1. Attachments are working again! Check out this thread for more details and to report any other bugs.

Another silly password test

Discussion in 'Fred's House of Pancakes' started by bwilson4web, Nov 16, 2016.

  1. bwilson4web

    bwilson4web BMW i3 and Model 3

    Joined:
    Nov 25, 2005
    27,228
    15,442
    0
    Location:
    Huntsville AL
    Vehicle:
    2018 Tesla Model 3
    Model:
    Prime Plus
    So this morning I was resetting my passwords since the primary one was about to expire. E-mail changed, no problem. Disk drive encryption, no problem. Corporate password ... problem.

    They ask "three questions" and if you don't get the exact, original speeling or Case wrong, you can't change it. Regardless, the old password worked and I called up the help desk who got me to a place to replace the three questions. Only this time, I answered, "one", "two", and "three" which reminds me of:


    "What do you mean, an African or a European swallow?"

    Bob Wilson
     
  2. Mendel Leisk

    Mendel Leisk Senior Member

    Joined:
    Oct 17, 2010
    54,907
    38,356
    80
    Location:
    Greater Vancouver, British Columbia, Canada
    Vehicle:
    2010 Prius
    Model:
    Touring
    Yeah be real careful with your security question answers, gotta be exact, or no entry for you.

    I read lately, one really bullet-proof method for devising a password: use four simple but disparate words, strung together. Supposedly very hard to crack. For example:

    dogfarmcarfan
     
    Coast Cruiser likes this.
  3. Trollbait

    Trollbait It's a D&D thing

    Joined:
    Feb 7, 2006
    21,845
    11,387
    0
    Location:
    eastern Pennsylvania
    Vehicle:
    Other Non-Hybrid
    A pass phrase instead of a password. Learned about them on xkcd. I think they need spaces between the words, otherwise a computer can brute strength break them about as quickly as a typical password today.
     
    Coast Cruiser and RCO like this.
  4. RCO

    RCO Senior Member

    Joined:
    Aug 31, 2016
    3,709
    5,183
    0
    Location:
    Cornwall
    Vehicle:
    Other Hybrid
    Model:
    N/A
    dogfartcarfog ????
     
  5. Mendel Leisk

    Mendel Leisk Senior Member

    Joined:
    Oct 17, 2010
    54,907
    38,356
    80
    Location:
    Greater Vancouver, British Columbia, Canada
    Vehicle:
    2010 Prius
    Model:
    Touring
    "dog" and "fart" are too contiguous: try again, lol.

    (Think I subconsciously was thinking dogfart though...)

    (Our Shiba sometimes let's one go, then does his Shiba sideway glance trick.)
     
    bisco and Coast Cruiser like this.
  6. Mendel Leisk

    Mendel Leisk Senior Member

    Joined:
    Oct 17, 2010
    54,907
    38,356
    80
    Location:
    Greater Vancouver, British Columbia, Canada
    Vehicle:
    2010 Prius
    Model:
    Touring
    I've never though of using spaces in a password. Just Googling now: apparently spaces not allowed often?
     
  7. Trollbait

    Trollbait It's a D&D thing

    Joined:
    Feb 7, 2006
    21,845
    11,387
    0
    Location:
    eastern Pennsylvania
    Vehicle:
    Other Non-Hybrid
    I was thinking the phrase of random words needed spaces to work, but apparently that isn't so.
    [​IMG]
     
    fuzzy1, RCO and Mendel Leisk like this.
  8. RCO

    RCO Senior Member

    Joined:
    Aug 31, 2016
    3,709
    5,183
    0
    Location:
    Cornwall
    Vehicle:
    Other Hybrid
    Model:
    N/A
    I've known lots of people like that, but never me.:whistle:

    Some characters like , and ( )= etc could be used instead of spaces. I know that using numbers to represent letters is easily cracked with hack algorithms, BTW.
     
    Coast Cruiser likes this.
  9. Coast Cruiser

    Coast Cruiser Senior Member

    Joined:
    Mar 12, 2016
    2,267
    2,571
    0
    Location:
    Pacific Coast Highway
    Vehicle:
    2016 Prius
    Model:
    Three
    My bank requires capital letters, small letters, numbers, and symbols.... And spaces if you want.

    What happened to the simple (before hacking) days of just using our birthday? :ROFLMAO:
     
    RCO likes this.
  10. ETC(SS)

    ETC(SS) The OTHER One Percenter.....

    Joined:
    Oct 28, 2010
    7,704
    6,504
    0
    Location:
    Redneck Riviera (Gulf South)
    Vehicle:
    Other Non-Hybrid
    Model:
    N/A
    The trouble is..........
    All IT people are soulless nebbishes who NEVER &*(%^%E##@!@! talk to each other (or anybody else!!)

    We use passphrases at big phone, but about one in every 4 IT people out in the real world will bounce my password change if I attempt the same strategery because it fails one of their buzz-kill "rules" (special characters, spaces, dictionary words, etc)
    Fortunately, I have a rolling system that seems to work, can be changed every 90 days, and meets about 90 percent of the password rules out there. One of these days I suppose I'll use a manager, but having to remember 1,438 different passwords seems to be a great tripwire for detecting the Alzheimer's.

