Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. I've personally grown to hate the security theatre of rotating my bank passwords every six months, especially because of requirements like "must contain one uppercase, one symbol, one lowercase, one special case and the blood of a unicorn."

I've personally grown to hate the security theatre of rotating my bank passwords every six months, especially because of requirements like "must contain one uppercase, one symbol, one lowercase, one special case and the blood of a unicorn."

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
infosecpasswordscybersecuritysecurity
17 Indlæg 16 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • pheonix@hachyderm.ioP This user is from outside of this forum
    pheonix@hachyderm.ioP This user is from outside of this forum
    pheonix@hachyderm.io
    wrote sidst redigeret af
    #1

    I've personally grown to hate the security theatre of rotating my bank passwords every six months, especially because of requirements like "must contain one uppercase, one symbol, one lowercase, one special case and the blood of a unicorn."

    When mathematically, a simple, grammatically incorrect sentence of 25 characters is much harder for a machine to crack than a gibberish 8-character password with symbols.

    Entropy loves length.

    I love the idea that the most secure key to your digital life could just be a weird little poem or an inside joke that only you know. Security doesn't have to be painful.

    #infosec #passwords #cybersecurity #UX #security #sysadmin #programming #foss #linux #privacy #enshittification #reading #finance

    cursedsql@hachyderm.ioC mossyfoot@pdx.socialM dejahentendu@dice.campD admin@mastodon.slightlycyberpunk.comA lor@goingdark.socialL 15 Replies Last reply
    1
    0
    • pheonix@hachyderm.ioP pheonix@hachyderm.io

      I've personally grown to hate the security theatre of rotating my bank passwords every six months, especially because of requirements like "must contain one uppercase, one symbol, one lowercase, one special case and the blood of a unicorn."

      When mathematically, a simple, grammatically incorrect sentence of 25 characters is much harder for a machine to crack than a gibberish 8-character password with symbols.

      Entropy loves length.

      I love the idea that the most secure key to your digital life could just be a weird little poem or an inside joke that only you know. Security doesn't have to be painful.

      #infosec #passwords #cybersecurity #UX #security #sysadmin #programming #foss #linux #privacy #enshittification #reading #finance

      cursedsql@hachyderm.ioC This user is from outside of this forum
      cursedsql@hachyderm.ioC This user is from outside of this forum
      cursedsql@hachyderm.io
      wrote sidst redigeret af
      #2

      @pheonix entropy has always been a size queen

      1 Reply Last reply
      0
      • pheonix@hachyderm.ioP pheonix@hachyderm.io

        I've personally grown to hate the security theatre of rotating my bank passwords every six months, especially because of requirements like "must contain one uppercase, one symbol, one lowercase, one special case and the blood of a unicorn."

        When mathematically, a simple, grammatically incorrect sentence of 25 characters is much harder for a machine to crack than a gibberish 8-character password with symbols.

        Entropy loves length.

        I love the idea that the most secure key to your digital life could just be a weird little poem or an inside joke that only you know. Security doesn't have to be painful.

        #infosec #passwords #cybersecurity #UX #security #sysadmin #programming #foss #linux #privacy #enshittification #reading #finance

        mossyfoot@pdx.socialM This user is from outside of this forum
        mossyfoot@pdx.socialM This user is from outside of this forum
        mossyfoot@pdx.social
        wrote sidst redigeret af
        #3

        @pheonix every security person has this link memorized by now:
        https://m.xkcd.com/936/

        1 Reply Last reply
        0
        • pheonix@hachyderm.ioP pheonix@hachyderm.io

          I've personally grown to hate the security theatre of rotating my bank passwords every six months, especially because of requirements like "must contain one uppercase, one symbol, one lowercase, one special case and the blood of a unicorn."

          When mathematically, a simple, grammatically incorrect sentence of 25 characters is much harder for a machine to crack than a gibberish 8-character password with symbols.

          Entropy loves length.

