# Life-cycle of Passwords

**URL:** <https://boards.straightdope.com/t/life-cycle-of-passwords/740741>\
**Category:** Miscellaneous and Personal Stuff I Must Share\
**Created:** [December 17, 2015, 11:41pm UTC](https://boards.straightdope.com/t/life-cycle-of-passwords/740741 "2015-12-17T23:41:25Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cabin\_Fever\_1](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cabin_fever_1/32/2908_2.png) [@Cabin\_Fever\_1](https://boards.straightdope.com/u/Cabin_Fever_1)\
**Post date:** [December 17, 2015, 11:41pm UTC](https://boards.straightdope.com/t/life-cycle-of-passwords/740741/1 "2015-12-17T23:41:25Z")

</div>

I had the best password ever.

A combination of letters (both lower case and upper case), numerals, special characters, and was at least 8 characters long. Most often longer in certain systems.  
I could add/subtract characters at will to said password, depending on their (often stupid) requirements.

An advantage was I didn’t need to write it down, as it was a cryptogram whose meaning was only known only by me. No need for password managers, nor sticky notes taped to the bottom of a dresser drawer.

Now I have been informed by \*\*\*\*\*\* and \*\*\*\* and \*\*\*\*\*\*\*\*\* that it is time to change login credentials.  
**I think I will let Mister Whiskers (a Maine Coon) walk across my keyboard and examine the results.**

The only problem I dread is changing said password on roughly 5-6 devices for every account.  
I am out of sticky notes also, though I have paper towels handy.

---

<div class="post-metadata">

**Author:** ![Merneith](https://avatars.discourse-cdn.com/v4/letter/m/57b2e6/32.png) [@Merneith](https://boards.straightdope.com/u/Merneith)\
**Post date:** [December 18, 2015, 1:09am UTC](https://boards.straightdope.com/t/life-cycle-of-passwords/740741/2 "2015-12-18T01:09:41Z")

</div>

Use a password manager. It will have a password generator to give you unique passwords for all your logins. I’ve used Roboform for the last twelve years. If I didn’t, I’d use KeePass. You will only need to remember one or two master passwords. Use the XKCD method to generate those. Yeah, sure, write them down in your diary or something that never leaves the house.

> **[Password Strength](https://xkcd.com/936/)**
>
> To anyone who understands information theory and security and is in an infuriating argument with someone who does not (possibly involving mixed case), I sincerely apologize.

---

<div class="post-metadata">

**Author:** ![pidgeon92](https://avatars.discourse-cdn.com/v4/letter/p/50afbb/32.png) [@pidgeon92](https://boards.straightdope.com/u/pidgeon92)\
**Post date:** [December 18, 2015, 1:18am UTC](https://boards.straightdope.com/t/life-cycle-of-passwords/740741/3 "2015-12-18T01:18:04Z")

</div>

Yep, a password manager. I use [1password](https://agilebits.com/onepassword). It’s on all of my computers, ithings and android.

---

<div class="post-metadata">

**Author:** ![usedtobe](https://avatars.discourse-cdn.com/v4/letter/u/ec9cab/32.png) [@usedtobe](https://boards.straightdope.com/u/usedtobe)\
**Post date:** [December 18, 2015, 7:11am UTC](https://boards.straightdope.com/t/life-cycle-of-passwords/740741/4 "2015-12-18T07:11:09Z")

</div>

You are REQUIRED to change passwords every X period: you are NOT required to\* wait\* every X period.

Change password. Wait 24 hours. Re-change password to same old password.

Some mainframes (1990+) learned to retain passwords and would not allow a new password to be the same as any from the last 5 passwords.  
So change it 5 times.

---

<div class="post-metadata">

**Author:** ![FairyChatMom](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/fairychatmom/32/21906_2.png) [@FairyChatMom](https://boards.straightdope.com/u/FairyChatMom)\
**Post date:** [December 18, 2015, 1:03pm UTC](https://boards.straightdope.com/t/life-cycle-of-passwords/740741/5 "2015-12-18T13:03:25Z")

</div>

For years I used a base password and changed it monthly by changing the numerical part, which consisted of the month and year. The only problem was on the stupid systems that wouldn’t allow repeated character in sequence. Really? I would think that would add to the complexity of breaking the password. Anyway, I’d just shift one of the repeated characters and off I’d go.

I should start doing that again, since I’m back in the workforce with the stoopit password requirements.

---

<div class="post-metadata">

**Author:** ![UncleRojelio](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/unclerojelio/32/3160_2.png) [@UncleRojelio](https://boards.straightdope.com/u/UncleRojelio)\
**Post date:** [December 18, 2015, 2:14pm UTC](https://boards.straightdope.com/t/life-cycle-of-passwords/740741/6 "2015-12-18T14:14:56Z")

</div>

> [@pidgeon92](#):
>
> Yep, a password manager. I use [1password](https://agilebits.com/onepassword). It’s on all of my computers, ithings and android.

+1

---

<div class="post-metadata">

**Author:** ![enipla](https://avatars.discourse-cdn.com/v4/letter/e/54ee81/32.png) [@enipla](https://boards.straightdope.com/u/enipla)\
**Post date:** [December 18, 2015, 2:36pm UTC](https://boards.straightdope.com/t/life-cycle-of-passwords/740741/7 "2015-12-18T14:36:53Z")

</div>

I have a password manager. It helps.

As for passwords, I choose a line out of a song I like, and use the first letter of each word. Then choose a number and use that numbers special char. Pretty easy to remember.

“Ticking away the moments that make up a dull day” Becomes -  
Tatmtmuadd4$

---

<div class="post-metadata">

**Author:** ![The\_Stainless\_Steel\_Rat](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/the_stainless_steel_rat/32/5727_2.png) [@The\_Stainless\_Steel\_Rat](https://boards.straightdope.com/u/The_Stainless_Steel_Rat)\
**Post date:** [December 18, 2015, 4:40pm UTC](https://boards.straightdope.com/t/life-cycle-of-passwords/740741/8 "2015-12-18T16:40:45Z")

</div>

My passwords usually (like most of you) have to have CAPS and lower-case, numbers and some ‘top-row’ stuff. So I borrow from experience and leave myself some code words that I know but would not be of help to anyone trying to ‘break’ it.

For example, oldAP©+Dad+2SW+newAP(nc) might give you a few hints, but getting it all would be a challenge, IMHO. Even if you puzzle out what it means, you would need an inimate knowledge of my history to figure it all out.

IMHO as always.

---

<div class="post-metadata">

**Author:** ![Senegoid](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/senegoid/32/6606_2.png) [@Senegoid](https://boards.straightdope.com/u/Senegoid)\
**Post date:** [December 19, 2015, 2:50am UTC](https://boards.straightdope.com/t/life-cycle-of-passwords/740741/9 "2015-12-19T02:50:41Z")

</div>

> [@usedtobe](#):
>
> Some mainframes (1990+) learned to retain passwords and would not allow a new password to be the same as any from the last 5 passwords.  
> So change it 5 times.

I used a system for several years where you didn’t get to choose your password at all. You could request a new one whenever you wanted, but you got a random password chosen for you. Security was a bit simpler in those days, so passwords were just a random sequence of six letters.

One guy told me his technique was to request a new password over and over until he got something he could pronounce.

ETA: And some systems make you wait a certain period of time before you can change your password again. I think Windows Server works this way, or it can be configured to.

---

<div class="post-metadata">

**Author:** ![Merneith](https://avatars.discourse-cdn.com/v4/letter/m/57b2e6/32.png) [@Merneith](https://boards.straightdope.com/u/Merneith)\
**Post date:** [December 19, 2015, 7:46am UTC](https://boards.straightdope.com/t/life-cycle-of-passwords/740741/10 "2015-12-19T07:46:13Z")

</div>

> [@usedtobe](#):
>
> You are REQUIRED to change passwords every X period: you are NOT required to\* wait\* every X period.
> 
> Change password. Wait 24 hours. Re-change password to same old password.
> 
> Some mainframes (1990+) learned to retain passwords and would not allow a new password to be the same as any from the last 5 passwords.  
> So change it 5 times.

We’re supposed to be fighting ignorance here. Change your password periodically because it’s the smart thing to do.

---

<div class="post-metadata">

**Author:** ![Lsura](https://avatars.discourse-cdn.com/v4/letter/l/7993a0/32.png) [@Lsura](https://boards.straightdope.com/u/Lsura)\
**Post date:** [December 19, 2015, 12:56pm UTC](https://boards.straightdope.com/t/life-cycle-of-passwords/740741/11 "2015-12-19T12:56:14Z")

</div>

I use song lyrics and l33t them up. So if I was going to use, say, “If I only had a brain” from the Wizard of Oz (since I’ve had that as an earworm for the last two days). The lines:

“I could be another Lincoln  
If I only had a brain.”

might become 1cb@Li10h@B or something like that.

I would never use that because the earworm I’d have every day would be terrible, but I pick something I like, and a line I’ll remember, and there it goes. I usually have it memorized within a couple of days.

---

<div class="post-metadata">

**Author:** ![Harvey\_The\_Heavy](https://avatars.discourse-cdn.com/v4/letter/h/c5a1d2/32.png) [@Harvey\_The\_Heavy](https://boards.straightdope.com/u/Harvey_The_Heavy)\
**Post date:** [December 20, 2015, 1:43pm UTC](https://boards.straightdope.com/t/life-cycle-of-passwords/740741/12 "2015-12-20T13:43:01Z")

</div>

I used to use old license plate numbers, which were seven characters of random letters and numbers. I can’t really anymore since now I am usually required to have eight characters and punctuation. I can’t even use the XKCD method for most things.

So here’s what I do at work now, although it’s probably not as secure as it could be. And my SDMB password is not using this method, so don’t get any funny ideas: I just start with a letter on the top row, usually Q, and type it three times, then go to the number above it and type it three times, then hit shift and type the punctuation on that number three times, so “qqq111!!!”. Then when I’m forced to change the password a few months later, I just move over to the next set of keys, “www222@@@” and so on. If I’m required to use both upper and lower case, I’ll just add another sequence of the letter, “qqqQQQ111!!!”. If anyone wants to hack into my work computer and do all my work for me, feel free.

