do increased security measures cause anyone else to have even worse passwords?

nageov3t

Lifer
Feb 18, 2004
42,816
83
91
my office has some pretty stringent password rules... 10+ characters, must include a lower case letter, number, and capital letter, can't repeat passwords, passwords must be changed once a month, etc...

but the thing is, I find it leads to me creating even worse passwords. I couldn't mind having one complex password that only changed once every 6 months or rotating between a couple passwords, but with these rules, I end up taking a really basic word (like password), capitalizing the first letter, and throwing a couple numbers at the end.
 
Oct 27, 2007
17,010
1
0
I've never worked in a situation like that but I'd imagine it would be the case. I heard a cool method of creating memorable passwords for things like forum/website registration. You use passwords like thisIsMyAnandtechPassword or myPasswordForATForum. They seem simple but the odds of someone correctly guessing them aren't high.
 

amdhunter

Lifer
May 19, 2003
23,324
219
106
I've noticed that people find pretty simple passwords like P@ssw0rd or something like that, but they are still somewhat harder than the usual simple password...
 

mugs

Lifer
Apr 29, 2003
48,924
45
91
I hate policies that require frequent password changes with no repeats. My last two passwords were Asdfjkl; and jkl;Asdf.
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
<2 words combined with symbol><two digit number><word with symbol>

Increase two digit number to change. But no, statiscally increased security measures are there for a reason - they are proven.

1m@Spider84yesiam


 

darkxshade

Lifer
Mar 31, 2001
13,749
6
81
I have the same problems and I hate it. What I usually do these days is to use some type of math formula so I don't forget what it is. I would use 2 random capitalized letters(RX for example) followed by the 6 numbers you get when dividing 5/7. I would write down R5X7 (pw would be RX714285). Honestly, I don't know why I even bother, who's going to be able to guess my pw anyway, type the pw incorrect 4 times and you get locked out plus the system can only be accessed from at work.
 

BrownTown

Diamond Member
Dec 1, 2005
5,314
1
0
yeah, and the fact I need so many means they are all the same, plus changing is just means changing the number ie Password0, Password1 etc...

Also I have them all written down on a piece of paper in my wallet, and I have seen several people with all their passwords on a sticky note on their monitor.
 

imported_Imp

Diamond Member
Dec 20, 2005
9,148
0
0
I used one of my generic passwords at work, the added variations as needed. Having to change it to a different one every month was stupid though. Ya, maye it might stop the stalker, but it's not like I give it out. I almost got my account locked a few times at the beginning of a new month/period, when I forgot what I changed it to (e.g. which letter did I capitalize, which number did I add/letter). If anything, this constant changing leads to having to write the password down somewhere for someone to read.
 

Bignate603

Lifer
Sep 5, 2000
13,897
1
0
I've started to use dates with the month spelled out. After a month of punching in our anniversary I won't forget it.
 

Cogman

Lifer
Sep 19, 2000
10,278
126
106
Having people change their passwords once a month is excessive. If a password is long enough, it will take far longer for a brute force method to crack it. (and any serious security system should limit the number of tries in a given amount of time)
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
Originally posted by: Imp
I used one of my generic passwords at work, the added variations as needed. Having to change it to a different one every month was stupid though. Ya, maye it might stop the stalker, but it's not like I give it out. I almost got my account locked a few times at the beginning of a new month/period, when I forgot what I changed it to (e.g. which letter did I capitalize, which number did I add/letter). If anything, this constant changing leads to having to write the password down somewhere for someone to read.

But the "auditors" said you need to change it every 4 weeks for security purposes? I mean it's SOX and all and that's what they told us to do! It was one of the level 1 security vulnerabilities - greater than 4 week password change policy!!!!!!! ZOMG, it's SOX!!

I love everything and everybody, but I have a special kind of hate and pure brain smashing anger for IT auditors that can't be described on a message board. And by smashing I mean grab their brain and smash it with your bare hands.
 

imported_Imp

Diamond Member
Dec 20, 2005
9,148
0
0
Originally posted by: darkxshade
type the pw incorrect 4 times and you get locked out plus the system can only be accessed from at work.

Ah, I remember that. I think our limit was 5. We had one IT software support guy at head office reset people's passwords all day long. They kept paper records and there was a couple inch stack at the end of every month. Think I had to take a half-hour 'break' once just to figure out one of my passwords I hadn't used in a long time. It was either that or keep trying, get it locked and call another office for them to reset it; then wait for them to callback to speak to me personally, verify, then reset.
 

