# & make sure you don't write that password down

**URL:** <https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410>\
**Category:** The BBQ Pit\
**Created:** [March 31, 2015, 1:16pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410 "2015-03-31T13:16:49Z")\
**Posts on this page:** 20\
**Page:** 2

<div class="post-metadata">

**Author:** ![septimus](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/septimus/32/410_2.png) [@septimus](https://boards.straightdope.com/u/septimus)\
**Post date:** [March 31, 2015, 5:55pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/21 "2015-03-31T17:55:43Z")

</div>

> [@Do\_Not\_Taunt](#):
>
> Uh, what? I’m yet to see a bank login that wasn’t conducted over HTTPS.

Https is still susceptible to keyboard sniffers. Challenge-response is not.

---

<div class="post-metadata">

**Author:** ![Emtar\_KronJonDerSohn](https://avatars.discourse-cdn.com/v4/letter/e/58956e/32.png) [@Emtar\_KronJonDerSohn](https://boards.straightdope.com/u/Emtar_KronJonDerSohn)\
**Post date:** [March 31, 2015, 6:36pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/22 "2015-03-31T18:36:00Z")

</div>

> [@Slash1972](#):
>
> Don’t all these rules actually reduce the search space for brute-forcing the password? I can’t think of a reason to make a password be EXACTLY 8 characters.

I always thought so. My old employer used a payroll company that had like 30 password requirements and required changing the password every 30 days. HR hated constant phone calls asking for a new temporary password to login so they had a big meeting telling everyone how to structure their passwords to pass the requirements and have an obvious progression. Easier for them, but if I know John Marksberry is suggestible and employee number xxxxx82 on the list and he probably signed up in October then his password is Jn82My!5.

Of course that was fairly useless, as the site obscured SS numbers, names, addresses, rate of pay, and everything else worth snooping through. But that non information sure was secure!

---

<div class="post-metadata">

**Author:** ![Hilarity\_N.Suze](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/hilarity_n.suze/32/6223_2.png) [@Hilarity\_N.Suze](https://boards.straightdope.com/u/Hilarity_N.Suze)\
**Post date:** [March 31, 2015, 6:57pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/23 "2015-03-31T18:57:51Z")

</div>

Your password will expire in 22 days. Would you like to change your password now?

---

<div class="post-metadata">

**Author:** ![gotpasswords](https://avatars.discourse-cdn.com/v4/letter/g/c57346/32.png) [@gotpasswords](https://boards.straightdope.com/u/gotpasswords)\
**Post date:** [March 31, 2015, 8:39pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/24 "2015-03-31T20:39:30Z")

</div>

[QUOTE=manson1972]  
I can’t think of a reason to make a password be EXACTLY 8 characters.  
[/QUOTE]

Legacy systems often have the exactly 8 requirement. They’re from happier pre-Internet times when the risk was primarily from someone physically in the office trying to use your access and we didn’t have to worry about some yutz in Estonia trying to access things from their bedroom.

Windows NT had hashing algorithms that actually made a 7-character password more secure than 8 or more.

Old Oracle stuff could handle 6-8 characters.

Old Solaris Unix systems would cheerfully ignore anything after 8 characters. If your password was Birthday, you could successfully log in with BirthdayCake or BirthdayParty.

Some current mainframe systems ignore case, so RedDog#2 will work just as well as reddog#2 or REDDOG#2 :smack:

ETA: You probably don’t want to know how much of this fantastically old stuff is still running in banks, and how much effort is put to mitigating the risks when some important program written in 1994 can only run on Oracle 2.6.

