# & make sure you don't write that password down

**URL:** <https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410>\
**Category:** The BBQ Pit\
**Created:** [March 31, 2015, 1:16pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410 "2015-03-31T13:16:49Z")\
**Posts on this page:** 20\
**Page:** 3

<div class="post-metadata">

**Author:** ![CinnamonBabka](https://avatars.discourse-cdn.com/v4/letter/c/bbce88/32.png) [@CinnamonBabka](https://boards.straightdope.com/u/CinnamonBabka)\
**Post date:** [August 6, 2015, 8:24pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/41 "2015-08-06T20:24:59Z")

</div>

Email [this](https://xkcd.com/936/) to the sysadmin.

---

<div class="post-metadata">

**Author:** ![The\_Lurker\_Above](https://avatars.discourse-cdn.com/v4/letter/t/dc4da7/32.png) [@The\_Lurker\_Above](https://boards.straightdope.com/u/The_Lurker_Above)\
**Post date:** [August 6, 2015, 8:30pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/42 "2015-08-06T20:30:51Z")

</div>

> [@Do\_Not\_Taunt](#):
>
> This, on the other hand, starts to enter the world of multi-factor authentication, which is much, much safer, and almost no one in the US bothers with…

Except for video games. My World of Warcraft account is _important_.

---

<div class="post-metadata">

**Author:** ![Moonlitherial](https://avatars.discourse-cdn.com/v4/letter/m/4bbf92/32.png) [@Moonlitherial](https://boards.straightdope.com/u/Moonlitherial)\
**Post date:** [August 7, 2015, 1:42pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/43 "2015-08-07T13:42:23Z")

</div>

> [@Skywatcher](#):
>
> My employer forces us to change our passwords every 60 days. Changed mine a couple days ago and found that new requirements have been enacted, asinine ones not much different from those in the OP.
> 
> My new password is basically “The-new-requirements-are-nuts!” in not so many words. Plus a string of numbers.

LOL!

After struggling through one of those “reveal each requirement with each password attempt” sites I ended up with a password that was something similar to WhofuckingC4RES!

---

<div class="post-metadata">

**Author:** ![dalej42](https://avatars.discourse-cdn.com/v4/letter/d/67e7ee/32.png) [@dalej42](https://boards.straightdope.com/u/dalej42)\
**Post date:** [August 7, 2015, 2:49pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/44 "2015-08-07T14:49:20Z")

</div>

I used to use Thissucks1!

---

<div class="post-metadata">

**Author:** ![Blaster\_Master](https://avatars.discourse-cdn.com/v4/letter/b/cab0a1/32.png) [@Blaster\_Master](https://boards.straightdope.com/u/Blaster_Master)\
**Post date:** [August 7, 2015, 5:29pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/45 "2015-08-07T17:29:51Z")

</div>

> [@Do\_Not\_Taunt](#):
>
> This, on the other hand, starts to enter the world of multi-factor authentication, which is much, much safer, and almost no one in the US bothers with…

A ton of stuff has it, but it’s often optional.

As someone mentioned, my WoW account has an optional authenticator on it, though my account has still been compromised TWICE with that (both times Blizzard’s fault because their incompetent GMs didn’t follow procedures).

My gmail has multi-factor authentication. I attached my phone to it, any time I log in to an unverified system or change certain account settings, I get a text and have to enter a verification code. I can choose to verify a system (like my home PC) which then skips the authentication.

My bank operates similarly to my gmail.

And as for passwords themselves, I tend to think that these password settings are missing the point. They should be easy to remember and hard for computers to brute force. I think [xkcd](https://xkcd.com/936/) did an awesome example of why so many of these schemes are stupid.

And for some of the schemes mentioned here, you’re making a critical mistake. You cannot use a scheme such that if someone knows one password of yours, they can guess another. Consider for a moment that if I use, say, that element password scheme everywhere, then is someone gets happens to get my password from an insecure site, say a random poorly secured website on the internet, it wouldn’t take much to guess what my password might be on a critical site, like my bank or email. I think the sports one I saw works pretty well because the association between the password and the memorization clues isn’t obvious.

I prefer a strategy of pass phrases. I choose a phrase that has a memorable association to whatever it is for me. So, take the SDMB as an example, something like “The Master Speaks” would be bad, since it’s something anyone familiar with the board would also have as an association, but I’m sure we all have some silly quote we remember, or a particular thread or whatever and I use that and run it through a transform akin to other methods mentioned above. For example, I can use the first letter of each word, or first couple if the phrase is too short, or even the whole thing if I’m allowed to use a really long password (I’ve had 30+ character passwords because they were easy to remember). And I generally don’t even need to make a note to remind me.

And this works because it means that even if someone happens to have one of my passwords, even if they can figure out my encoding scheme, it doesn’t help them guess another one. Someone who doesn’t know me has no way of guessing that a non-obvious association and the encoding keeps it from being easily brute forced and meet most complexity requirements, but because of the association, it’s still super easy to remember. And, yeah, I do tend to pick associations based upon how much I care about securing it. For my email, it’s like a 6 or 7 step chain that, as it occurred to me made sense, and now it’s there, but even people I know wouldn’t figure that out, but something like a random page that requires me to log in for generic stuff will get a much simpler one, especially if I use it rarely. And ones where I could care less if anyone gets access because there’s nothing private there, I’ll just use a very generic password.

---

<div class="post-metadata">

**Author:** ![clairobscur](https://avatars.discourse-cdn.com/v4/letter/c/839c29/32.png) [@clairobscur](https://boards.straightdope.com/u/clairobscur)\
**Post date:** [August 7, 2015, 5:43pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/46 "2015-08-07T17:43:41Z")

</div>

> [@Chimera](#):
>
> Into Chemistry?
> 
> H#1Hydrogen  
> C#6Carbon  
> Pu#94Plutonium
> 
> Get the gist? Sign, atomic number, name.
> 
> […]
> 
> And gosh, how do you remember the password?
> 
> Simple: Write “carbon” on a sticky at your desk if you use C#6Carbon. The word alone won’t work unless someone knows the pattern you use, but it will be enough to remind you of what it is.

I use what is basically a variation of this system at work, using other numbered items easily searchable on internet if I forget the password.

However, i’m pretty sure the security people would hate this kind of patterns if they were told about it, since knowing an old password and reading the sticky would make guessing the new password trivial.

---

<div class="post-metadata">

**Author:** ![Skammer](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/skammer/32/143_2.png) [@Skammer](https://boards.straightdope.com/u/Skammer)\
**Post date:** [August 7, 2015, 6:04pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/47 "2015-08-07T18:04:07Z")

</div>

> [@kayaker](#):
>
> What if your dog’s name isn’t 8 letters long?😕

> [@Czarcasm](#):
>
> Change your dog’s name, of course.  
> _Duh!_

I change my dog’s name every 30 days just to be safe. Normally I’d forget what I changed it to, but that’s why I match it to my bank account.

---

<div class="post-metadata">

**Author:** ![bump](https://avatars.discourse-cdn.com/v4/letter/b/7c8e57/32.png) [@bump](https://boards.straightdope.com/u/bump)\
**Post date:** [August 7, 2015, 7:29pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/48 "2015-08-07T19:29:25Z")

</div>

> [@Skywatcher](#):
>
> My employer forces us to change our passwords every 60 days. Changed mine a couple days ago and found that new requirements have been enacted, asinine ones not much different from those in the OP.
> 
> My new password is basically “The-new-requirements-are-nuts!” in not so many words. Plus a string of numbers.

You think that’s bad… try working in IT in a position where you have access to multiple systems.

I can think of seven passwords that I commonly use, and I think I have a handful more logins on systems that I rarely log into, and whose passwords I’ve long forgotten.

That’s in addition to probably 15-20 passwords for various sites, devices, credit cards, banks, utility providers, game systems, etc…

I’ve ended up with a handful of “standard” passwords that I vary in ways that are predictable to me, but not necessarily to everyone else, in order to meet the varying requirements.

---

<div class="post-metadata">

**Author:** ![Senegoid](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/senegoid/32/6606_2.png) [@Senegoid](https://boards.straightdope.com/u/Senegoid)\
**Post date:** [August 7, 2015, 7:34pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/49 "2015-08-07T19:34:28Z")

</div>

> [@Skammer](#):
>
> I change my dog’s name every 30 days just to be safe. Normally I’d forget what I changed it to, but that’s why I match it to my bank account.