          I love the idea that the most secure key to your digital life could just be a weird little poem or an inside joke that only you know. Security doesn't have to be painful.

          #infosec #passwords #cybersecurity #UX #security #sysadmin #programming #foss #linux #privacy #enshittification #reading #finance

          dejahentendu@dice.campD This user is from outside of this forum
          dejahentendu@dice.campD This user is from outside of this forum
          dejahentendu@dice.camp
          wrote sidst redigeret af
          #4

          @pheonix sometimes, when I'm driving, my kiddo logs into my work phone to see what an alert was about. They always complain that my password is misspelled. I just smile and shrug. Long and simple, but just a little weird.

          1 Reply Last reply
          0
          • pheonix@hachyderm.ioP pheonix@hachyderm.io

            I've personally grown to hate the security theatre of rotating my bank passwords every six months, especially because of requirements like "must contain one uppercase, one symbol, one lowercase, one special case and the blood of a unicorn."

            When mathematically, a simple, grammatically incorrect sentence of 25 characters is much harder for a machine to crack than a gibberish 8-character password with symbols.

            Entropy loves length.

            I love the idea that the most secure key to your digital life could just be a weird little poem or an inside joke that only you know. Security doesn't have to be painful.

            #infosec #passwords #cybersecurity #UX #security #sysadmin #programming #foss #linux #privacy #enshittification #reading #finance

            admin@mastodon.slightlycyberpunk.comA This user is from outside of this forum
            admin@mastodon.slightlycyberpunk.comA This user is from outside of this forum
            admin@mastodon.slightlycyberpunk.com
            wrote sidst redigeret af
            #5

            @pheonix Password expiration has not been considered best practice in many years. If they're still doing that I've gotta wonder what other wildly obsolete security measures they might be relying on. Consider a new bank, I have four and none of them do that shit lol

            https://www.ncsc.gov.uk/pdfs/blog-post/problems-forcing-regular-password-expiry.pdf

            https://community.isc2.org/t5/Industry-News/Microsoft-and-NIST-Say-Password-Expiration-Policies-Are-No/td-p/39893

            1 Reply Last reply
            0
            • pheonix@hachyderm.ioP pheonix@hachyderm.io

              I've personally grown to hate the security theatre of rotating my bank passwords every six months, especially because of requirements like "must contain one uppercase, one symbol, one lowercase, one special case and the blood of a unicorn."

              When mathematically, a simple, grammatically incorrect sentence of 25 characters is much harder for a machine to crack than a gibberish 8-character password with symbols.

              Entropy loves length.

              I love the idea that the most secure key to your digital life could just be a weird little poem or an inside joke that only you know. Security doesn't have to be painful.

              #infosec #passwords #cybersecurity #UX #security #sysadmin #programming #foss #linux #privacy #enshittification #reading #finance

              lor@goingdark.socialL This user is from outside of this forum
              lor@goingdark.socialL This user is from outside of this forum
              lor@goingdark.social
              wrote sidst redigeret af
              #6

              @pheonix

              The blood of the unicorn is getting harder and harder to source!

              levzadov@kolektiva.socialL 1 Reply Last reply
              0
              • pheonix@hachyderm.ioP pheonix@hachyderm.io

                I've personally grown to hate the security theatre of rotating my bank passwords every six months, especially because of requirements like "must contain one uppercase, one symbol, one lowercase, one special case and the blood of a unicorn."

                When mathematically, a simple, grammatically incorrect sentence of 25 characters is much harder for a machine to crack than a gibberish 8-character password with symbols.

                Entropy loves length.

                I love the idea that the most secure key to your digital life could just be a weird little poem or an inside joke that only you know. Security doesn't have to be painful.

                #infosec #passwords #cybersecurity #UX #security #sysadmin #programming #foss #linux #privacy #enshittification #reading #finance

                mkj@social.mkj.earthM This user is from outside of this forum
                mkj@social.mkj.earthM This user is from outside of this forum
                mkj@social.mkj.earth
                wrote sidst redigeret af
                #7

                @pheonix And by the time you're up to six words Diceware, that's the same level of security as 15 random alphanumeric characters (single-cased), at about 45-50 characters (arguably more easily) typed.

