# Qwertycard password assistance cards - how good/bad an idea is this?

**URL:** <https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178>\
**Category:** Factual Questions\
**Created:** [February 17, 2021, 10:04pm UTC](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178 "2021-02-17T22:04:50Z")\
**Posts on this page:** 13\
**Page:** 4

<div class="post-metadata">

**Author:** ![md-2000](https://avatars.discourse-cdn.com/v4/letter/m/9d8465/32.png) [@md-2000](https://boards.straightdope.com/u/md-2000)\
**Post date:** [October 22, 2021, 6:20am UTC](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178/61 "2021-10-22T06:20:37Z")

</div>

An important point to also emphasize - there are no algorithms for hacking passwords that say “getting warmer!”. Passwords (unless the site is really stupid) are stored as hashes. A good hash algorithm does not indicate a guess is close to correct - one character off and the resulting hash is far off. (Or else the hash algorithm is incorrectly chosen and weak, and there’s plenty of research to avoid this)

So the enemy of dictionary attacks that include variants is the number of conceivable variants and whether there’s an algorithmic way to enumerate them…

Similarly, 2FA is great until you lose your phone or someone SIM-hijacks you. Every process has an upside and a downside. When the hackers get your Twitter password, it’s unlikely they also get control of your phone number.

Whether a greater effort will be made to hack your password depends on your target value. Rachel Maddow recently told the story of a Romanian hacker who broke into a number of assorted accounts for various celebrities - by the simple expedient of reading gossip websites and trying name of pet, mother’s maiden name, and whatever else he could dig up about the celebrities. But if we’re not Paris Hilton, basically as mentioned the hackers will just add us to an algorithmic dictionary attack and move on if that can’t figure out our password.

---

<div class="post-metadata">

**Author:** ![drachillix](https://avatars.discourse-cdn.com/v4/letter/d/48db29/32.png) [@drachillix](https://boards.straightdope.com/u/drachillix)\
**Post date:** [November 28, 2021, 7:09am UTC](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178/62 "2021-11-28T07:09:34Z")

</div>

Something easy to remember for user while looking much like random letters to an automated process.

---

<div class="post-metadata">

**Author:** ![The\_Librarian](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/the_librarian/32/402_2.png) [@The\_Librarian](https://boards.straightdope.com/u/The_Librarian)\
**Post date:** [November 28, 2021, 10:27am UTC](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178/63 "2021-11-28T10:27:40Z")

</div>

> [@md-2000](#):
>
> But if we’re not Paris Hilton

This sentiment is why ransomware is a multi-billion industry.

Yes, there are people out to get you (all of us). Do use good security practices.

---

<div class="post-metadata">

**Author:** ![Schnitte](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/schnitte/32/9033_2.png) [@Schnitte](https://boards.straightdope.com/u/Schnitte)\
**Post date:** [November 28, 2021, 11:20am UTC](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178/64 "2021-11-28T11:20:42Z")

</div>

And what do you do if the automated process is smarter than simply trying random letters?

---

<div class="post-metadata">

**Author:** ![Saint\_Cad](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/saint_cad/32/18907_2.png) [@Saint\_Cad](https://boards.straightdope.com/u/Saint_Cad)\
**Post date:** [November 28, 2021, 2:04pm UTC](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178/65 "2021-11-28T14:04:20Z")

</div>

> [@md-2000](#):
>
> Similarly, 2FA is great until you lose your phone or someone SIM-hijacks you.

Or you get customer service that helps “you” out by changing your phone number for you when you can’t log into your account.

---

<div class="post-metadata">

**Author:** ![Bubbp](https://avatars.discourse-cdn.com/v4/letter/b/b38774/32.png) [@Bubbp](https://boards.straightdope.com/u/Bubbp)\
**Post date:** [November 28, 2021, 3:05pm UTC](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178/66 "2021-11-28T15:05:31Z")

</div>

Worked in IT Security for 20 years and have run many password crackers (legally). A fairly recent study (sorry, I don’t have the source handy) showed that that _longer passwords are definitely safer_. Something that I always advocated for business systems (to no avail most of the time).

One, because it takes longer to crack, and two, because there are so many ‘short’ passwords, it’s a waste of cpu cycles to attempt to crack the longer ones. In other words, why go after the hard ones when there’s so much low hanging fruit? Unless you are specifically targeted as an individual, using a ‘pass phrase’ is very effective against ID theft. 20 characters are not hard to memorize if you use a memorable phrase. “_My shoes are blue velvet 123_” - 28 characters, including a capital, spaces, and numbers. This is easy to remember, and even if you only change a few characters for re-use, is still long enough to deter most hackers.

---

<div class="post-metadata">

**Author:** ![Chronos](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chronos/32/134_2.png) [@Chronos](https://boards.straightdope.com/u/Chronos)\
**Post date:** [November 28, 2021, 6:36pm UTC](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178/67 "2021-11-28T18:36:54Z")

</div>

> [@](#):
>
> A fairly recent study (sorry, I don’t have the source handy) showed that that _longer passwords are definitely safer_ .

That’s absolutely, definitely, without a doubt, true. The usual advice for improving password security is to increase the kinds of characters used in your password. But a password randomly generated from the set of all possible characters generatable on a standard English keyboard is actually less secure than one randomly generated entirely of digits, but twice as long: The keyboard characters have 95 possibilities (if the password field accepts spaces), while a pair of digits has 100 possibilities.