It wouldn’t really hurt anything to write down all your dog’s names and keep it on a slip of paper in your wallet, assuming that your dog (like most dogs) can’t read.

---

<div class="post-metadata">

**Author:** ![Inigo\_Montoya](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/inigo_montoya/32/124_2.png) [@Inigo\_Montoya](https://boards.straightdope.com/u/Inigo_Montoya)\
**Post date:** [August 7, 2015, 7:39pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/50 "2015-08-07T19:39:16Z")

</div>

> [@Spiderman](#):
>
> I heard of setting up your account with your mother’s maiden name as either “I can’t tell you that” or “Fuck you”, which would make for interesting account validation conversation when you call your credit card for any reason.

OK, so right after we got married & opened our checking account, the wife and I were getting signed up to access the account online (along with about a dozen others for cards, savings, power bill, etc.). After trying 4 or 5 variants of our preferred username and finding those all were taken, we got mad and just signed in as “FuckYou(xyz)”.

Later we were both at the actual branch dealing with something and the guy asked if we had online access. We didn’t remember whether we’d set it up so the guy checked for us. A couple seconds after his eyebrows popped up he asked us whether we’d had some difficulty settling on a username. 🙂

---

<div class="post-metadata">

**Author:** ![Miller](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/miller/32/481_2.png) [@Miller](https://boards.straightdope.com/u/Miller)\
**Post date:** [August 7, 2015, 9:13pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/51 "2015-08-07T21:13:10Z")

</div>

I forgot my password to access my bank account online a month ago, and discovered that my bank’s password recovery system is a closed loop. Before they’ll reset your password, they want you to verify that you are who you say you are… which they do by asking you to enter your password.

:smack:

I’m really, really hoping that was just a bug in the logic of the password recovery system, and not a deliberate design choice. But either way, it doesn’t put my bank in a very flattering light. I’d be very concerned that my money isn’t safe there, if I had any.

---

<div class="post-metadata">

**Author:** ![Yllaria](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/yllaria/32/3452_2.png) [@Yllaria](https://boards.straightdope.com/u/Yllaria)\
**Post date:** [August 7, 2015, 9:15pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/52 "2015-08-07T21:15:11Z")

</div>

> [@Moonlitherial](#):
>
> LOL!
> 
> After struggling through one of those “reveal each requirement with each password attempt” sites I ended up with a password that was something similar to WhofuckingC4RES!

A password that starts with Fuc4 uses the Capital and Number. So it’s a pretty good start.

---

<div class="post-metadata">

**Author:** ![GargoyleWB](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/gargoylewb/32/199_2.png) [@GargoyleWB](https://boards.straightdope.com/u/GargoyleWB)\
**Post date:** [August 7, 2015, 9:17pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/53 "2015-08-07T21:17:43Z")

</div>

> [@Senegoid](#):
>
> It wouldn’t really hurt anything to write down all your dog’s names and keep it on a slip of paper in your wallet, assuming that your dog (like most dogs) can’t read.

To also protect from dog logins, use only the interior rows of keys, not the top and bottom rows. Dogs can’t hit the interior keys with their paws without mashing multiple buttons.

---

<div class="post-metadata">

**Author:** ![Senegoid](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/senegoid/32/6606_2.png) [@Senegoid](https://boards.straightdope.com/u/Senegoid)\
**Post date:** [August 8, 2015, 7:04am UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/54 "2015-08-08T07:04:36Z")

</div>

> [@GargoyleWB](#):
>
> To also protect from dog logins, use only the interior rows of keys, not the top and bottom rows. Dogs can’t hit the interior keys with their paws without mashing multiple buttons.

Oh, pshaw. Your dog could log in to your account, steal all your money and personal information, even steal your identity, and nobody would ever be the wiser. [Cite.](https://upload.wikimedia.org/wikipedia/en/f/f8/Internet_dog.jpg)

ETA: If your dog is a dachshund, he could even dox you.