                Both about 2^77.

                Yet I keep thinking that "dribble pusher swipe defiling mocker clobber" is likely easier for most people (with enough grasp of English to read this post) to remember and even type out than "zaiv3thaes7lah1".

                #passwords #Diceware

                1 Reply Last reply
                0
                • pheonix@hachyderm.ioP pheonix@hachyderm.io

                  I've personally grown to hate the security theatre of rotating my bank passwords every six months, especially because of requirements like "must contain one uppercase, one symbol, one lowercase, one special case and the blood of a unicorn."

                  When mathematically, a simple, grammatically incorrect sentence of 25 characters is much harder for a machine to crack than a gibberish 8-character password with symbols.

                  Entropy loves length.

                  I love the idea that the most secure key to your digital life could just be a weird little poem or an inside joke that only you know. Security doesn't have to be painful.

                  #infosec #passwords #cybersecurity #UX #security #sysadmin #programming #foss #linux #privacy #enshittification #reading #finance

                  sinvega@mas.toS This user is from outside of this forum
                  sinvega@mas.toS This user is from outside of this forum
                  sinvega@mas.to
                  wrote sidst redigeret af
                  #8

                  @pheonix it is absurd to me that the software I know of that let me do a blank text field with a blank text prompt reminder, and thus is more secure than any other system I've seen, was windows 8

                  1 Reply Last reply
                  0
                  • pheonix@hachyderm.ioP pheonix@hachyderm.io

                    I've personally grown to hate the security theatre of rotating my bank passwords every six months, especially because of requirements like "must contain one uppercase, one symbol, one lowercase, one special case and the blood of a unicorn."

                    When mathematically, a simple, grammatically incorrect sentence of 25 characters is much harder for a machine to crack than a gibberish 8-character password with symbols.

                    Entropy loves length.

                    I love the idea that the most secure key to your digital life could just be a weird little poem or an inside joke that only you know. Security doesn't have to be painful.

                    #infosec #passwords #cybersecurity #UX #security #sysadmin #programming #foss #linux #privacy #enshittification #reading #finance

                    sinvega@mas.toS This user is from outside of this forum
                    sinvega@mas.toS This user is from outside of this forum
                    sinvega@mas.to
                    wrote sidst redigeret af
                    #9

                    @pheonix "But your password can be brute force!"

                    sure but it's very very long

                    "what if you forget?"

                    I won't, because of the prompt

                    "but the prompt will give it away!"

                    anyone who can figure out what the fuck that prompt means is a PSYCHIC ALIEN STALKER

                    1 Reply Last reply
                    0
                    • pheonix@hachyderm.ioP pheonix@hachyderm.io

                      I've personally grown to hate the security theatre of rotating my bank passwords every six months, especially because of requirements like "must contain one uppercase, one symbol, one lowercase, one special case and the blood of a unicorn."

                      When mathematically, a simple, grammatically incorrect sentence of 25 characters is much harder for a machine to crack than a gibberish 8-character password with symbols.

                      Entropy loves length.

                      I love the idea that the most secure key to your digital life could just be a weird little poem or an inside joke that only you know. Security doesn't have to be painful.

                      #infosec #passwords #cybersecurity #UX #security #sysadmin #programming #foss #linux #privacy #enshittification #reading #finance

                      marcusmasto@mas.toM This user is from outside of this forum
                      marcusmasto@mas.toM This user is from outside of this forum
                      marcusmasto@mas.to
                      wrote sidst redigeret af
                      #10

                      @pheonix

                      So would ColourlessGreenIdeasSleepFuriously be OK?

                      #NoamChomsky

                      1 Reply Last reply
                      0
                      • pheonix@hachyderm.ioP pheonix@hachyderm.io

                        I've personally grown to hate the security theatre of rotating my bank passwords every six months, especially because of requirements like "must contain one uppercase, one symbol, one lowercase, one special case and the blood of a unicorn."

                        When mathematically, a simple, grammatically incorrect sentence of 25 characters is much harder for a machine to crack than a gibberish 8-character password with symbols.

                        Entropy loves length.

                        I love the idea that the most secure key to your digital life could just be a weird little poem or an inside joke that only you know. Security doesn't have to be painful.

                        #infosec #passwords #cybersecurity #UX #security #sysadmin #programming #foss #linux #privacy #enshittification #reading #finance

                        retreival9096@hachyderm.ioR This user is from outside of this forum
                        retreival9096@hachyderm.ioR This user is from outside of this forum
                        retreival9096@hachyderm.io
                        wrote sidst redigeret af
                        #11

                        @pheonix Or, choose a 6 digit pin, but no repeated digits or 3 or more digits in sequence" -- which of course makes it effectively *less* than 6 digits randomness (no repeats brings it down to 10!/4!, but I'm having a hard time estimating the cost of no sequences of 3 or more consecutive digits).

                        1 Reply Last reply
                        0
                        • pheonix@hachyderm.ioP pheonix@hachyderm.io

                          I've personally grown to hate the security theatre of rotating my bank passwords every six months, especially because of requirements like "must contain one uppercase, one symbol, one lowercase, one special case and the blood of a unicorn."

                          When mathematically, a simple, grammatically incorrect sentence of 25 characters is much harder for a machine to crack than a gibberish 8-character password with symbols.

                          Entropy loves length.

                          I love the idea that the most secure key to your digital life could just be a weird little poem or an inside joke that only you know. Security doesn't have to be painful.

                          #infosec #passwords #cybersecurity #UX #security #sysadmin #programming #foss #linux #privacy #enshittification #reading #finance

                          greem@cyberplace.socialG This user is from outside of this forum
                          greem@cyberplace.socialG This user is from outside of this forum
                          greem@cyberplace.social
                          wrote sidst redigeret af
                          #12

                          @pheonix mine have changed style over the years, but my most frequently used are now made of Things I Can See when setting a new one.

                          Kinda like "Terrier Cheese Thief Bastard" or similar 🙂

                          1 Reply Last reply
                          0
                          • pheonix@hachyderm.ioP pheonix@hachyderm.io

                            I've personally grown to hate the security theatre of rotating my bank passwords every six months, especially because of requirements like "must contain one uppercase, one symbol, one lowercase, one special case and the blood of a unicorn."

                            When mathematically, a simple, grammatically incorrect sentence of 25 characters is much harder for a machine to crack than a gibberish 8-character password with symbols.

                            Entropy loves length.

                            I love the idea that the most secure key to your digital life could just be a weird little poem or an inside joke that only you know. Security doesn't have to be painful.

                            #infosec #passwords #cybersecurity #UX #security #sysadmin #programming #foss #linux #privacy #enshittification #reading #finance

                            madic@chaos.socialM This user is from outside of this forum
                            madic@chaos.socialM This user is from outside of this forum
                            madic@chaos.social
                            wrote sidst redigeret af
                            #13

                            @pheonix And there are still many Systems that don't allow long passwords...
                            Or, way more terrible, the Input field allows an undefined lengths but the Password gets cut silently at some point

                            1 Reply Last reply
                            0
                            • pheonix@hachyderm.ioP pheonix@hachyderm.io

                              I've personally grown to hate the security theatre of rotating my bank passwords every six months, especially because of requirements like "must contain one uppercase, one symbol, one lowercase, one special case and the blood of a unicorn."

                              When mathematically, a simple, grammatically incorrect sentence of 25 characters is much harder for a machine to crack than a gibberish 8-character password with symbols.

                              Entropy loves length.

                              I love the idea that the most secure key to your digital life could just be a weird little poem or an inside joke that only you know. Security doesn't have to be painful.