    My credit is frozen and my checking account is protected by abject poverty - so I'm not really all that worried about privacy, but I do rotate my passwords regularly and keep them as robust as the character limits (another rule that varies) allow.


    All except my PC login.
    Think they'll ever guess it's H8Cl1nt0n! ??? :D
    (my 1994 'go-to' password!! It's served me well for over a decade!!)
     
    RCO likes this.
  11. Mendel Leisk

    Mendel Leisk Senior Member

    Joined:
    Oct 17, 2010
    54,907
    38,356
    80
    Location:
    Greater Vancouver, British Columbia, Canada
    Vehicle:
    2010 Prius
    Model:
    Touring
    Do you still remember your military "number"? Up here they use Social Insurance Number, it's basically hardwired now, know it better than my grandkids names. :whistle:

    One trick I found, for aiding short term memory at least: mutter the number, it sticks better. I was a checker for quite a while: I'd need to retain a number for a minute or two. Was always muttering away, lol.
     
  12. ETC(SS)

    ETC(SS) The OTHER One Percenter.....

    Joined:
    Oct 28, 2010
    7,704
    6,504
    0
    Location:
    Redneck Riviera (Gulf South)
    Vehicle:
    Other Non-Hybrid
    Model:
    N/A
    My military ID # is the same as my SSN without the dashes.

    We always used to say: "Whataya goona do? Take the dashes out of my Social Security Number???"
     
    Mendel Leisk likes this.
  13. Mendel Leisk

    Mendel Leisk Senior Member

    Joined:
    Oct 17, 2010
    54,907
    38,356
    80
    Location:
    Greater Vancouver, British Columbia, Canada
    Vehicle:
    2010 Prius
    Model:
    Touring
    It's interesting how you can remember a long number better, with dashes or spaces. Breaks it up into mental meals.
     
    RCO likes this.
  14. Coast Cruiser

    Coast Cruiser Senior Member

    Joined:
    Mar 12, 2016
    2,267
    2,571
    0
    Location:
    Pacific Coast Highway
    Vehicle:
    2016 Prius
    Model:
    Three
    You just made me hungry. I'm jumping in my Prius and headed to McDonald's. :ROFLMAO:
    Later, gators.





    merged back to back posts as usual



    I love those "mental meals." I don't get fat.
     
    #14 Coast Cruiser, Nov 17, 2016
    Last edited by a moderator: Nov 18, 2016
    RCO and Mendel Leisk like this.
  15. RRxing

    RRxing Senior Member

    Joined:
    Jul 7, 2009
    2,518
    1,790
    0
    Location:
    NEPA
    Vehicle:
    Other Hybrid
    Model:
    Limited
    Laden or unladen?
     
  16. bwilson4web

    bwilson4web BMW i3 and Model 3

    Joined:
    Nov 25, 2005
    27,228
    15,442
    0
    Location:
    Huntsville AL
    Vehicle:
    2018 Tesla Model 3
    Model:
    Prime Plus
    The better systems use an RSA token:
    [​IMG]
    The six numbers change every minute. So you reuse the same prefix/suffix with the number and it makes a unique, one-time-only, password.

    Bob Wilson
     
  17. bhtooefr

    bhtooefr Senior Member

    Joined:
    Apr 4, 2016
    1,396
    1,489
    0
    Location:
    Newark, OH, USA
    Vehicle:
    2016 Prius
    Model:
    Three
    And then my client's preferred login method involves a smart card. Looks just like a chip credit card, and is in fact similar technology.

    I really just use a password manager for everything, and then store the answers to the security questions in there, too. Most of my passwords, I've never even seen, I just copy and paste them out of the manager, it generates them. KeePass is my password manager of choice, largely because it handles password management in a local file, which I keep on my server and my phone.
     
  18. Rebound

    Rebound Senior Member

    Joined:
    Mar 11, 2010
    3,964
    2,610
    0
    Location:
    Portland, OR
    Vehicle:
    2012 Prius Plug-in
    Model:
    Plug-in Base
    Just create a phrase and use it. Not very hard to do:

    I can't stand my ex-wife one bit!

    Icsmx-w1b!

    Easy to remember, easy to enter. Lots of entropy.
     
    RCO likes this.
  19. fuzzy1

    fuzzy1 Senior Member

    Joined:
    Feb 26, 2009
    17,184
    10,087
    90
    Location:
    Western Washington
    Vehicle:
    Other Hybrid
    Model:
    N/A
    But this condensed version suffers the same low entropy problem as the 'hard to remember' version in the cartoon.
     
    RCO likes this.
  20. Rebound

    Rebound Senior Member

    Joined:
    Mar 11, 2010
    3,964
    2,610
    0
    Location:
    Portland, OR
    Vehicle:
    2012 Prius Plug-in
    Model:
    Plug-in Base
    Why? It's 80 bits. And you cannot make a four word password on most systems. I use pass phrases like this all the time. They're very easy to remember.
     
    #20 Rebound, Nov 18, 2016
    Last edited: Nov 18, 2016