nov 27, 2007
3,745
1
0
Originally posted by: Howard
I'd tell you my easy scheme but it'd to pretty easy to figure out mine. :(

i convert the name of the website to pig latin, reverse the order of the letters, trans-numerate the word using order-in-alphabet, then convert that to hexadecimal.


works like a charm