# Guy who came up with all those crazy password rules now says he's sorry

**URL:** <https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171>\
**Category:** Miscellaneous and Personal Stuff I Must Share\
**Created:** [August 9, 2017, 1:01pm UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171 "2017-08-09T13:01:55Z")\
**Posts on this page:** 20\
**Page:** 3

<div class="post-metadata">

**Author:** ![RitterSport](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/rittersport/32/6326_2.png) [@RitterSport](https://boards.straightdope.com/u/RitterSport)\
**Post date:** [August 9, 2017, 8:36pm UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/41 "2017-08-09T20:36:41Z")

</div>

> [@](#):
>
> Really? That’s awesome! Let me try!
> 
> * * *

It worked!

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [August 9, 2017, 8:41pm UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/42 "2017-08-09T20:41:17Z")

</div>

> [@Guinastasia](#):
>
> Hey, you know if you type in your SD password here it shows up as astericks? Check it out: \*\*\*\*\*\*\*\*\*\*

aaaaaaaaarse!

---

<div class="post-metadata">

**Author:** ![Filbert](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/filbert/32/3433_2.png) [@Filbert](https://boards.straightdope.com/u/Filbert)\
**Post date:** [August 9, 2017, 8:58pm UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/43 "2017-08-09T20:58:13Z")

</div>

Oh god yes, the insecurity questions. The ones you have to invent answers to unless you want all your family members and half your old school friends to be able to get in… Seriously, whose daft idea were they? Much worse than the silly password rules.

When the actual answers to the default security questions are things easily discoverable on many people’s Facebook accounts, something really needs a rethink.

---

<div class="post-metadata">

**Author:** ![gnoitall](https://avatars.discourse-cdn.com/v4/letter/g/bb73d2/32.png) [@gnoitall](https://boards.straightdope.com/u/gnoitall)\
**Post date:** [August 9, 2017, 8:59pm UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/44 "2017-08-09T20:59:22Z")

</div>

> [@Jackmannii](#):
>
> The username/password combo of admin/password hasn’t failed me yet.
> 
> I would like to find out who’s responsible for claiming that submitted passwords have already been assigned to other users when that clearly isn’t true.
> 
> I have a hard time believing that GooGleIsExCrEmENtonToAst666 is someone else’s gmail password. :mad:

Hey, I have that on my luggage!

(The combination lock is larger than the suitcase. :D)

---

<div class="post-metadata">

**Author:** ![Icarus](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/icarus/32/72_2.png) [@Icarus](https://boards.straightdope.com/u/Icarus)\
**Post date:** [August 9, 2017, 9:15pm UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/45 "2017-08-09T21:15:43Z")

</div>

The technology is not quite there yet, but using your camera and microphone, passwords should include: a pantone color (252 C?), a sound (a shrimp sneezing), along with a random gesticulation (perhaps a Battement dégagé?), and in the future - an odor (red gravy with sage).

Only then will we be really secure.

---

<div class="post-metadata">

**Author:** ![Folacin](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/folacin/32/3195_2.png) [@Folacin](https://boards.straightdope.com/u/Folacin)\
**Post date:** [August 9, 2017, 9:15pm UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/46 "2017-08-09T21:15:57Z")

</div>

> [@Slash1972](#):
>
> This seems strange. Can you elaborate?

Well, yeah, it is strange. I don’t know why they haven’t changed the configuration on that - I’m hoping it’s because they realize having yet another level of security beyond my having to log on to the network and then log on to a server to actually access the repository and then enter a password with stupid generation rules is a bridge too far.

Alternatively, no one in a security position has noticed. I’m not telling them, that’s for certain.

---

<div class="post-metadata">

**Author:** ![Clothahump](https://avatars.discourse-cdn.com/v4/letter/c/51bf81/32.png) [@Clothahump](https://boards.straightdope.com/u/Clothahump)\
**Post date:** [August 9, 2017, 9:20pm UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/47 "2017-08-09T21:20:16Z")

</div>

> [@Khendrask](#):
>
> Not only do the password rules suck, but I have incredible hate for the “Security Questions”, unless they at least let you make up your own.
> 
> I have too many with things like “Your High School”, or “Your Pet’s Name”. Okay, stupid to complain about, but for school, did I put the initials? “AB Charlie HS”? Did I spell it out? “Alpha Bravo Charlie” ? Did I just use the “Charlie”?
> 
> For pets, My current pet? The pet I had when I made the account? When was that?
> 
> I generally ignore all of them now, and just have the bank or whatever text me a security code, but a lot still won’t do that.

As far as security questions go, answer them all with the same answer, such as the name of your first pet, even if it’s asking for your mother’s maiden name or whatever.

I’ve posted this before, but it’s worth repeating. There is a simple formula for generating unique passwords for individual sites:

Pick three letters that are meaningful to you. Maybe your first girl/boyfriend’s initials or something like that, but don’t use your own. Make the first be upper case and the last two lower case. For this example, I’ll use my first girlfriend’s initials Mar.

Pick a special character. Just one is all. For this example, I’ll use @.

Pick a string of four digits that are meaningful to you, but not your SSN or something similar. The address of the house I grew up in was 1608, so let’s use that.

The last thing you need is the first three letters of the site you are visiting. Note that this will change each time. For this example, assume I am going to create an online account with Chase Bank. I’ll use Cha.

So I now string them together as follows: my first three letters, the special character, the three letters of the site and the four digit string. This would give me a password for Chase of Mar@Cha1608. If I were going to Wells Fargo, it would be Mar@Wel1608, etc.

This password structure has all the elements required, is easy to remember and is unique for each secure site you use it on. FWIW, password strength checkers indicate that the sample passwords shown would take over a hundred years to crack.

---

<div class="post-metadata">

**Author:** ![Shoeless](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/shoeless/32/7099_2.png) [@Shoeless](https://boards.straightdope.com/u/Shoeless)\
**Post date:** [August 9, 2017, 9:38pm UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/48 "2017-08-09T21:38:57Z")

</div>

The worst one I had recently was setting my PIN for a new RSA token at work.

- 6-8 characters, alphanumeric, not case sensitive
- Cannot repeat the same character for entire PIN
- Cannot have a repeating pair of characters
- Cannot have a repeating set of three characters
- Cannot have a set of 3 characters repeated in reverse
- Cannot use characters that appear consecutively on the keyboard

Seriously? WTF?

---

<div class="post-metadata">

**Author:** ![Tim\_T-Bonham.net](https://avatars.discourse-cdn.com/v4/letter/t/46a35a/32.png) [@Tim\_T-Bonham.net](https://boards.straightdope.com/u/Tim_T-Bonham.net)\
**Post date:** [August 9, 2017, 10:21pm UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/49 "2017-08-09T22:21:23Z")

</div>

> [@](#):
>
> The only problem is that Bill Burr didn’t really know much about how passwords worked back in 2003 …

What ridiculous claim is this?

I was using a password on a Teletype-33 in 1968, and it had many of these same rules. (Except we didn’t have to worry about a lower-case letter – there were none.) But a minimum length of 6 characters, using both letters & numbers, and no repeating characters – those rules applied.

These special snowflake millennials seem to think they are the first at everything, and have it so hard.

And get off my lawn!

---

<div class="post-metadata">

**Author:** ![CarnalK](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/carnalk/32/486_2.png) [@CarnalK](https://boards.straightdope.com/u/CarnalK)\
**Post date:** [August 9, 2017, 10:33pm UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/50 "2017-08-09T22:33:29Z")

</div>

> [@t-bonham@scc.net](#):
>
> What ridiculous claim is this?
> 
> I was using a password on a Teletype-33 in 1968, and it had many of these same rules. (Except we didn’t have to worry about a lower-case letter – there were none.) But a minimum length of 6 characters, using both letters & numbers, and no repeating characters – those rules applied.
> 
> These special snowflake millennials seem to think they are the first at everything, and have it so hard.
> 
> And get off my lawn!

The guy in the article is 72 yrs old. How the fuck old are you to be calling him a whipper snapper millennial? Do you even use reading glasses, bro?

---

<div class="post-metadata">

**Author:** ![pulykamell](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/pulykamell/32/3166_2.png) [@pulykamell](https://boards.straightdope.com/u/pulykamell)\
**Post date:** [August 9, 2017, 10:44pm UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/51 "2017-08-09T22:44:09Z")

</div>

Doesn’t the no repeating characters rule narrow the search space for the ne’er do wells?

