# bl0w-m3 does not meet our password requirements

**URL:** <https://boards.straightdope.com/t/bl0w-m3-does-not-meet-our-password-requirements/493204>\
**Category:** The BBQ Pit\
**Created:** [April 15, 2009, 6:35pm UTC](https://boards.straightdope.com/t/bl0w-m3-does-not-meet-our-password-requirements/493204 "2009-04-15T18:35:32Z")\
**Posts on this page:** 20\
**Page:** 2

<div class="post-metadata">

**Author:** ![Bartman](https://avatars.discourse-cdn.com/v4/letter/b/779978/32.png) [@Bartman](https://boards.straightdope.com/u/Bartman)\
**Post date:** [April 16, 2009, 1:47am UTC](https://boards.straightdope.com/t/bl0w-m3-does-not-meet-our-password-requirements/493204/21 "2009-04-16T01:47:53Z")

</div>

> [@Manduck](#):
>
> I don’t understand the second requirement. How can it have been “changed” if you’re supplying a new password?😕

This is to prevent someone from quickly changing their password a few times to get past the “has not been used in the previous three password changes” requirement. With the rules as listed in place, you could still do it but it would take you three days before you could get back to password #1.

---

<div class="post-metadata">

**Author:** ![Bartman](https://avatars.discourse-cdn.com/v4/letter/b/779978/32.png) [@Bartman](https://boards.straightdope.com/u/Bartman)\
**Post date:** [April 16, 2009, 2:07am UTC](https://boards.straightdope.com/t/bl0w-m3-does-not-meet-our-password-requirements/493204/22 "2009-04-16T02:07:13Z")

</div>

> [@Lemur866](#):
>
> And this is totally retarded. It’s one thing to expect someone to have a strong password and change it every few months. It’s impossible if they have to have several different strong passwords and change them every few months. Why can’t they give every employee one set of credentials that can be given permissions to use different systems?

There are a lot of tools out there trying to do this… but depending on your systems this can be devilishly hard. On my systems 99% everything is tied to the Windows authenitcation. We use tools to synch this with the systems our users are likely to use.

But once you get away from the well traveled paths of Active Directory things get wilder. In addition to Windows I have HP-UX, Solaris, AIX, Tru-64, Linux (RedHat, SuSE, & Debian), FreeBSD, NetBSD, OpenBSD, OpenVMS, iSeries (AS/400), NonStop, zOS, and a few I’ve forgotten as well. And most of those I have in different versions as well.

And that is just the Operating Systems. Lots of different applications have their own authentication tools. Many allow OS authentication methods some don’t. I have a password database (password protected of course 🙂 ) with over a thousand entries just for the use of my sys admin team.

Where you tend to run into these kinds of multiple authentications is in orginziations that are large and or old. That’s where you see lots of mish mashed solutions, some decades old, where everything is running on non-compatable technologies. Take **Edward The Head** ’s example at the FAA. I’m willing to bet that every seperate system he mentioned is on a different piece of technology. I would love to get everything down to single user sign on. But given what I have I don’t forsee that happening within the next 20 years or less.

---

<div class="post-metadata">

**Author:** ![Lilacs](https://avatars.discourse-cdn.com/v4/letter/l/e9c0ed/32.png) [@Lilacs](https://boards.straightdope.com/u/Lilacs)\
**Post date:** [April 16, 2009, 2:28am UTC](https://boards.straightdope.com/t/bl0w-m3-does-not-meet-our-password-requirements/493204/23 "2009-04-16T02:28:11Z")

</div>

At this point, I have about 5 different passwords at work for different things.

At one point they were mostly the same. Then their change dates were all different, some I go through two passwords before I change another.

For our newest software, we had to have someone come and install it and OK it on our computers. The Sheriff’s department takes their shit seriously. So, I had to tell their IT guy my password. He told me my password was too complicated. Well…isn’t that the point?

My favorite is the RSA secur id token. I have to have a password to log on to my computer. Then to open this particular software, a password number to enter in addtion to my ever changing pass token number. And more often than not, I have to enter a SECOND token number just in case, you know, I’m trying to get in illegally and maybe will be caught in that minute wait for the number to change.

