# Guy who came up with all those crazy password rules now says he's sorry

**URL:** <https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171>\
**Category:** Miscellaneous and Personal Stuff I Must Share\
**Created:** [August 9, 2017, 1:01pm UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171 "2017-08-09T13:01:55Z")\
**Posts on this page:** 20\
**Page:** 4

<div class="post-metadata">

**Author:** ![Mr\_Downtown](https://avatars.discourse-cdn.com/v4/letter/m/8e8cbc/32.png) [@Mr\_Downtown](https://boards.straightdope.com/u/Mr_Downtown)\
**Post date:** [August 10, 2017, 4:12am UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/61 "2017-08-10T04:12:47Z")

</div>

Alas, United Airlines has now taken it on themselves to defeat all you people answering _Mona Lisa_ or _Fuck You_ to every question. They’ve restricted users to a multiple choice list!

Not only do they ask about offbeat topics (what adult has a favorite sea creature?) but they then provide 10 answers that you must choose from. So if your **actual** favorite painter or first major city visited isn’t on the list, good luck.

Apparently they don’t always show you the full list, so you can’t just decide on the next-to-last item in the list. I finally chose a particular letter of the alphabet and then, for all questions, selected the answer nearest (but prior to) that letter.

Whoever thought that scheme was an advance in civilization should be reassigned to chemical toilet duty.

---

<div class="post-metadata">

**Author:** ![CarnalK](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/carnalk/32/486_2.png) [@CarnalK](https://boards.straightdope.com/u/CarnalK)\
**Post date:** [August 10, 2017, 5:37am UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/62 "2017-08-10T05:37:36Z")

</div>

I guess with drop downs my workaround would be an arbitrary rule like whichever option has the most vowels or first alphabetically starting with the last letter in the option.

---

<div class="post-metadata">

**Author:** ![CarnalK](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/carnalk/32/486_2.png) [@CarnalK](https://boards.straightdope.com/u/CarnalK)\
**Post date:** [August 10, 2017, 5:52am UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/63 "2017-08-10T05:52:54Z")

</div>

Ooh. You could merge the strategies. All word security answers could be “3rd vowel alphabetically [related to question noun]” and drop down answers would always be the one whose third vowel was alphabetically first.

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [August 10, 2017, 5:58am UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/64 "2017-08-10T05:58:38Z")

</div>

> [@LSLGuy](#):
>
> The answer to each and every one of those questions is “bullshit”. If the website insists your answers be unique they become instead:[ul]  
> [li]What was the name of your first pet? _bullshit pet_[/li][li]City Mom born in _bullshit city_[/li][li]City Dad born in _bullshit city_[/li][li]First foreign country visited _bullshit country_[/li][li]First & last name of childhood best friend _bullshit friend_[/li][li]First & Last name of first manager _bullshit manager_[/li][li]First & Last name of first girl/boyfriend _bullshit girlfriend or bullshit boyfriend depending on your orientation_[/li][li]First concert you attended _bullshit concert_[/li][li]What was the last name of your favorite teacher in your final year of school? _bullshit teacher_[/li][li]What was your childhood nickname that most people do not know? _bullshit nickname_[/li][li]First & last name of the maid/matron of honor at your wedding _bullshit maid_[/li][li]First & last name of the best man of honor at your wedding _bullshit man_[/li][li]First & last name of oldest niece _bullshit niece_[/li][li]First & last name of oldest nephew _bullshit nephew_[/li][/ul]Remember that you can pick which Qs to use. So pick the questions that give unambiguous clues about which noun is the bullshit noun.
> 
> This isn’t difficult, people.

Are you proposing this as circumvention of a security step, or a solution to a security problem, because it isn’t the latter.

Any scheme that you cook up for making passwords easier to remember makes them easier to break - especially if it’s a predictable pattern that you use across a wide range of services.

---

<div class="post-metadata">

**Author:** ![Folacin](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/folacin/32/3195_2.png) [@Folacin](https://boards.straightdope.com/u/Folacin)\
**Post date:** [August 10, 2017, 11:14am UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/65 "2017-08-10T11:14:00Z")

</div>

> [@CarnalK](#):
>
> I guess with drop downs my workaround would be an arbitrary rule like whichever option has the most vowels or first alphabetically starting with the last letter in the option.

But do they give you the drop down when they ask for the answers?

---

<div class="post-metadata">

**Author:** ![aruvqan](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/aruvqan/32/2891_2.png) [@aruvqan](https://boards.straightdope.com/u/aruvqan)\
**Post date:** [August 10, 2017, 1:17pm UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/66 "2017-08-10T13:17:40Z")

</div>

> [@Khendrask](#):
>
> Not only do the password rules suck, but I have incredible hate for the “Security Questions”, unless they at least let you make up your own.
> 
> I have too many with things like “Your High School”, or “Your Pet’s Name”. Okay, stupid to complain about, but for school, did I put the initials? “AB Charlie HS”? Did I spell it out? “Alpha Bravo Charlie” ? Did I just use the “Charlie”?
> 
> For pets, My current pet? The pet I had when I made the account? When was that?
> 
> I generally ignore all of them now, and just have the bank or whatever text me a security code, but a lot still won’t do that.

