# Guy who came up with all those crazy password rules now says he's sorry

**URL:** <https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171>\
**Category:** Miscellaneous and Personal Stuff I Must Share\
**Created:** [August 9, 2017, 1:01pm UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171 "2017-08-09T13:01:55Z")\
**Posts on this page:** 11\
**Page:** 5

<div class="post-metadata">

**Author:** ![Siam\_Sam](https://avatars.discourse-cdn.com/v4/letter/s/d78d45/32.png) [@Siam\_Sam](https://boards.straightdope.com/u/Siam_Sam)\
**Post date:** [August 11, 2017, 5:23am UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/81 "2017-08-11T05:23:41Z")

</div>

> [@Darren\_Garrison](#):
>
> So I can go back to using 12345?

I never stopped!

---

<div class="post-metadata">

**Author:** ![Clothahump](https://avatars.discourse-cdn.com/v4/letter/c/51bf81/32.png) [@Clothahump](https://boards.straightdope.com/u/Clothahump)\
**Post date:** [August 11, 2017, 5:36am UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/82 "2017-08-11T05:36:09Z")

</div>

> [@CurtC](#):
>
> I see a gaping security hole here.

I don’t. If you are referring to the three letters of the site being visited, the formula is flexible enough that I can change it to split the 4 digits and put them in the site identifier.

So for Chase, instead of Mar@Cha1608, I could use Mar@C16ha08. As long as I am consistent in the structure of the password and use that same structure throughout, it’s all good.

---

<div class="post-metadata">

**Author:** ![Melbourne](https://avatars.discourse-cdn.com/v4/letter/m/b5e925/32.png) [@Melbourne](https://boards.straightdope.com/u/Melbourne)\
**Post date:** [August 11, 2017, 9:33am UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/83 "2017-08-11T09:33:13Z")

</div>

> [@Khendrask](#):
>
> I have too many with things like “Your High School”, or “Your Pet’s Name”. .

Those are really just alternative password questions. So when you name your pet, the pet’s name should be a mixture of UPPER CASE and lower case latters, with some numbers and symbols, at least 8 characters long

Here Pr!n$e01…

---

<div class="post-metadata">

**Author:** ![ftg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ftg/32/2801_2.png) [@ftg](https://boards.straightdope.com/u/ftg)\
**Post date:** [August 11, 2017, 12:24pm UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/84 "2017-08-11T12:24:11Z")

</div>

I really wonder what those “security” question people are thinking.

Street you grew up on? Which of several are you supposed to pick?  
Childhood pet? What childhood pet?  
Favorite teacher? Umm, none of them?  
Ideal vacation? How many words for this? And next month it’ll be different.

And on and on.

For most sites NONE of them will really work for me.

Yep, I do \<weird non-word\> \<key question word\> for each of them.

And as noted: even if you have real answers to these, too many people can guess them.

Security questions, reality shows, etc. We are morphing into Bizzaro World.

---

<div class="post-metadata">

**Author:** ![hajario](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/hajario/32/171_2.png) [@hajario](https://boards.straightdope.com/u/hajario)\
**Post date:** [August 11, 2017, 12:55pm UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/85 "2017-08-11T12:55:26Z")

</div>

> [@ftg](#):
>
> I really wonder what those “security” question people are thinking.
> 
> Street you grew up on? Which of several are you supposed to pick?  
> Childhood pet? What childhood pet?  
> Favorite teacher? Umm, none of them?  
> Ideal vacation? How many words for this? And next month it’ll be different.
> 
> And on and on.
> 
> For most sites NONE of them will really work for me.
> 
> Yep, I do \<weird non-word\> \<key question word\> for each of them.
> 
> And as noted: even if you have real answers to these, too many people can guess them.
> 
> Security questions, reality shows, etc. We are morphing into Bizzaro World.

What’s so damn difficult? You don’t have to give the actual correct answer, you just have to be consistent. Just choose one particular street and teacher and stick to it. As if the web page is going to come back at you and say “Incorrect. You lived on a street other than Maple for six weeks longer. Please resubmit.”

By the way, reality shows have been around for a few decades. They’re nothing new. I have managed to not watch them. It’s really easy.