---

<div class="post-metadata">

**Author:** ![Chronos](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chronos/32/134_2.png) [@Chronos](https://boards.straightdope.com/u/Chronos)\
**Post date:** [August 9, 2017, 11:35pm UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/52 "2017-08-09T23:35:46Z")

</div>

> [@](#):
>
> Quoth **Clothahump** :
> 
> FWIW, password strength checkers indicate that the sample passwords shown would take over a hundred years to crack.

And they took less than a hundred years to tell you this? Then they’re just bullshitting. From what I’ve read about password crackers, that’d probably be somewhere in the few-hours range. Or nearly instantaneous, if they have access to any of your other passwords at all.

> [@](#):
>
> Quoth **Folacin** ’s rules:
> 
> •MUST NOT contain a sequence of three or more characters from the previous password

If their system had even the basic rudiments of security, it would be impossible to enforce this restriction. The fact that they are enforcing it proves that they haven’t made any attempt whatsoever at security.

The two worst I’ve seen, though, were both at universities. One was from my grad school: The administration was concerned about security in their Banner system (where students can check grades, schedule classes, and so on), so they sent out a memo saying that everyone should have passwords at least eight characters long, containing letters, numbers, and symbols, and so on… except the only passwords the system would actually accept were six-digit numbers.

The other was at the community college where I taught as an adjunct. When I was setting up my account there, it kept on telling me that my password wasn’t meeting the complexity requirements, so I kept on making it more and more complex… except that it turned out that it wasn’t meeting the complexity requirements because it was _too_ complex, and what the system actually wanted was seven lowercase letters and a digit.

---

<div class="post-metadata">

**Author:** ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)\
**Post date:** [August 10, 2017, 12:21am UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/53 "2017-08-10T00:21:58Z")

</div>

> [@Spiderman](#):
>
> I just went onto a new website & you had to choose three questions from the drop down list; they included:[ul]  
> [li]What was the name of your first pet? _(First pet, the dog they had until I was 2 & don’t really remember, or the first dog I got when living on my own?)_[/li][li]City Mom born in [/li][li]City Dad born in _(I know where my parents lived when they were born, but what city depends upon which hospital, which I don’t know.)_[/li][li]First foreign country visited[/li][li]First & last name of childhood best friend[/li][li]First & Last name of first manager[/li][li]First & Last name of first girl/boyfriend[/li][li]First concert you attended[/li][li]What was the last name of your favorite teacher in your final year of school?[/li][li]What was your childhood nickname that most people do not know?[/li][/ul]  
> The rest of the questions are from decades ago; I couldn’t tell you some of answers if lives depended on it.  
> The following questions were also in the list but may not have a valid answer if you’re single, eloped, or are an only child.  
> [ul]  
> [li]First & last name of the maid/matron of honor at your wedding[/li][li]First & last name of the best man of honor at your wedding[/li][li]First & last name of oldest niece[/li][li]First & last name of oldest nephew[/li][/ul]

The answer to each and every one of those questions is “bullshit”. If the website insists your answers be unique they become instead:[ul]  
[li]What was the name of your first pet? _bullshit pet_[/li][li]City Mom born in _bullshit city_[/li][li]City Dad born in _bullshit city_[/li][li]First foreign country visited _bullshit country_[/li][li]First & last name of childhood best friend _bullshit friend_[/li][li]First & Last name of first manager _bullshit manager_[/li][li]First & Last name of first girl/boyfriend _bullshit girlfriend or bullshit boyfriend depending on your orientation_[/li][li]First concert you attended _bullshit concert_[/li][li]What was the last name of your favorite teacher in your final year of school? _bullshit teacher_[/li][li]What was your childhood nickname that most people do not know? _bullshit nickname_[/li][li]First & last name of the maid/matron of honor at your wedding _bullshit maid_[/li][li]First & last name of the best man of honor at your wedding _bullshit man_[/li][li]First & last name of oldest niece _bullshit niece_[/li][li]First & last name of oldest nephew _bullshit nephew_[/li][/ul]Remember that you can pick which Qs to use. So pick the questions that give unambiguous clues about which noun is the bullshit noun.

This isn’t difficult, people.

---

<div class="post-metadata">

**Author:** ![CarnalK](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/carnalk/32/486_2.png) [@CarnalK](https://boards.straightdope.com/u/CarnalK)\
**Post date:** [August 10, 2017, 12:56am UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/54 "2017-08-10T00:56:44Z")

</div>

> [@LSLGuy](#):
>
> ]  
> This isn’t difficult, people.