---

<div class="post-metadata">

**Author:** ![Slash1972](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/slash1972/32/6461_2.png) [@Slash1972](https://boards.straightdope.com/u/Slash1972)\
**Post date:** [March 31, 2015, 8:48pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/25 "2015-03-31T20:48:33Z")

</div>

> [@gotpasswords](#):
>
> Legacy systems often have the exactly 8 requirement. They’re from happier pre-Internet times when the risk was primarily from someone physically in the office trying to use your access and we didn’t have to worry about some yutz in Estonia trying to access things from their bedroom.
> 
> Windows NT had hashing algorithms that actually made a 7-character password more secure than 8 or more.
> 
> Old Oracle stuff could handle 6-8 characters.
> 
> Old Solaris Unix systems would cheerfully ignore anything after 8 characters. If your password was Birthday, you could successfully log in with BirthdayCake or BirthdayParty.
> 
> Some current mainframe systems ignore case, so RedDog#2 will work just as well as reddog#2 or REDDOG#2 :smack:
> 
> ETA: You probably don’t want to know how much of this fantastically old stuff is still running in banks, and how much effort is put to mitigating the risks when some important program written in 1994 can only run on Oracle 2.6.

oh yeah, I’m familiar with the legacy/NT/ignore case issues in the past. It is just really surprising to see a new “Internet presence” feature “new, improved on-line access” need a password that needs EXACTLY 8 characters 😕:eek:

---

<div class="post-metadata">

**Author:** ![Do\_Not\_Taunt](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/do_not_taunt/32/2968_2.png) [@Do\_Not\_Taunt](https://boards.straightdope.com/u/Do_Not_Taunt)\
**Post date:** [March 31, 2015, 9:10pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/26 "2015-03-31T21:10:29Z")

</div>

> [@septimus](#):
>
> Https is still susceptible to keyboard sniffers. Challenge-response is not.

I assumed you meant network-packet sniffing. What manner of challenge response is common for EU banks?

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [March 31, 2015, 10:54pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/27 "2015-03-31T22:54:28Z")

</div>

It seems like some administrators have conflated ‘complex’ and ‘secure’ with ‘hard to remember’ - and although there is some overlap, there definitely is a whiff of “Haha! fuck you!” coming off some of the password formatting rules I’ve seen in the last couple of years - as well as a hint of “I don’t know how to configure this these rules, so I clicked every option!”

---

<div class="post-metadata">

**Author:** ![silenus](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/silenus/32/166_2.png) [@silenus](https://boards.straightdope.com/u/silenus)\
**Post date:** [March 31, 2015, 11:27pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/28 "2015-03-31T23:27:55Z")

</div>

**Haha1fuckyou!** would make a pretty good password.

---

<div class="post-metadata">

**Author:** ![Spiderman](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/spiderman/32/230_2.png) [@Spiderman](https://boards.straightdope.com/u/Spiderman)\
**Post date:** [March 31, 2015, 11:53pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/29 "2015-03-31T23:53:53Z")

</div>

> [@gotpasswords](#):
>
> Legacy systems often have the exactly 8 requirement.

It might be a legacy system, but \*Non-alphanumeric character check have at least 1 of the following non-alphanumeric characters: \_, \_ \* is a new requirement.

I _had_ a system, but it was based on 8 chara, not 7.

> [@silenus](#):
>
> **Haha1fuckyou!** would make a pretty good password.

I heard of setting up your account with your mother’s maiden name as either “I can’t tell you that” or “Fuck you”, which would make for interesting account validation conversation when you call your credit card for any reason.

---

<div class="post-metadata">

**Author:** ![Chimera](https://avatars.discourse-cdn.com/v4/letter/c/8e8cbc/32.png) [@Chimera](https://boards.straightdope.com/u/Chimera)\
**Post date:** [April 1, 2015, 12:34am UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/30 "2015-04-01T00:34:53Z")

</div>

> [@Spiderman](#):
>
> I heard of setting up your account with your mother’s maiden name as either “I can’t tell you that” or “Fuck you”, which would make for interesting account validation conversation when you call your credit card for any reason.

I’ve been the agent on the other end. “Ok, I’m not asking you that question”.