---

<div class="post-metadata">

**Author:** ![CookingWithGas](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cookingwithgas/32/485_2.png) [@CookingWithGas](https://boards.straightdope.com/u/CookingWithGas)\
**Post date:** [August 11, 2017, 1:17pm UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/86 "2017-08-11T13:17:40Z")

</div>

> [@Procrustus](#):
>
> I like “What color is an orange?”
> 
> Easy to remember.

And easy to guess.

> [@hajario](#):
>
> What’s so damn difficult? You don’t have to give the actual correct answer, you just have to be consistent. Just choose one particular street and teacher and stick to it…

I have logins to maybe 200 accounts. I might have one site out of those that uses childhood street as a security question. I might have to answer that question once every two years. How the hell am I going to remember what answer I gave two years ago? I’ll tell you how, I have to record them all, which in itself can be a security hole.

---

<div class="post-metadata">

**Author:** ![Slash1972](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/slash1972/32/6461_2.png) [@Slash1972](https://boards.straightdope.com/u/Slash1972)\
**Post date:** [August 11, 2017, 1:50pm UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/87 "2017-08-11T13:50:41Z")

</div>

> [@Dr.Strangelove](#):
>
> Your idea is basically equivalent to storing the passwords in cleartext. Those 3-letter segments can be trivially brute-forced, and assembling them back together into the original password is also trivial.

Yeah, I actually thought about this driving home yesterday. You are correct, it’s not really adding anything. I think I answered too quickly yesterday because I had to go to a meeting 🙂

---

<div class="post-metadata">

**Author:** ![Sunspace](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/sunspace/32/1250_2.png) [@Sunspace](https://boards.straightdope.com/u/Sunspace)\
**Post date:** [August 11, 2017, 3:56pm UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/88 "2017-08-11T15:56:37Z")

</div>

> [@CookingWithGas](#):
>
> I use a federal government system that prohibits any dictionary words anywhere in your password. They are just begging for people to either write down their passwords or forget them.

That is easily defeatable… just use words from other languages! No-one is going to be checking you password for words in Hittite or Quechua…

---

<div class="post-metadata">

**Author:** ![ftg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ftg/32/2801_2.png) [@ftg](https://boards.straightdope.com/u/ftg)\
**Post date:** [August 12, 2017, 12:51pm UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/89 "2017-08-12T12:51:04Z")

</div>

> [@hajario](#):
>
> What’s so damn difficult? You don’t have to give the actual correct answer, you just have to be consistent. Just choose one particular street and teacher and stick to it. As if the web page is going to come back at you and say “Incorrect. You lived on a street other than Maple for six weeks longer. Please resubmit.”

Please note: I clearly _am_ sticking to a particular “street” and “teacher”. Just not remotely real ones.

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [August 12, 2017, 3:15pm UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/90 "2017-08-12T15:15:28Z")

</div>

> [@Clothahump](#):
>
> I don’t. If you are referring to the three letters of the site being visited, the formula is flexible enough that I can change it to split the 4 digits and put them in the site identifier.
> 
> So for Chase, instead of Mar@Cha1608, I could use Mar@C16ha08. As long as I am consistent in the structure of the password and use that same structure throughout, it’s all good.

If you \*have \*structure, it’s bad.

---

<div class="post-metadata">

**Author:** ![gaffa](https://avatars.discourse-cdn.com/v4/letter/g/e68b1a/32.png) [@gaffa](https://boards.straightdope.com/u/gaffa)\
**Post date:** [August 14, 2017, 3:40pm UTC](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171/91 "2017-08-14T15:40:29Z")

</div>

That’s why I use LastPass. Yes, I’m having to trust a 3rd party, but they let Steve Gibson audit their code, and he says it’s secure. At some point you have to say “That’s good enough for me!”

So now all my passwords are complete long gibberish with a mix of upper and lower case, numbers, letters and typographical symbols indistinguishable from line noise (if you’re old enough to remember that.)

[Previous page](https://boards.straightdope.com/t/guy-who-came-up-with-all-those-crazy-password-rules-now-says-hes-sorry/793171.md?page=4)