Reading a one page thread and noticing someone already made your exact suggestion isn’t difficult either but people still fail to do that.

---

<div class="post-metadata">

**Author:** ![hajario](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/hajario/32/171_2.png) [@hajario](https://boards.straightdope.com/u/hajario)\
**Post date:** [August 10, 2017, 1:15am UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/55 "2017-08-10T01:15:59Z")

</div>

> [@Guinastasia](#):
>
> Hey, you know if you type in your SD password here it shows up as astericks? Check it out: \*\*\*\*\*\*\*\*\*\*

hunter2

---

<div class="post-metadata">

**Author:** ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)\
**Post date:** [August 10, 2017, 1:18am UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/56 "2017-08-10T01:18:47Z")

</div>

@ **CarnalK** : Actually, I did see you had done that. Very neatly and succinctly. I also saw the other people ahead of you who suggested “use the same made up answer every time”.

But **Spiderman** ’s long-form complaint was after all those posts. Which implied to me that he didn’t see them either.

I thought maybe he’d appreciate a personalized answer. When I noticed he’d used brown type I had a stroke of literary genius. For a lazy hazy post-wine-with-dinner kind of “genius”. I’m sorry if you were offended.

---

<div class="post-metadata">

**Author:** ![Paul\_in\_Qatar](https://avatars.discourse-cdn.com/v4/letter/p/ccd318/32.png) [@Paul\_in\_Qatar](https://boards.straightdope.com/u/Paul_in_Qatar)\
**Post date:** [August 10, 2017, 1:50am UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/57 "2017-08-10T01:50:09Z")

</div>

I have ten passwords, each with three variations. The passwords are never written anywhere. My notebook has “Bank” on the page for “Password 3a.” My secrets die with me.

---

<div class="post-metadata">

**Author:** ![CarnalK](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/carnalk/32/486_2.png) [@CarnalK](https://boards.straightdope.com/u/CarnalK)\
**Post date:** [August 10, 2017, 2:19am UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/58 "2017-08-10T02:19:11Z")

</div>

> [@LSLGuy](#):
>
> @ **CarnalK** : Actually, I did see you had done that. Very neatly and succinctly. I also saw the other people ahead of you who suggested “use the same made up answer every time”.
> 
> But **Spiderman** ’s long-form complaint was after all those posts. Which implied to me that he didn’t see them either.
> 
> I thought maybe he’d appreciate a personalized answer. When I noticed he’d used brown type I had a stroke of literary genius. For a lazy hazy post-wine-with-dinner kind of “genius”. I’m sorry if you were offended.

Wasn’t offended at all. Just ragging on you.

---

<div class="post-metadata">

**Author:** ![Spiderman](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/spiderman/32/230_2.png) [@Spiderman](https://boards.straightdope.com/u/Spiderman)\
**Post date:** [August 10, 2017, 3:36am UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/59 "2017-08-10T03:36:02Z")

</div>

> [@LSLGuy](#):
>
> @ **CarnalK** : Actually, I did see you had done that. Very neatly and succinctly. I also saw the other people ahead of you who suggested “use the same made up answer every time”.
> 
> But **Spiderman** ’s long-form complaint was after all those posts. Which implied to me that he didn’t see them either.

I think I was the first to say make all of your passwords the same in Post #11. The problem for me is that my older accounts were setup with ‘real’ answers & over time, it would be tough to remember if it’s a real answer or a “Fuck You” answer & that was created later. It was timely that I had to register for that site today & that I doubt I’d remember the real answers if & when I ever do hit the challenge questions.

The fact that multiple people, including me, have stated how to get around the ‘security’ with BS methods just proves that it’s another case of security theater.

---

<div class="post-metadata">

**Author:** ![CurtC](https://avatars.discourse-cdn.com/v4/letter/c/ce73a5/32.png) [@CurtC](https://boards.straightdope.com/u/CurtC)\
**Post date:** [August 10, 2017, 3:49am UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/60 "2017-08-10T03:49:13Z")

</div>

> [@Clothahump](#):
>
> This would give me a password for Chase of Mar@Cha1608. If I were going to Wells Fargo, it would be Mar@Wel1608, etc.

I see a gaping security hole here.

[Previous page](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171.md?page=2)

[Next page](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171.md?page=4)