---

<div class="post-metadata">

**Author:** ![Guinastasia](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/guinastasia/32/5751_2.png) [@Guinastasia](https://boards.straightdope.com/u/Guinastasia)\
**Post date:** [April 16, 2009, 2:32am UTC](https://boards.straightdope.com/t/bl0w-m3-does-not-meet-our-password-requirements/493204/24 "2009-04-16T02:32:12Z")

</div>

> [@MeanOldLady](#):
>
> I worked with a lady who used to keep all her passwords written down on a notepad inside her (unlocked) drawer.

But…Neville did that…and that’s how Sirius Black got into Gryffindor Tower!!!

😃  
(I confess, I usually tend to use the same password for various things…yeah, I know. One time I just picked words of things around me-like a book, the name of a bottle of handcream, etc)

---

<div class="post-metadata">

**Author:** ![Palo\_Verde](https://avatars.discourse-cdn.com/v4/letter/p/65b543/32.png) [@Palo\_Verde](https://boards.straightdope.com/u/Palo_Verde)\
**Post date:** [April 16, 2009, 2:49am UTC](https://boards.straightdope.com/t/bl0w-m3-does-not-meet-our-password-requirements/493204/25 "2009-04-16T02:49:48Z")

</div>

The ones that drive me crazy are the ones that don’t tell you the requirements until you try to supply one: For example:

Computer: Enter new password  
Me: A- U- T- Z

Computer: Password must have at least 8 digits  
Me: A- U- T- Z- A- U- T- Z

Computer: Password must have at least one number in it  
ME: A- U- T- Z- 2- 0- 0- 9

Computer: Password must not end in an odd number or start with an A, G, T, H, J, or S  
Me: ???

If they have requirements, they should tell you ahead of time! Grrrr!

---

<div class="post-metadata">

**Author:** ![Some\_FNG](https://avatars.discourse-cdn.com/v4/letter/s/48db29/32.png) [@Some\_FNG](https://boards.straightdope.com/u/Some_FNG)\
**Post date:** [April 16, 2009, 3:52am UTC](https://boards.straightdope.com/t/bl0w-m3-does-not-meet-our-password-requirements/493204/26 "2009-04-16T03:52:25Z")

</div>

Military stuff makes for great passwords (in my cubicle farm)- M1A2Abrams, M1126Stryker, etc.  
They’re easy for me to remember, they satisfy the alphanumeric requirements and no one in my office would ever guess them. YMMV, of course.

---

<div class="post-metadata">

**Author:** ![Trepa\_Mayfield](https://avatars.discourse-cdn.com/v4/letter/t/edb3f5/32.png) [@Trepa\_Mayfield](https://boards.straightdope.com/u/Trepa_Mayfield)\
**Post date:** [April 16, 2009, 4:25am UTC](https://boards.straightdope.com/t/bl0w-m3-does-not-meet-our-password-requirements/493204/27 "2009-04-16T04:25:43Z")

</div>

> [@kaylasdad99](#):
>
> So “guLLible63” would be just fine then, right?
> 
> 😃

But…gullible is in the dictionary.

---

<div class="post-metadata">

**Author:** ![Bear\_Nenno](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bear_nenno/32/3358_2.png) [@Bear\_Nenno](https://boards.straightdope.com/u/Bear_Nenno)\
**Post date:** [April 16, 2009, 5:43am UTC](https://boards.straightdope.com/t/bl0w-m3-does-not-meet-our-password-requirements/493204/28 "2009-04-16T05:43:56Z")

</div>

My password requires:  
At least 2 Capital Letters  
At least 2 lowercase letters  
At least 2 special characters like !@#$%  
Changed like every 90 or 120 days  
8-15 digits long or something like that  
can’t repeat with last 10 passwords

Holy crap. I have a set password and then all I change is the letters in the begining. I learned that technique from a poster on this board. Since I need two capitals and two lowercase, I just move down the keyboard every time I need to change it.  
So if right now my password is HHhh1234!@, then next month I will change it to JJjj1234!@, then KKkk1234!@. Works great and I can always remember my 15 digit password.