---

<div class="post-metadata">

**Author:** ![md-2000](https://avatars.discourse-cdn.com/v4/letter/m/9d8465/32.png) [@md-2000](https://boards.straightdope.com/u/md-2000)\
**Post date:** [November 28, 2021, 9:49pm UTC](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178/68 "2021-11-28T21:49:42Z")

</div>

> [@Saint\_Cad](#):
>
> Or you get customer service that helps “you” out by changing your phone number for you when you can’t log into your account.

Usually one of the easier methods of SIM hijacking - that, and actual customer service person being paid to do so… Some such SIM hijacks are so questionable there most likely was bribery involved. very low level people that have this level of access.

> [@The\_Librarian](#):
>
> > [@md-2000](#):
> >
> > But if we’re not Paris Hilton
> 
> This sentiment is why ransomware is a multi-billion industry.
> 
> Yes, there are people out to get you (all of us). Do use good security practices.

But people in the public eye are far easier targets when it comes to knowing the name of their pet or their mother’s maiden name. Plus those pesky security questions like who was your best friend growing up, favorite schoolteacher, where you got married. Public figures tended to share that info with gossip magazines.

But yes, if your password is simple, if it is a dictionary word plus 2 characters, etc. - all the simple stuff mentioned in this thread - then you are at risk. If all your life story is on social media and people can match it with your account names - then you may as well be Paris Hilton. If you click on odd links in emails - you may as well be Paris Hilton.

---

<div class="post-metadata">

**Author:** ![turtlescanfly](https://avatars.discourse-cdn.com/v4/letter/t/65b543/32.png) [@turtlescanfly](https://boards.straightdope.com/u/turtlescanfly)\
**Post date:** [November 28, 2021, 10:05pm UTC](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178/69 "2021-11-28T22:05:04Z")

</div>

I’ll just add that when a website asks you a security question, you are under no obligation to give the correct answer to the question. I routinely give fake answers, it only matters that I remember what I gave.

I had a very pleasant childhood growing up on Mockingbird Lane with my dog Lassie and my best friend Dobie Gillis. As far as a hacker is concerned, my mothers maiden name is Bouvier and I went to Chester A. Arthur middle school. My first job was safety inspector for a nuclear power plant, and my first car was a Gremlin…

All you need is a robust fake narrative and you’re safe, at least from that type of attack.

---

<div class="post-metadata">

**Author:** ![Chronos](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chronos/32/134_2.png) [@Chronos](https://boards.straightdope.com/u/Chronos)\
**Post date:** [November 28, 2021, 11:18pm UTC](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178/70 "2021-11-28T23:18:00Z")

</div>

As long as you answer consistently. Was your first job “safety inspector for a nuclear power plant”, or was it “nuclear safety inspector”? At some point, you might as well just record your security answers wherever you record your passwords, and at that point, your first job might as well be “f$Y37hB8]L”

---

<div class="post-metadata">

**Author:** ![scudsucker](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/scudsucker/32/14101_2.png) [@scudsucker](https://boards.straightdope.com/u/scudsucker)\
**Post date:** [November 29, 2021, 12:55am UTC](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178/71 "2021-11-29T00:55:36Z")

</div>

A non-english word accompanying your pass phrase can throw off dictionary attacks. For example ny bank account password includes a “Kaapse-taal” swear word. (Kaapse-taal being a unique dialect of Afrikaans, and one not likely to appear in rainbow tables)

I imagine Hungarian or Choctaw slang words would be similarly memorable (if you speak either) and will be unlikely to appear in the hackers list in his rainbow tables.

---

<div class="post-metadata">

**Author:** ![The\_Librarian](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/the_librarian/32/402_2.png) [@The\_Librarian](https://boards.straightdope.com/u/The_Librarian)\
**Post date:** [November 29, 2021, 6:52am UTC](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178/72 "2021-11-29T06:52:27Z")

</div>

> [@turtlescanfly](#):
>
> I’ll just add that when a website asks you a security question, you are under no obligation to give the correct answer to the question. I routinely give fake answers, it only matters that I remember what I gave.

I usually C/P the question, generate a 24 character random string and paste that string as the answer and add it to the “notes” field of my password manager.  
My mothers maiden name: %043NbM3@IDE6NtajZgWqCZliU  
my first pet: D#Xtv9L1nNR7!rW2YLT3v11gq$

---

<div class="post-metadata">

**Author:** ![Dag\_Otto](https://avatars.discourse-cdn.com/v4/letter/d/439d5e/32.png) [@Dag\_Otto](https://boards.straightdope.com/u/Dag_Otto)\
**Post date:** [November 29, 2021, 6:13pm UTC](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178/73 "2021-11-29T18:13:52Z")

</div>

> [@The\_Librarian](#):
>
> I usually C/P the question, generate a 24 character random string and paste that string as the answer and add it to the “notes” field of my password manager.  
> My mothers maiden name: %043NbM3@IDE6NtajZgWqCZliU  
> my first pet: D#Xtv9L1nNR7!rW2YLT3v11gq$

I do the same, but I will suggest that you limit the characters to lowercase and numbers only. I’ve had to read these back to customer service agents as part of the identity verification process, and not having to specify uppercase or lowercase, or deal with the names for the special characters is a bit of a timesaver. Cutting and pasting complex strings is easy, speaking them is a bit harder.

[Previous page](https://boards.straightdope.com/t/qwertycard-password-assistance-cards-how-good-bad-an-idea-is-this/933178.md?page=3)