---

<div class="post-metadata">

**Author:** ![Mr\_Shine](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mr_shine/32/464_2.png) [@Mr\_Shine](https://boards.straightdope.com/u/Mr_Shine)\
**Post date:** [April 1, 2015, 12:54am UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/31 "2015-04-01T00:54:18Z")

</div>

What I don’t understand is why none of the sites with ridiculous password rules ever give an error message when attempting to login “that password is impossible with our ruleset, for a reminder when you set your password it had to fit these rules…” In fact the only reminder of the rules you tend to get is when you try to change it, and it won’t accept your new attempt.

---

<div class="post-metadata">

**Author:** ![Chimera](https://avatars.discourse-cdn.com/v4/letter/c/8e8cbc/32.png) [@Chimera](https://boards.straightdope.com/u/Chimera)\
**Post date:** [April 1, 2015, 1:53am UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/32 "2015-04-01T01:53:51Z")

</div>

> [@Mr\_Shine](#):
>
> What I don’t understand is why none of the sites with ridiculous password rules ever give an error message when attempting to login “that password is impossible with our ruleset, for a reminder when you set your password it had to fit these rules…” In fact the only reminder of the rules you tend to get is when you try to change it, and it won’t accept your new attempt.

Our internal database support site spells it out quite clearly.

But as far as many users are concerned, we may have filed it at the bottom of a locked filing cabinet in a disused lavatory. It’s not like they read the emails they get, never mind actually looking for useful information. If it doesn’t fall like manna from the sky, they wouldn’t know about it.

---

<div class="post-metadata">

**Author:** ![Left\_Hand\_of\_Dorkness](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/left_hand_of_dorkness/32/7156_2.png) [@Left\_Hand\_of\_Dorkness](https://boards.straightdope.com/u/Left_Hand_of_Dorkness)\
**Post date:** [April 1, 2015, 3:25am UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/33 "2015-04-01T03:25:51Z")

</div>

> [@Mr\_Shine](#):
>
> What I don’t understand is why none of the sites with ridiculous password rules ever give an error message when attempting to login “that password is impossible with our ruleset, for a reminder when you set your password it had to fit these rules…” In fact the only reminder of the rules you tend to get is when you try to change it, and it won’t accept your new attempt.

One of the worst systems I’ve ever used is for my online grad school classes. First, there’s no “forgot your password?” link for students. Faculty have one, but students have to call the help desk during working hours if you forget a password (which you’re pretty likely to do, since there are at least three different logins you need to access the system, some of which you desperately need exactly once a semester).

But the best part is that there are password rules that are not published anywhere, except as error messages if you don’t follow them. And those error messages flash on the screen at the speed of computerthought before disappearing, leaving you with a blank password field. It’s infuriating.

---

<div class="post-metadata">

**Author:** ![kferr](https://avatars.discourse-cdn.com/v4/letter/k/71e660/32.png) [@kferr](https://boards.straightdope.com/u/kferr)\
**Post date:** [April 1, 2015, 10:52am UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/34 "2015-04-01T10:52:38Z")

</div>

> [@Do\_Not\_Taunt](#):
>
> I assumed you meant network-packet sniffing. What manner of challenge response is common for EU banks?

For one of my accounts I have userid, password, and ‘memorable word’. I enter the full userid and password then get a page that says something like “select characters 2, 4, and 9 of you memorable word” It uses drop down selection lists for the characters which (I think) will defeat keyloggers. When I set up a new outgoing payment recipient a number appears on the screen, then my phone rings with an automated call from the bank. I enter the number on the screen into the phone and the transaction is confirmed.

---

<div class="post-metadata">

**Author:** ![BigT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bigt/32/12044_2.png) [@BigT](https://boards.straightdope.com/u/BigT)\
**Post date:** [April 1, 2015, 11:13am UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/35 "2015-04-01T11:13:05Z")

</div>

> [@Slash1972](#):
>
> Don’t all these rules actually reduce the search space for brute-forcing the password? I can’t think of a reason to make a password be EXACTLY 8 characters.

Yes. As in, passwords are easily brute-forcible on that system. The only thing stopping it would be a limited number of tries–but that won’t matter if someone gets access to the password file.