Throckmorton

Lifer
Aug 23, 2007
16,830
3
0
I hate when they make you change often. I think it's established that if you make people change passwords too often, with too complex rules, they tend to write it down, creating a security vulnerability.
 

sourceninja

Diamond Member
Mar 8, 2005
8,805
65
91
Let me give you a few of my old passwords, that shoudl help you

I used pattern based passwords. Here's some examples

1qaz=[;.
xsw2@#$4rfv
&YGVVFR$4rfv
MNBdfgIUY456
and one more 9*uIlKnm

Our policy is changing every 3 months. We currently do not allow repeats, but I plan to get that changed eventually. Too busy right now with other major overhauls to bring it up. So pick a pattern and you can get hundreds of variations just by moving it around the keyboard. I actually use one pattern for all my passwords at work, I just remember the first key for each system.
 

DrPizza

Administrator Elite Member Goat Whisperer
Mar 5, 2001
49,606
166
111
www.slatebrookfarm.com
Originally posted by: sourceninja
Let me give you a few of my old passwords, that shoudl help you

I used pattern based passwords. Here's some examples

1qaz=[;.
xsw2@#$4rfv
&YGVVFR$4rfv
MNBdfgIUY456
and one more 9*uIlKnm

Our policy is changing every 3 months. We currently do not allow repeats, but I plan to get that changed eventually. Too busy right now with other major overhauls to bring it up. So pick a pattern and you can get hundreds of variations just by moving it around the keyboard. I actually use one pattern for all my passwords at work, I just remember the first key for each system.

I think I read somewhere on the forums here that if someone's already made it far enough in to start brute force attacking passwords, then your security measures have already failed.
 

Green Man

Golden Member
Jan 21, 2001
1,110
1
0
I don't mind PW complexity, but we got a new Security idiot who had to prove his worth by enacting a PW must be changed every 6 weeks policy.

Screw that A-hole, I took myself off the domain and had my email forwarded.

No one's said anything about it to me and it's been 9 months since.
 

Bill Brasky

Diamond Member
May 18, 2006
4,345
1
0
Originally posted by: sourceninja
Let me give you a few of my old passwords, that shoudl help you

I used pattern based passwords. Here's some examples

1qaz=[;.
xsw2@#$4rfv
&YGVVFR$4rfv
MNBdfgIUY456
and one more 9*uIlKnm

Our policy is changing every 3 months. We currently do not allow repeats, but I plan to get that changed eventually. Too busy right now with other major overhauls to bring it up. So pick a pattern and you can get hundreds of variations just by moving it around the keyboard. I actually use one pattern for all my passwords at work, I just remember the first key for each system.

Hey, that's actually a really good idea. I especially like the last pattern.

My dad uses french words with the vowels dropped and number patterns in between. I thought that was pretty clever.

Originally posted by: Champ
my work password has to be changed every 2 months...my last 4
12345
123456
1234567
12345678

LOL. No letters or punctuation though?
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
Originally posted by: DrPizza
I think I read somewhere on the forums here that if someone's already made it far enough in to start brute force attacking passwords, then your security measures have already failed.

Reference my post about IT auditors.

You're correct, if somebody can actually attempt brute force authentication then you're hosed.

What the internal password policies are for is the inside brute force authentication attack.

Never mind that the entire manufacturing industry is still running WEP for wireless and it's to expensive to fix it.
 

jarfykk

Senior member
Mar 29, 2001
501
1
0
My personal hell: 14 character minimum requiring 2 of each of the following: capital letter, lower case letter, number, symbol. This password must change every 45-days (no repeats, ever...at least in the 3 years I've been here) with reminders coming at 30-35-40-41-42-43-44-45 days out to ENSURE you change it. Used to use different permutations of the same basic password but literally ran out of numbers/symbols/capitalization that weren't repeats. Couple this with photo, smart card + longer-than-normal PIN, and biometric measures and you get the feeling you're not wanted some days...
 
Oct 27, 2007
17,010
1
0
Originally posted by: sourceninja
Let me give you a few of my old passwords, that shoudl help you

I used pattern based passwords. Here's some examples

1qaz=[;.
xsw2@#$4rfv
&YGVVFR$4rfv
MNBdfgIUY456
and one more 9*uIlKnm

Our policy is changing every 3 months. We currently do not allow repeats, but I plan to get that changed eventually. Too busy right now with other major overhauls to bring it up. So pick a pattern and you can get hundreds of variations just by moving it around the keyboard. I actually use one pattern for all my passwords at work, I just remember the first key for each system.

Those are neat. Shouldn't the trailing 'm' be capitalised in the last one?
 

Dr. Detroit

Diamond Member
Sep 25, 2004
8,199
665
126
Just was required ti have number, capital letter, and once of these ! @ # $ in my password with a minimum of 8-characters.

 

ISAslot

Platinum Member
Jan 22, 2001
2,881
97
91
I just use memorable phrases I make up on the fly, then use the first letter of each word, capitalizing some, and converting some to symbols and numbers.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |