# Qwertycard password assistance cards - how good/bad an idea is this?

**URL:** <https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178>\
**Category:** Factual Questions\
**Created:** [February 17, 2021, 10:04pm UTC](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178 "2021-02-17T22:04:50Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [February 17, 2021, 10:04pm UTC](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178/1 "2021-02-17T22:04:50Z")

</div>

This product popped up as an ad pretending to be a news article somewhere:  
[https://www.qwertycards.com/](https://www.qwertycards.com/)

So it’s a card the size of a credit card, printed with a simple substitution cipher for the 26 letters of the alphabet, laid out like a QWERTY keyboard, plus a unique static string printed in the place of the space bar.  
The idea is that you use this to create passwords for the sites you are logging into, by compounding:

- the ‘spacebar code’ (so that part will be the same every time)
- A secret word, ciphered using the card (not obliged to be the same every time, but you can bet users will use the same secret word every time)
- The name of the website, ciphered using the card

Maybe it’s just me, but this seems like a terrible idea. Sure, it creates a messy-looking long password that _looks like_ the sort of thing that strong passwords _look like_, but two thirds of the password characters are going to be the same for every site, and the remaining one third has a meaningful and consistent relationship to a guessable string.

Am I right?

---

<div class="post-metadata">

**Author:** ![gnoitall](https://avatars.discourse-cdn.com/v4/letter/g/bb73d2/32.png) [@gnoitall](https://boards.straightdope.com/u/gnoitall)\
**Post date:** [February 17, 2021, 10:12pm UTC](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178/2 "2021-02-17T22:12:31Z")

</div>

Someone is selling a security product based on ROT-13? 🤦‍♂️

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [February 17, 2021, 10:16pm UTC](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178/3 "2021-02-17T22:16:38Z")

</div>

Pretty much (I mean, it’s not ROT-13, but it’s more or less as good as that), and their pitch appears to be ‘look, the passwords are, like, _long_ and also they are, like _random_ because we use a random number generator to make the cards’

---

<div class="post-metadata">

**Author:** ![iamthewalrus\_3](https://avatars.discourse-cdn.com/v4/letter/i/258eb7/32.png) [@iamthewalrus\_3](https://boards.straightdope.com/u/iamthewalrus_3)\
**Post date:** [February 17, 2021, 10:33pm UTC](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178/4 "2021-02-17T22:33:18Z")

</div>

Seems like a lot more work and less secure than using a password manager, but also probably better than what like 95% of people do.

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [February 17, 2021, 10:40pm UTC](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178/5 "2021-02-17T22:40:16Z")

</div>

I don’t know. I think it might actually make things worse for a lot of people

---

<div class="post-metadata">

**Author:** ![iamthewalrus\_3](https://avatars.discourse-cdn.com/v4/letter/i/258eb7/32.png) [@iamthewalrus\_3](https://boards.straightdope.com/u/iamthewalrus_3)\
**Post date:** [February 17, 2021, 10:49pm UTC](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178/6 "2021-02-17T22:49:17Z")

</div>

Most people use a short combination of a dictionary word or two with a number or special character added, and reuse it all over the place. Using this card is _way_ better than that.

---

<div class="post-metadata">

**Author:** ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)\
**Post date:** [February 17, 2021, 11:18pm UTC](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178/7 "2021-02-17T23:18:43Z")

</div>

> [@Mangetout](#):
>
> Maybe it’s just me, but this seems like a terrible idea. Sure, it creates a messy-looking long password that _looks like_ the sort of thing that strong passwords _look like_ , but two thirds of the password characters are going to be the same for every site, and the remaining one third has a meaningful and consistent relationship to a guessable string.
> 
> Am I right?

The attack you’re implicitly describing against this card would require the bad guys to have collected my username (e.g. my email, so not too secret) and my PW from several sites. One site of which would have had to store them insecurely enough that it could be reversibly decrypted.

Armed with 1 or better yet two PWs in the clear, they could then attack the rest pretty easily. Assuming they knew I was using QWERTYCARD as my PW rubric.

The problem with password insecurity is not that people pick crappy PWs. Though they certainly do pick crappy PWs. It’s that they use the same PW on multiple sites (or equivalently use their FB, Google, or Apple creds as universal logins on multiple sites.)

All of those errors mean one compromised site or PW gives the bad guys the keys to your whole kingdom.

To the degree QWERTYCARD succeeded in getting people to use unique PWs, it’d be a net gain right there. Even if those PWs are less than fully cryptographically strong. It’d be usefully increasing the total strength of the user’s portfolio of PWs. My PW vault has just under 300 PWs in it. Duplication is a big problem for many people.

But as you say, as to any single PW on a single site, the tool gives a larger impression of improved security than it delivers actual improved security.

---

<div class="post-metadata">

**Author:** ![Chronos](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chronos/32/134_2.png) [@Chronos](https://boards.straightdope.com/u/Chronos)\
**Post date:** [February 18, 2021, 3:17am UTC](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178/8 "2021-02-18T03:17:05Z")

</div>

Simpler solution: Get a plain ordinary index card (they’re cheap), and write your passwords down on it.

---

<div class="post-metadata">

**Author:** ![Schnitte](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/schnitte/32/9033_2.png) [@Schnitte](https://boards.straightdope.com/u/Schnitte)\
**Post date:** [February 18, 2021, 10:13am UTC](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178/9 "2021-02-18T10:13:27Z")

</div>

Edit: Deleted.

---

<div class="post-metadata">

**Author:** ![Schnitte](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/schnitte/32/9033_2.png) [@Schnitte](https://boards.straightdope.com/u/Schnitte)\
**Post date:** [February 18, 2021, 10:16am UTC](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178/10 "2021-02-18T10:16:45Z")

</div>

> [@Chronos](#):
>
> Simpler solution: Get a plain ordinary index card (they’re cheap), and write your passwords down on it.

Indeed. That doesn’t seem to be much less secure than these Qwertycards, but it’s a lot easier and cheaper.

In my view, these cards create a fake sense of password strength. You think you have a good password because it’s an unintelligible string of characters, but from a real security point of view it’s very weak. The spacebar code is the same for all websites, so you’re importing all the problems from multiple use of the same password across sites. Most likely the same for the secret word, which will, for most users, not only be the same across all websites but an easy-to-memorise (and hence easy to crack) string. And the encryption of the name of the website is a simple substitution, which is, cryptographically, as weak as it can get.

An evildoer who gets access to a user’s Qwertycard will have little trouble getting access to pretty much all log-in credentials of that user across websites. So you need to take good care of that card. But then you can just as well write down your passwords in plain text on a piece of paper and carry that with you.

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [February 18, 2021, 11:34am UTC](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178/11 "2021-02-18T11:34:55Z")

</div>

> [@Schnitte](#):
>
> In my view, these cards create a fake sense of password strength. You think you have a good password because it’s an unintelligible string of characters, but from a real security point of view it’s very weak.

Yep, that’s the point exactly - it’s like the advice that was in circulation as little as a couple of years ago, about using an easy to remember word, and swapping out some letters for numbers; mypassword becomes myp455w02d - it provides only the **feeling** of security, which is actually counterproductive, because feeling secure stops people from seeking more actual, real security.

---

<div class="post-metadata">

**Author:** ![echoreply](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/echoreply/32/3641_2.png) [@echoreply](https://boards.straightdope.com/u/echoreply)\
**Post date:** [February 18, 2021, 4:35pm UTC](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178/12 "2021-02-18T16:35:28Z")

</div>

My guess is that if people use these cards at all, they’ll just use the spacebar string as their password. That is much easier than doing all of the manual cryptography.

On the other hand, anything that can get people to use a different password for different logins will greatly increase security.

---

<div class="post-metadata">

**Author:** ![Schnitte](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/schnitte/32/9033_2.png) [@Schnitte](https://boards.straightdope.com/u/Schnitte)\
**Post date:** [February 18, 2021, 8:37pm UTC](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178/13 "2021-02-18T20:37:38Z")

</div>

Another problem that I see with this technique is that it disincentivises periodic changes of passwords. As long as you keep the same card - which I suppose most users will do for a long time -, changing your passwords requires finding a new “secret word” - something which, I suppose, most users won’t do on a regular basis. So they’ll be stuck with the same log-in credentials for a long period of time.

---

<div class="post-metadata">

**Author:** ![Deeg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/deeg/32/2955_2.png) [@Deeg](https://boards.straightdope.com/u/Deeg)\
**Post date:** [February 18, 2021, 9:30pm UTC](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178/14 "2021-02-18T21:30:10Z")

</div>

My thoughts exactly; just use a password manager.

---

<div class="post-metadata">

**Author:** ![Chronos](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chronos/32/134_2.png) [@Chronos](https://boards.straightdope.com/u/Chronos)\
**Post date:** [February 18, 2021, 9:40pm UTC](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178/15 "2021-02-18T21:40:26Z")

</div>

> [@Schnitte](#):
>
> Another problem that I see with this technique is that it disincentivises periodic changes of passwords.

That’s a feature, not a bug. Periodic changes of passwords decrease security, not increase it.

---

<div class="post-metadata">

**Author:** ![Schnitte](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/schnitte/32/9033_2.png) [@Schnitte](https://boards.straightdope.com/u/Schnitte)\
**Post date:** [February 18, 2021, 10:11pm UTC](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178/16 "2021-02-18T22:11:44Z")

</div>

> [@Chronos](#):
>
> That’s a feature, not a bug. Periodic changes of passwords decrease security, not increase it.

Do they? I realise that what is considered good practice in passwords varies over time, but I thought the advice to change them periodically is still maintained. What’s the theory behind advising against that? The idea that frequent changes make people pick bad passwords out of sheer laziness or forgefulness?

---

<div class="post-metadata">

**Author:** ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)\
**Post date:** [February 18, 2021, 10:46pm UTC](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178/17 "2021-02-18T22:46:07Z")

</div>

> [@Schnitte](#):
>
> The idea that frequent changes make people pick bad passwords out of sheer laziness or forgefulness?

This.

For diligent people using a PW manager, regular changes are harm-reducing. But for people doing it the old fashioned way with human memory and index cards, frequent changes are harm-producing.

A lot of advice has not kept up with the times. Then again, I suspect PW manager use is still down in the single digits percentage of all internet users.

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [February 18, 2021, 10:53pm UTC](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178/18 "2021-02-18T22:53:19Z")

</div>

Yeah, latest advice is that frequent password changes mean that people are nearly always in that phase where they are still adjusting to the new password, and they react to this by choosing simpler passwords, or ones that are easier to remember because they have meaning (which means they are prone to attack by guessing), or they write the password down and keep it close to the computer

---

<div class="post-metadata">

**Author:** ![Chronos](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chronos/32/134_2.png) [@Chronos](https://boards.straightdope.com/u/Chronos)\
**Post date:** [February 19, 2021, 12:57am UTC](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178/19 "2021-02-19T00:57:20Z")

</div>

And what attack is protected against by changing every six weeks, or whatever it is? Someone got ahold of your password, but waited weeks to use it?

---

<div class="post-metadata">

**Author:** ![gnoitall](https://avatars.discourse-cdn.com/v4/letter/g/bb73d2/32.png) [@gnoitall](https://boards.straightdope.com/u/gnoitall)\
**Post date:** [February 19, 2021, 4:24am UTC](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178/20 "2021-02-19T04:24:30Z")

</div>

> [@Chronos](#):
>
> And what attack is protected against by changing every six weeks, or whatever it is?

And old password dump from a site. There were historical compromises where the password database stolen was from a non-recent backup.

[Next page](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178.md?page=2)