DO what I do, use the same word for everything - moms middle name - Grace, first pet - Grace, favorite food - Grace [or whatever]

If my bestie hadn’t died, I would still be able to crack anything of his - he worked his way through the Imperial Japanese Navy of WW2, and then added a number to correspond with the month and an ^ if it needed a special symbol.

One of my sooper sekret skwirrl passwords is actually my log in from when I worked at ADT in the mid 90s =) Totally nothing I would have come up with, not linked to anybody’s birthday, anniversary, death day …

---

<div class="post-metadata">

**Author:** ![Hari\_Seldon](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/hari_seldon/32/5173_2.png) [@Hari\_Seldon](https://boards.straightdope.com/u/Hari_Seldon)\
**Post date:** [August 10, 2017, 2:18pm UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/67 "2017-08-10T14:18:20Z")

</div>

I have a password of the form X#x#x#x#x# (X,x stand for upper, lower case letter, # for a number). Ever try to enter that on a soft keyboard, where you have to shift between every pair of characters? But they insist on at least one upper case and one lower case letter and at least one number. I could change it of course, but I have a way of recalling this sequence. Yes, a 4 word phrase, all in lower case, would be much more secure.

---

<div class="post-metadata">

**Author:** ![Buttercup\_Smith](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/buttercup_smith/32/473_2.png) [@Buttercup\_Smith](https://boards.straightdope.com/u/Buttercup_Smith)\
**Post date:** [August 10, 2017, 2:47pm UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/68 "2017-08-10T14:47:43Z")

</div>

I usually go with favorite movie and favorite flavor of ice cream or city of birth as those do not change.

---

<div class="post-metadata">

**Author:** ![CarnalK](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/carnalk/32/486_2.png) [@CarnalK](https://boards.straightdope.com/u/CarnalK)\
**Post date:** [August 10, 2017, 3:13pm UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/69 "2017-08-10T15:13:36Z")

</div>

> [@Mangetout](#):
>
> Are you proposing this as circumvention of a security step, or a solution to a security problem, because it isn’t the latter.
> 
> Any scheme that you cook up for making passwords easier to remember makes them easier to break - especially if it’s a predictable pattern that you use across a wide range of services.

Giving actual answers to security questions is more of a flaw than random easy to remember words, most especially in our era of oversharing and phishing.

---

<div class="post-metadata">

**Author:** ![Procrustus](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/procrustus/32/2994_2.png) [@Procrustus](https://boards.straightdope.com/u/Procrustus)\
**Post date:** [August 10, 2017, 3:20pm UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/70 "2017-08-10T15:20:16Z")

</div>

[quote=“Mr\_Downtown, post:61, topic:793171”]

Alas, United Airlines has now taken it on themselves to defeat all you people answering _Mona Lisa_ or _Fuck You_ to every question. They’ve restricted users to a multiple choice list!

[QUOTE]

Is United Airlines having a big problem with people trying to make reservations in other people’s name?

---

<div class="post-metadata">

**Author:** ![JcWoman](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/jcwoman/32/2889_2.png) [@JcWoman](https://boards.straightdope.com/u/JcWoman)\
**Post date:** [August 10, 2017, 3:41pm UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/71 "2017-08-10T15:41:24Z")

</div>

> [@Clothahump](#):
>
> So I now string them together as follows: my first three letters, the special character, the three letters of the site and the four digit string. This would give me a password for Chase of Mar@Cha1608. If I were going to Wells Fargo, it would be Mar@Wel1608, etc.
> 
> This password structure has all the elements required, is easy to remember and is unique for each secure site you use it on. FWIW, password strength checkers indicate that the sample passwords shown would take over a hundred years to crack.

You forgot to add a sequential number in there somewhere to handle those stupid password lifetime rules.

> [@Mr\_Downtown](#):
>
> Not only do they ask about offbeat topics (what adult has a favorite sea creature?) but they then provide 10 answers that you must choose from. So if your **actual** favorite painter or first major city visited isn’t on the list, good luck.

(raise hand) All hail the Mighty Kraken!  
But of course that’s probably not one of their stupid answer choices.

One of the systems used by a previous employer actually forced us to fill out TEN effing different security questions. All were mandatory and no duplicates were allowed. That sucked so, so hard.

---

<div class="post-metadata">

**Author:** ![Enright3](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/enright3/32/2897_2.png) [@Enright3](https://boards.straightdope.com/u/Enright3)\
**Post date:** [August 10, 2017, 3:47pm UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/72 "2017-08-10T15:47:20Z")

</div>

I had one reminder question to be _favorite color_. When I typed in “red” I received an error that the answer was too short!

