logoalt Hacker News

mikestewtoday at 2:28 PM5 repliesview on HN

”Finally, the company should have enforced a strong password policy that would have prevented our heroes from finding dozens of accounts with “winter2023!” as the password.”

Capitalize that “w”, and you’ve got a password that will pass most PWD policies. Why do they think it was “winter2023!” to begin with? In 90 days when the PWD expires, well, it will be spring of the next year, so…

The better idea is to require passwords with some real entropy, and get rid of expiring passwords. It’s not 1999 anymore.


Replies

alt227today at 4:30 PM

Expiring passwords are one of my biggest gripes, and I still see them everywhere

show 3 replies
Xeoncrosstoday at 2:33 PM

1. Open a web browser and do a search

2. Read until you find a sentence that you like.

3. Use it as your password

show 3 replies
samrustoday at 3:08 PM

I swear if the ghouls running things had abit more decency and allowed people to actually access and controll their passkeys then that would be the future, everyone would adopt it. The experience is so nice with key pair exchange for ssh. Its just that there i have thr security of knowing exactly where my secret is and how i can manage it, its just a file and i can move it like a file

Nobody wants the risk of getting locked out because of apple and googles walled garden bullshit

James_Ktoday at 3:55 PM

Letting users pick their own passwords has always been a mistake. If passwords are needed, the system should choose them.

show 2 replies