---

<div class="post-metadata">

**Author:** ![Cazzle](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cazzle/32/75_2.png) [@Cazzle](https://boards.straightdope.com/u/Cazzle)\
**Post date:** [August 8, 2015, 7:36am UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/55 "2015-08-08T07:36:19Z")

</div>

> [@Slash1972](#):
>
> Don’t all these rules actually reduce the search space for brute-forcing the password? I can’t think of a reason to make a password be EXACTLY 8 characters.

Ugh, my bank requires exactly 6 digits, one must be a number, no special characters or capital letters. I’ve emailed them several times asking them to increase the maximum character length but they keep replying that they believe it’s sufficiently secure. I have a 22 character password on my email, and six on my bank. :rolleyes: And that on-screen keyboard is a nightmare when I’m in a situation where I’m worried my screen may be observed while I’m entering it.

---

<div class="post-metadata">

**Author:** ![j666](https://avatars.discourse-cdn.com/v4/letter/j/9de0a6/32.png) [@j666](https://boards.straightdope.com/u/j666)\
**Post date:** [August 8, 2015, 1:31pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/56 "2015-08-08T13:31:03Z")

</div>

> [@Hilarity\_N.Suze](#):
>
> Your password will expire in 22 days. Would you like to change your password now?

I get so used to ignoring those reminders I miss the “in 1 days” regularly, and need IT to reset me.

I used to be more diligent until after one of the many times I locked myself out right after changing my password, IT told me to write it down (instead of telling me to wait 15 minutes before using it for another application - they finally started doing that after two years, and we had all already figured it out).

Now I just let it expire and ask them to reset me.

---

<div class="post-metadata">

**Author:** ![Smeghead](https://avatars.discourse-cdn.com/v4/letter/s/f1d935/32.png) [@Smeghead](https://boards.straightdope.com/u/Smeghead)\
**Post date:** [August 8, 2015, 4:24pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/57 "2015-08-08T16:24:32Z")

</div>

> [@Miller](#):
>
> I’d be very concerned that my money isn’t safe there, if I had any.

Where would it be safer than in a system that no one can access?!

---

<div class="post-metadata">

**Author:** ![dropzone](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dropzone/32/7515_2.png) [@dropzone](https://boards.straightdope.com/u/dropzone)\
**Post date:** [August 8, 2015, 4:57pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/58 "2015-08-08T16:57:41Z")

</div>

My bank asks for my user name (first and last name, no spaces or caps). Then it has one of three challenge questions: paternal grandfather’s first name and father’s middle name and “Name of first boyfriend/girlfriend;” if I were gay or a straight female they could all be the same. Next is a photo of an HP 200A audio oscillator to prove they are who they pretend to be(!), and finally my password, which happens to be, well, I won’t say. All very highly secure.

Some sites I have my user name and password in the name of my favorites. I really don’t care who hacks my gmail account.

---

<div class="post-metadata">

**Author:** ![Nava](https://avatars.discourse-cdn.com/v4/letter/n/da6949/32.png) [@Nava](https://boards.straightdope.com/u/Nava)\
**Post date:** [August 10, 2015, 4:57am UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/59 "2015-08-10T04:57:53Z")

</div>

I’ve finally given up and started, no, not keeping lists of passwords in a txt.

Keeping lists of password requirements in a fucking txt. Because some of the places I need to log into (such as several of my utilities) can’t be arsed tell you what their requirements are, and one gives the wrong information. Hey you morons! If it has to be all-numbers, provide that hint somewhere, and if it has to be exactly 9 characters long don’t say “6 or more”.

Oh and the ones who require “special characters” but of course it’s a limited list thereof. Your webpage shouldn’t go into spasms if someone types a diacritic into a password field.

---

<div class="post-metadata">

**Author:** ![adhemar](https://avatars.discourse-cdn.com/v4/letter/a/3da27b/32.png) [@adhemar](https://boards.straightdope.com/u/adhemar)\
**Post date:** [August 10, 2015, 5:54pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/60 "2015-08-10T17:54:24Z")

</div>

I have a govenment password that must be 14 characters, must have at least one capital letter, one special character and one numeral, no repeat letters and no known words, also no previously used password. I have to use a password generator and it still rejects those. also the password is only good for 60 days.

[Previous page](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410.md?page=2)

[Next page](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410.md?page=4)