---

<div class="post-metadata">

**Author:** ![Boyo\_Jim](https://avatars.discourse-cdn.com/v4/letter/b/87869e/32.png) [@Boyo\_Jim](https://boards.straightdope.com/u/Boyo_Jim)\
**Post date:** [April 16, 2009, 10:59am UTC](https://boards.straightdope.com/t/bl0w-m3-does-not-meet-our-password-requirements/493204/29 "2009-04-16T10:59:00Z")

</div>

> [@Bear\_Nenno](#):
>
> My password requires:  
> At least 2 Capital Letters  
> At least 2 lowercase letters  
> At least 2 special characters like !@#$%  
> Changed like every 90 or 120 days  
> 8-15 digits long or something like that  
> can’t repeat with last 10 passwords
> 
> Holy crap. I have a set password and then all I change is the letters in the begining. I learned that technique from a poster on this board. Since I need two capitals and two lowercase, I just move down the keyboard every time I need to change it.  
> So if right now my password is HHhh1234!@, then next month I will change it to JJjj1234!@, then KKkk1234!@. Works great and I can always remember my 15 digit password.

Where is it you work again?

---

<div class="post-metadata">

**Author:** ![Earthworm\_Jim](https://avatars.discourse-cdn.com/v4/letter/e/f07891/32.png) [@Earthworm\_Jim](https://boards.straightdope.com/u/Earthworm_Jim)\
**Post date:** [April 16, 2009, 11:04am UTC](https://boards.straightdope.com/t/bl0w-m3-does-not-meet-our-password-requirements/493204/30 "2009-04-16T11:04:49Z")

</div>

Looks like Symantecs password requirements. That crap was ridiculous.

---

<div class="post-metadata">

**Author:** ![enipla](https://avatars.discourse-cdn.com/v4/letter/e/54ee81/32.png) [@enipla](https://boards.straightdope.com/u/enipla)\
**Post date:** [April 16, 2009, 1:17pm UTC](https://boards.straightdope.com/t/bl0w-m3-does-not-meet-our-password-requirements/493204/31 "2009-04-16T13:17:06Z")

</div>

> [@Bear\_Nenno](#):
>
> My password requires:  
> At least 2 Capital Letters  
> At least 2 lowercase letters  
> At least 2 special characters like !@#$%  
> Changed like every 90 or 120 days  
> 8-15 digits long or something like that  
> can’t repeat with last 10 passwords
> 
> Holy crap. I have a set password and then all I change is the letters in the begining. I learned that technique from a poster on this board. Since I need two capitals and two lowercase, I just move down the keyboard every time I need to change it.  
> So if right now my password is HHhh1234!@, then next month I will change it to JJjj1234!@, then KKkk1234!@. Works great and I can always remember my 15 digit password.

I do something similar. I just memorize keyboard positions for example - !123qaz]’/

---

<div class="post-metadata">

**Author:** ![Harmonious\_Discord](https://avatars.discourse-cdn.com/v4/letter/h/74df32/32.png) [@Harmonious\_Discord](https://boards.straightdope.com/u/Harmonious_Discord)\
**Post date:** [April 16, 2009, 1:42pm UTC](https://boards.straightdope.com/t/bl0w-m3-does-not-meet-our-password-requirements/493204/32 "2009-04-16T13:42:30Z")

</div>

Hey boss why don’t you check your passwords on this web site that rates them for security. I’ve been using it for a year now. Joe over there has his on MySpace so he can look them up whenever he needs to.

---

<div class="post-metadata">

**Author:** ![Polycarp](https://avatars.discourse-cdn.com/v4/letter/p/82dd89/32.png) [@Polycarp](https://boards.straightdope.com/u/Polycarp)\
**Post date:** [April 16, 2009, 1:43pm UTC](https://boards.straightdope.com/t/bl0w-m3-does-not-meet-our-password-requirements/493204/33 "2009-04-16T13:43:22Z")

</div>

> [@Lute Skywatcher](#):
>
> Lucky you. It’s six here.
> 
> Personally, I use zip codes (e.g.: Ny12345-0001) that are from previous residences.

You used to live in the President’s Office at General Electric? :o

---

<div class="post-metadata">

**Author:** ![Kalhoun](https://avatars.discourse-cdn.com/v4/letter/k/3bc359/32.png) [@Kalhoun](https://boards.straightdope.com/u/Kalhoun)\
**Post date:** [April 16, 2009, 2:14pm UTC](https://boards.straightdope.com/t/bl0w-m3-does-not-meet-our-password-requirements/493204/34 "2009-04-16T14:14:07Z")

</div>

Try 3ATM3\*JrKoFF

---

<div class="post-metadata">

**Author:** ![Oredigger77](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/oredigger77/32/3181_2.png) [@Oredigger77](https://boards.straightdope.com/u/Oredigger77)\
**Post date:** [April 16, 2009, 2:36pm UTC](https://boards.straightdope.com/t/bl0w-m3-does-not-meet-our-password-requirements/493204/35 "2009-04-16T14:36:19Z")

</div>

I like to use equations that describe my life. One I use a while ago after a breakup was

Me-exgf=hpy09

It meets every password requirement I’ve ever heard of and they are incredibly easy to remember. Right now my pass word is about the coming of spring.

---

<div class="post-metadata">

**Author:** ![Skywatcher](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/skywatcher/32/254_2.png) [@Skywatcher](https://boards.straightdope.com/u/Skywatcher)\
**Post date:** [April 16, 2009, 2:45pm UTC](https://boards.straightdope.com/t/bl0w-m3-does-not-meet-our-password-requirements/493204/36 "2009-04-16T14:45:59Z")

</div>

> [@Polycarp](#):
>
> You used to live in the President’s Office at General Electric? :o

😃

I wasn’t about to give out one I actually use.

---

<div class="post-metadata">

**Author:** ![Martin\_Hyde](https://avatars.discourse-cdn.com/v4/letter/m/47e85d/32.png) [@Martin\_Hyde](https://boards.straightdope.com/u/Martin_Hyde)\
**Post date:** [April 16, 2009, 3:52pm UTC](https://boards.straightdope.com/t/bl0w-m3-does-not-meet-our-password-requirements/493204/37 "2009-04-16T15:52:45Z")

</div>

I’ve taken to using [this](http://www.pctools.com/guides/password/) for instances where there are particularly aggravating password requirements.

All my passwords these days are kept in a password protected excel file, which is safe enough for me. I went that route when so many different systems had so many different password requirements that it became impossible for me to even keep some general them or semblance from system to system.

But honestly about 7/10 or so of my passwords, even if my worst enemy had them, would give very little that would screw me over in any way. The important stuff is all protected by SecurID so unless I lose my key fob, and they have my login information I feel pretty secure.

---

<div class="post-metadata">

**Author:** ![amaguri](https://avatars.discourse-cdn.com/v4/letter/a/49beb7/32.png) [@amaguri](https://boards.straightdope.com/u/amaguri)\
**Post date:** [April 16, 2009, 5:58pm UTC](https://boards.straightdope.com/t/bl0w-m3-does-not-meet-our-password-requirements/493204/38 "2009-04-16T17:58:13Z")

</div>

i currently have 22 different logons and passwords for various applications at work. many of them have unique requirements, like capital letters or special characters, and most of them must be reset in 30 or 60 days (not all on the same schedule). yes, i do have a list typed out and sitting on my desk. i have no idea how any normal human is expected to have all of this stuff memorized.

---

<div class="post-metadata">

**Author:** ![Irishman](https://avatars.discourse-cdn.com/v4/letter/i/b487fb/32.png) [@Irishman](https://boards.straightdope.com/u/Irishman)\
**Post date:** [April 16, 2009, 7:54pm UTC](https://boards.straightdope.com/t/bl0w-m3-does-not-meet-our-password-requirements/493204/39 "2009-04-16T19:54:42Z")

</div>

**Lilacs** said:

> [@](#):
>
> For our newest software, we had to have someone come and install it and OK it on our computers. The Sheriff’s department takes their shit seriously. So, I had to tell their IT guy my password.

Now that’s wrong. Either he should have an administrator account so he can install SW, or you should login for him. IT shouldn’t need _your_ password.

---

<div class="post-metadata">

**Author:** ![Trepa\_Mayfield](https://avatars.discourse-cdn.com/v4/letter/t/edb3f5/32.png) [@Trepa\_Mayfield](https://boards.straightdope.com/u/Trepa_Mayfield)\
**Post date:** [April 16, 2009, 9:59pm UTC](https://boards.straightdope.com/t/bl0w-m3-does-not-meet-our-password-requirements/493204/40 "2009-04-16T21:59:46Z")

</div>

> [@pedescribe](#):
>
> But…gullible is in the dictionary.

:smack::smack::smack::smack::smack::smack::smack::smack::smack::smack::smack::smack::smack::smack::smack::smack::smack::smack::smack:

[Previous page](https://boards.straightdope.com/t/bl0w-m3-does-not-meet-our-password-requirements/493204.md?page=1)

[Next page](https://boards.straightdope.com/t/bl0w-m3-does-not-meet-our-password-requirements/493204.md?page=3)