Not that they probably have good encryption there, either.

---

<div class="post-metadata">

**Author:** ![BeeGee](https://avatars.discourse-cdn.com/v4/letter/b/b5a626/32.png) [@BeeGee](https://boards.straightdope.com/u/BeeGee)\
**Post date:** [April 1, 2015, 12:13pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/36 "2015-04-01T12:13:57Z")

</div>

I use baseball players. My system doesn’t restrict me to eight letters, but no words of even two letters, so I just use the first initial off each word with a=4, e=3,o=0. I add a stat to the end. So the sticky on my monitor says “rfhr” Ok, my right fielder is Ritchie Zisk. Pitch at risk to Ritchie Zisk. P4rtRZ. Next I add my character. I use the same one everything’s#. Then his homeruns. P4rtRZ#207.

If I had to do 8 characters exactly, I’d do initials, set character, position, set character, stat. So the hint “3 finger so” means Three Finger Brown’s shutouts. MB#rp$55.

---

<div class="post-metadata">

**Author:** ![Shodan](https://avatars.discourse-cdn.com/v4/letter/s/9f8e36/32.png) [@Shodan](https://boards.straightdope.com/u/Shodan)\
**Post date:** [April 1, 2015, 12:21pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/37 "2015-04-01T12:21:58Z")

</div>

> [@silenus](#):
>
> **Haha1fuckyou!** would make a pretty good password.

My very first job in IT was to write algorithms to prevent users from using offensive words in their password. That’s when I learned that “why should anyone care, and how would they find out” are not questions to be asked by junior level programmers.

Regards,  
Shodan

---

<div class="post-metadata">

**Author:** ![Catamount](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/catamount/32/2840_2.png) [@Catamount](https://boards.straightdope.com/u/Catamount)\
**Post date:** [April 1, 2015, 1:35pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/38 "2015-04-01T13:35:53Z")

</div>

> [@silenus](#):
>
> **Haha1fuckyou!** would make a pretty good password.

That’s pretty close to my actual work password. Now I have to change it to something more offensive. Thanks.

---

<div class="post-metadata">

**Author:** ![Do\_Not\_Taunt](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/do_not_taunt/32/2968_2.png) [@Do\_Not\_Taunt](https://boards.straightdope.com/u/Do_Not_Taunt)\
**Post date:** [April 1, 2015, 4:01pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/39 "2015-04-01T16:01:31Z")

</div>

> [@kferr](#):
>
> For one of my accounts I have userid, password, and ‘memorable word’. I enter the full userid and password then get a page that says something like “select characters 2, 4, and 9 of you memorable word” It uses drop down selection lists for the characters which (I think) will defeat keyloggers.

Well, that’s like trying to defeat a keylogger by using an on-screen keyboard. If the keylogger is restricted to literally logging keystrokes, yeah, it’ll work. But the counter-measure is easy - screen cap on mouse clicks, or record choices taken from dropdowns or buttons clicked, etc.

> [@](#):
>
> When I set up a new outgoing payment recipient a number appears on the screen, then my phone rings with an automated call from the bank. I enter the number on the screen into the phone and the transaction is confirmed.

This, on the other hand, starts to enter the world of multi-factor authentication, which is much, much safer, and almost no one in the US bothers with…

---

<div class="post-metadata">

**Author:** ![Skywatcher](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/skywatcher/32/254_2.png) [@Skywatcher](https://boards.straightdope.com/u/Skywatcher)\
**Post date:** [August 6, 2015, 8:19pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/40 "2015-08-06T20:19:21Z")

</div>

My employer forces us to change our passwords every 60 days. Changed mine a couple days ago and found that new requirements have been enacted, asinine ones not much different from those in the OP.

My new password is basically “The-new-requirements-are-nuts!” in not so many words. Plus a string of numbers.

[Previous page](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410.md?page=1)

[Next page](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410.md?page=3)