At work we’re required to change our pw x number of days; but then you get nag popups for 15 more days. I always wait until two or three days before I get locked out. Even then, my password has been the same for several years; with a number incremented by 1 each time. I’m now up to xxxxxxxx38 :rolleyes:

---

<div class="post-metadata">

**Author:** ![CookingWithGas](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cookingwithgas/32/485_2.png) [@CookingWithGas](https://boards.straightdope.com/u/CookingWithGas)\
**Post date:** [August 10, 2017, 4:09pm UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/73 "2017-08-10T16:09:02Z")

</div>

I use a federal government system that prohibits any dictionary words anywhere in your password. They are just begging for people to either write down their passwords or forget them.

---

<div class="post-metadata">

**Author:** ![running\_coach](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/running_coach/32/15836_2.png) [@running\_coach](https://boards.straightdope.com/u/running_coach)\
**Post date:** [August 10, 2017, 4:34pm UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/74 "2017-08-10T16:34:26Z")

</div>

> [@Enright3](#):
>
> I had one reminder question to be _favorite color_. When I typed in “red” I received an error that the answer was too short!

[Bugs Bunny] What a maroon![/Bugs Bunny]

---

<div class="post-metadata">

**Author:** ![Nava](https://avatars.discourse-cdn.com/v4/letter/n/da6949/32.png) [@Nava](https://boards.straightdope.com/u/Nava)\
**Post date:** [August 10, 2017, 4:37pm UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/75 "2017-08-10T16:37:05Z")

</div>

> [@Khendrask](#):
>
> Not only do the password rules suck, but I have incredible hate for the “Security Questions”, unless they at least let you make up your own.

I particularly love getting “Mother’s maiden name?” in Spanish or Portuguese. It’s in our ID, it’s in our company email\*, it’s in all our official paperwork…

- depending on the company it may not be. But sometimes keeping it off can require knowing a good lawyer.

---

<div class="post-metadata">

**Author:** ![Slash1972](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/slash1972/32/6461_2.png) [@Slash1972](https://boards.straightdope.com/u/Slash1972)\
**Post date:** [August 10, 2017, 7:42pm UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/76 "2017-08-10T19:42:48Z")

</div>

> [@Chronos](#):
>
> If their system had even the basic rudiments of security, it would be impossible to enforce this restriction. The fact that they are enforcing it proves that they haven’t made any attempt whatsoever at security

No, it’s possible to enforce it. At time of password creation, they save the hashes of every 3 consecutive character string in the password. Then, when you create a new password, they do the same thing and compare the hashes to the saved ones. If any match, then you are not allowed to use the new password.

Or, they store the passwords in the clear 😃

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [August 10, 2017, 9:59pm UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/77 "2017-08-10T21:59:09Z")

</div>

> [@Clothahump](#):
>
> I’ve posted this before, but it’s worth repeating. There is a simple formula for generating unique passwords for individual sites

Your formula means that if one of your passwords gets leaked, it’s incredibly easy to figure out the others.

---

<div class="post-metadata">

**Author:** ![Dr.Strangelove](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dr.strangelove/32/6613_2.png) [@Dr.Strangelove](https://boards.straightdope.com/u/Dr.Strangelove)\
**Post date:** [August 11, 2017, 12:12am UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/78 "2017-08-11T00:12:46Z")

</div>

> [@Slash1972](#):
>
> Or, they store the passwords in the clear 😃

Your idea is basically equivalent to storing the passwords in cleartext. Those 3-letter segments can be trivially brute-forced, and assembling them back together into the original password is also trivial.

---

<div class="post-metadata">

**Author:** ![TruCelt](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/trucelt/32/523_2.png) [@TruCelt](https://boards.straightdope.com/u/TruCelt)\
**Post date:** [August 11, 2017, 1:22am UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/79 "2017-08-11T01:22:20Z")

</div>

I use the only guaranteed system: Choosing passwords that are deep in Geek. That way when the crackers get hold of them, they realize I am one of them, and don’t steal the $259 in my checking account.

---

<div class="post-metadata">

**Author:** ![CelticKnot](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/celticknot/32/3392_2.png) [@CelticKnot](https://boards.straightdope.com/u/CelticKnot)\
**Post date:** [August 11, 2017, 4:02am UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/80 "2017-08-11T04:02:25Z")

</div>

I have a weird memory for numbers. I can’t remember how much of the fabric the customer asked me for 1 minute ago, but I remember the license plates of many of the cars I have driven, Those letter/number combinations form the basis for my passwords. I add the same special characters to them, and remember them using the same mnemonics I used to remember them when they were on my car. I just have to write down the mnemonics for each page:  
Yahoo: Party bus #2  
shopping site: 51 cucumbers  
etc.

[Previous page](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171.md?page=3)

[Next page](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171.md?page=5)
