# & make sure you don't write that password down

**URL:** <https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410>\
**Category:** The BBQ Pit\
**Created:** [March 31, 2015, 1:16pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410 "2015-03-31T13:16:49Z")\
**Posts on this page:** 8\
**Page:** 4

<div class="post-metadata">

**Author:** ![j666](https://avatars.discourse-cdn.com/v4/letter/j/9de0a6/32.png) [@j666](https://boards.straightdope.com/u/j666)\
**Post date:** [August 11, 2015, 3:00am UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/61 "2015-08-11T03:00:35Z")

</div>

> [@adhemar](#):
>
> I have a govenment password that must be 14 characters, must have at least one capital letter, one special character and one numeral, no repeat letters and no known words, also no previously used them.

Why don’t they use biometric? It has to be cheaper than maintaining staffing levels necessary to reset all the forgotten passwords.

---

<div class="post-metadata">

**Author:** ![Leaper](https://avatars.discourse-cdn.com/v4/letter/l/4bbf92/32.png) [@Leaper](https://boards.straightdope.com/u/Leaper)\
**Post date:** [August 11, 2015, 5:23am UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/62 "2015-08-11T05:23:39Z")

</div>

> [@adhemar](#):
>
> I have a govenment password that must be 14 characters, must have at least one capital letter, one special character and one numeral, no repeat letters and no known words, also no previously used password. I have to use a password generator and it still rejects those. also the password is only good for 60 days.

… And writing it down is punishable by up to a week in a federal jail for endangering the integrity of a government system.

---

<div class="post-metadata">

**Author:** ![gotpasswords](https://avatars.discourse-cdn.com/v4/letter/g/c57346/32.png) [@gotpasswords](https://boards.straightdope.com/u/gotpasswords)\
**Post date:** [August 11, 2015, 10:38pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/63 "2015-08-11T22:38:26Z")

</div>

[QUOTE=Nava]  
Oh and the ones who require “special characters” but of course it’s a limited list thereof. Your webpage shouldn’t go into spasms if someone types a diacritic into a password field.  
[/QUOTE]

Don’t blame your bank or whatever is being fussy. Blame legacy operating systems and applications.

It’s not the website (e.g.: Weblogic or Apache) that can’t handle funny characters. It’s the back-end database that will be knocked sideways into next Thursday. As one example, Oracle will interpret the backslash as an escape to change characters in the string, unless the user knows to enclose the password with double quotes. Likewise, Oracle wants to use $ and % as environment variables, so passwords that start with those may cause problems. SQL and DB2 also have their own quirks. [Watch out for little Bobby Tables.](https://xkcd.com/327/)

As a side note, crackers can use these requirements to “footprint” the system and identify the operating system, webserver middleware and backend database, so some sites don’t describe the requirements, thinking it’s safer that way. In reality, it just irritates the valid users.

---

<div class="post-metadata">

**Author:** ![Deeg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/deeg/32/2955_2.png) [@Deeg](https://boards.straightdope.com/u/Deeg)\
**Post date:** [August 12, 2015, 6:21am UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/64 "2015-08-12T06:21:07Z")

</div>

> [@Blaster\_Master](#):
>
> And for some of the schemes mentioned here, you’re making a critical mistake. You cannot use a scheme such that if someone knows one password of yours, they can guess another. Consider for a moment that if I use, say, that element password scheme everywhere, then is someone gets happens to get my password from an insecure site, say a random poorly secured website on the internet, it wouldn’t take much to guess what my password might be on a critical site, like my bank or email. I think the sports one I saw works pretty well because the association between the password and the memorization clues isn’t obvious.

While you are technically correct it’s really not a big deal for a vast majority of people. Hackers are trying to crack things roboticly; they aren’t going to waste time trying to figure out if someone is using a system unless it’s worth their while. Bill Gates probably shouldn’t use a system; most Dopers can get away with it.

---

<div class="post-metadata">

**Author:** ![Little\_Nemo](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/little_nemo/32/3120_2.png) [@Little\_Nemo](https://boards.straightdope.com/u/Little_Nemo)\
**Post date:** [August 12, 2015, 6:33am UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/65 "2015-08-12T06:33:54Z")

</div>

The next dog I have, I’m going to name him Password just to mess with sysadmins.

---

<div class="post-metadata">

**Author:** ![GrumpyBunny](https://avatars.discourse-cdn.com/v4/letter/g/bc8723/32.png) [@GrumpyBunny](https://boards.straightdope.com/u/GrumpyBunny)\
**Post date:** [August 12, 2015, 12:06pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/66 "2015-08-12T12:06:11Z")

</div>

> [@Chimera](#):
>
> But as far as many users are concerned, we may have filed it at the bottom of a locked filing cabinet in a disused lavatory. It’s not like they read the emails they get, never mind actually looking for useful information. If it doesn’t fall like manna from the sky, they wouldn’t know about it.

I hear your annoyance, but I’ll point out that some users are freakin’ drowning in email. (I would get literally 8,000 a day at my old job, most totally pointless “This file loaded” crap, but even with rules and auto-delete, it’s a PITA to keep up.)

---

<div class="post-metadata">

**Author:** ![AtomicDog](https://avatars.discourse-cdn.com/v4/letter/a/ac91a4/32.png) [@AtomicDog](https://boards.straightdope.com/u/AtomicDog)\
**Post date:** [August 12, 2015, 4:46pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/67 "2015-08-12T16:46:47Z")

</div>

> [@Spiderman](#):
>
> It might be a legacy system, but \*Non-alphanumeric character check have at least 1 of the following non-alphanumeric characters: \_, \_ \* is a new requirement.
> 
> I _had_ a system, but it was based on 8 chara, not 7.
> 
> I heard of setting up your account with your mother’s maiden name as either “I can’t tell you that” or “Fuck you”, which would make for interesting account validation conversation when you call your credit card for any reason.

Years ago, my work password was “shithead.” I loved that one, until it expired and I was forced to change it.

---

<div class="post-metadata">

**Author:** ![Mama\_Zappa](https://avatars.discourse-cdn.com/v4/letter/m/71e660/32.png) [@Mama\_Zappa](https://boards.straightdope.com/u/Mama_Zappa)\
**Post date:** [August 13, 2015, 7:09pm UTC](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410/68 "2015-08-13T19:09:37Z")

</div>

> [@andros](#):
>
> Except for the whole “precisely 8 characters” restriction, which is entirely inane.

At least they _told_ you the 8 characters (well, 7 really).

I once spent several days trying to update a work-related password. Required number of numeric/alpha/upper/lower/special characters, minimum length 14… only when they said “at least” they really meant _exactly_ 14. And not all special characters worked, and they didn’t say which ones would.

[Previous page](https://boards.straightdope.com/t/make-sure-you-dont-write-that-password-down/716410.md?page=3)