                              #infosec #passwords #cybersecurity #UX #security #sysadmin #programming #foss #linux #privacy #enshittification #reading #finance

                              johns_priv@mastodon.socialJ This user is from outside of this forum
                              johns_priv@mastodon.socialJ This user is from outside of this forum
                              johns_priv@mastodon.social
                              wrote sidst redigeret af
                              #14

                              @pheonix Years ago, as local support I recommended people to use a phrase from a movie, song, or poem they liked as passphrase for the disk encryption.
                              I'll always remember the guy humming "somewhere over the rainbow" while unlocking his laptop.

                              I didn't have the courage to tell him everyone knew his passphrase xDD

                              1 Reply Last reply
                              0
                              • lor@goingdark.socialL lor@goingdark.social

                                @pheonix

                                The blood of the unicorn is getting harder and harder to source!

                                levzadov@kolektiva.socialL This user is from outside of this forum
                                levzadov@kolektiva.socialL This user is from outside of this forum
                                levzadov@kolektiva.social
                                wrote sidst redigeret af
                                #15

                                @lor @pheonix

                                Only invisible pink unicorns.

                                1 Reply Last reply
                                0
                                • pheonix@hachyderm.ioP pheonix@hachyderm.io

                                  I've personally grown to hate the security theatre of rotating my bank passwords every six months, especially because of requirements like "must contain one uppercase, one symbol, one lowercase, one special case and the blood of a unicorn."

                                  When mathematically, a simple, grammatically incorrect sentence of 25 characters is much harder for a machine to crack than a gibberish 8-character password with symbols.

                                  Entropy loves length.

                                  I love the idea that the most secure key to your digital life could just be a weird little poem or an inside joke that only you know. Security doesn't have to be painful.

                                  #infosec #passwords #cybersecurity #UX #security #sysadmin #programming #foss #linux #privacy #enshittification #reading #finance

                                  keraba@mastodon.socialK This user is from outside of this forum
                                  keraba@mastodon.socialK This user is from outside of this forum
                                  keraba@mastodon.social
                                  wrote sidst redigeret af
                                  #16

                                  @pheonix

                                  Regarding the length of your poem, remember that English has about 1.3 bit of entropy per letter.

                                  1 Reply Last reply
                                  0
                                  • pheonix@hachyderm.ioP pheonix@hachyderm.io

                                    I've personally grown to hate the security theatre of rotating my bank passwords every six months, especially because of requirements like "must contain one uppercase, one symbol, one lowercase, one special case and the blood of a unicorn."

                                    When mathematically, a simple, grammatically incorrect sentence of 25 characters is much harder for a machine to crack than a gibberish 8-character password with symbols.

                                    Entropy loves length.

                                    I love the idea that the most secure key to your digital life could just be a weird little poem or an inside joke that only you know. Security doesn't have to be painful.

                                    #infosec #passwords #cybersecurity #UX #security #sysadmin #programming #foss #linux #privacy #enshittification #reading #finance

                                    b3n@x0r.beB This user is from outside of this forum
                                    b3n@x0r.beB This user is from outside of this forum
                                    b3n@x0r.be
                                    wrote sidst redigeret af
                                    #17

                                    @pheonix
                                    It'H@rd2FindUnic0rnB|00d

                                    1 Reply Last reply
                                    0
                                    • jwcph@helvede.netJ jwcph@helvede.net shared this topic
                                    Svar
                                    • Svar som emne
                                    Login for at svare
                                    • Ældste til nyeste
                                    • Nyeste til ældste
                                    • Most Votes


                                    • Log ind

                                    • Har du ikke en konto? Tilmeld

                                    • Login or register to search.
                                    Powered by NodeBB Contributors
                                    Graciously hosted by data.coop
                                    • First post
                                      Last post
                                    0
                                    • Hjem
                                    • Seneste
                                    • Etiketter
                                    • Populære
                                    • Verden
                                    • Bruger
                                    • Grupper