---

<div class="post-metadata">

**Author:** ![Cabin\_Fever\_1](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cabin_fever_1/32/2908_2.png) [@Cabin\_Fever\_1](https://boards.straightdope.com/u/Cabin_Fever_1)\
**Post date:** [December 20, 2015, 3:04pm UTC](https://boards.straightdope.com/t/life-cycle-of-passwords/740741/13 "2015-12-20T15:04:46Z")

</div>

So for fun and giggles I plopped Mister Whiskers down on my laptop keyboard.  
Now my gggggg key is stuck and the H key is misbehhavinggggggggggggg.

here is his password gggenerated:  
kkerw=e9983fq8gggh0l kj;;;;

No way am I going to remember that. Plus speelcheck is having a fit  
Lesson learned. Don’t put a 40 pound (estimated) cat on top of ones keybpwrd.

I need a new hhobby.

---

<div class="post-metadata">

**Author:** ![Senegoid](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/senegoid/32/6606_2.png) [@Senegoid](https://boards.straightdope.com/u/Senegoid)\
**Post date:** [December 21, 2015, 4:47am UTC](https://boards.straightdope.com/t/life-cycle-of-passwords/740741/14 "2015-12-21T04:47:53Z")

</div>

> [@Harvey\_The\_Heavy](#):
>
> So here’s what I do at work now, although it’s probably not as secure as it could be. And my SDMB password is not using this method, so don’t get any funny ideas: I just start with a letter on the top row, usually Q, and type it three times, then go to the number above it and type it three times, then hit shift and type the punctuation on that number three times, so “qqq111!!!”. Then when I’m forced to change the password a few months later, I just move over to the next set of keys, “www222@@@” and so on. If I’m required to use both upper and lower case, I’ll just add another sequence of the letter, “qqqQQQ111!!!”. If anyone wants to hack into my work computer and do all my work for me, feel free.

My password scheme is similar to this – I pick a password that makes some geometric pattern according to the layout of the keys on the keyboard. I’ve said too much.

---

<div class="post-metadata">

**Author:** ![usedtobe](https://avatars.discourse-cdn.com/v4/letter/u/ec9cab/32.png) [@usedtobe](https://boards.straightdope.com/u/usedtobe)\
**Post date:** [December 21, 2015, 5:41am UTC](https://boards.straightdope.com/t/life-cycle-of-passwords/740741/15 "2015-12-21T05:41:24Z")

</div>

I was one of those 50’s “Free Range”\* kids. As a pre-condition, my mother made sure I memorized:  
my name  
my address  
my phone number.

50+ years later, I still remember this drill.

The address (number, ordinal, street name, street type e.g. 123 N Main Ave.) makes a pretty good base for a password.

There was a comic strip years go in which a character uttered a nonsense term. That term stuck, and I used a vowel-progression on it for many years.

- 
  - back then the term was “kid”. Yes, _ **really!** _

---

<div class="post-metadata">

**Author:** ![septimus](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/septimus/32/410_2.png) [@septimus](https://boards.straightdope.com/u/septimus)\
**Post date:** [December 21, 2015, 1:59pm UTC](https://boards.straightdope.com/t/life-cycle-of-passwords/740741/16 "2015-12-21T13:59:24Z")

</div>

My go-to password for sites that require upper, lower, special AND numeric only uses three keys counting Shift:  
aA1!aA1!  
This is not my password for SDMB, which allowed all-lowercase when I set my password, but you can use it to post comments under my name at certain other sites.

It’s ironic that stupid little blogging sites have strict password rules, while U.S. accounts connected to large sums of money don’t even use challenge-response like European bank websites. (Yes, they use https but that doesn’t defeat keyboard sniffers.)

---

<div class="post-metadata">

**Author:** ![Cabin\_Fever\_1](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cabin_fever_1/32/2908_2.png) [@Cabin\_Fever\_1](https://boards.straightdope.com/u/Cabin_Fever_1)\
**Post date:** [December 21, 2015, 3:17pm UTC](https://boards.straightdope.com/t/life-cycle-of-passwords/740741/17 "2015-12-21T15:17:36Z")

</div>

> [@septimus](#):
>
> My go-to password for sites that require upper, lower, special AND numeric only uses three keys counting Shift:  
> aA1!aA1!  
> This is not my password for SDMB, which allowed all-lowercase when I set my password, but you can use it to post comments under my name at certain other sites.
> 
> It’s ironic that stupid little blogging sites have strict password rules, while U.S. accounts connected to large sums of money don’t even use challenge-response like European bank websites. (Yes, they use https but that doesn’t defeat keyboard sniffers.)

Two factor authentication, but I feel your pain.  
On phone with CS rep who hasn’t clue. What?, wait?, why not? no way? WTF?

Thank you for keeping my money safe. I thought that was one of your jobs. F\*\*\* you world-wide bank and for hiring morons who don’t know how to tie shoe-laces.  
Mods… sorry, just had to vent. Feel free to bump this to the Pit.  
Grrr
