SIGforum
Sick of passwords

This topic can be found at:
https://sigforum.com/eve/forums/a/tpc/f/230601935/m/9200051115

October 02, 2024, 04:50 PM
ZSMICHAEL
Sick of passwords
At least several times per day I am required to enter passwords on several sites. Invariably I make an error and am sent to Password Hell while an IT person solves the issue. Typically the IT person is at the end of a long hold. Is there not a better way?
October 02, 2024, 05:07 PM
V-Tail
Use a password manager.



הרחפת שלי מלאה בצלופחים
October 02, 2024, 05:21 PM
CoolRich59
Password manager is definitely the way to go.

Mine has a browser extension. When I need to log in to a site, I just input a couple of keystrokes and it loads both my user ID and my password.


_____________________________________________________________________
“One of the common failings among honorable people is a failure to appreciate how thoroughly dishonorable some other people can be, and how dangerous it is to trust them.” – Thomas Sowell
October 02, 2024, 06:30 PM
dsiets
quote:
Originally posted by V-Tail:
Use a password manager.

October 02, 2024, 07:10 PM
RogueJSK
I'm shocked that nobody has mentioned a password manager thus far.
October 03, 2024, 05:48 AM
egregore
Why not just write them down on sticky notes?
October 03, 2024, 07:10 AM
92fstech
I'm with the OP. I'm completely and utterly over passwords. Ridiculous complexity requirements, stupidly short mandatory change intervals, policies that don't allow re-use of old passwords...it all pretty much guarantees that you're going to forget it before you have to use it again. Especially for stuff you only do once or twice a year. Which means every time you have to pay your insurance, or check your health records, you get to go through the whole recovery process, two factor authentication, etc etc...and heaven help you if your phone number has changed!

Yeah, you can write it down, or store them all in some sketchy app so whoever developed it can have access via backdoor to all your stuff. I don't see how that's more secure than a simple password (or system of passwords) that you can actually remember in your head all by yourself. But the freaking security people have made that approach pretty much impossible these days.
October 03, 2024, 08:07 AM
Pipe Smoker
For about the fifth time in this thread, use a password manager.

A unique long, strong PW for every account. And they sync over all devices. E.g., iPhone and MacBook. Furthermore, a password manager will log you in to the account.

I use mSecure. About $15/year. Money well spent in this hacker-plagued world.



Don’t argue with fools.
October 03, 2024, 08:10 AM
Perception
The good news is that the NIST has updated their password guidelines this year. They removed the requirement for uppercase, lowercase, and special characters because in practice it makes users more likely to create weak passwords.

They also now recommend only changing passwords when the user requests a change or the password is found to be compromised. This change is due to the fact that frequent password changes makes it more likely that users will pick weak passwords for memorization or use patterns that make them easier to guess, in addition to the constant frustration of having to change all the time.

Password managers are still probably the best solution, but hopefully we will have some peace from constant changes coming.




"The people hate the lizards and the lizards rule the people."
"Odd," said Arthur, "I thought you said it was a democracy."
"I did," said Ford, "it is."
"So," said Arthur, hoping he wasn't sounding ridiculously obtuse, "why don't the people get rid of the lizards?"
"It honestly doesn't occur to them. They've all got the vote, so they all pretty much assume that the government they've voted in more or less approximates the government they want."
"You mean they actually vote for the lizards."
"Oh yes," said Ford with a shrug, "of course."
"But," said Arthur, going for the big one again, "why?"
"Because if they didn't vote for a lizard, then the wrong lizard might get in."
October 03, 2024, 08:30 AM
Georgeair
I would love to hear from your "IT person". I bet they have some input as well on the Hell you describe.....

What systems are you using that that don't have a self-serve way to reset passwords?

Oh - and maybe a password manager?



You only have integrity once. - imprezaguy02

October 03, 2024, 09:16 AM
Fly-Sig
And, why do they hide what I'm typing behind *****? Why isn't it defaulted to visible, and allow me to choose hidden if I am in public? 99.999% of the time I enter a password I am in a private location where nobody else will see my screen.
October 03, 2024, 10:30 AM
V-Tail
Creating a password...

cabbage

Sorry, the password must be more than 8 characters.

boiled cabbage

Sorry, the password must contain 1 numerical character.

1 boiled cabbage

Sorry, the password cannot have blank spaces.

50fuckingboiledcabbages

Sorry, the password must contain at least one uppercase character.

50FUCKINGboiledcabbages

Sorry, the password cannot use more than one uppercase character consecutively.

50FuckingBoiledCabbagesShovedUpYourArse,IfYouDon'tGiveMeAccessImmediately

Sorry, the password cannot contain punctuation.

NowlAmGettingReallyPissedOff50FuckingBoiledCabbagesShovedUpYourArselfYou DontGiveMeAccessImmediately

Sorry, that password is already in use!



הרחפת שלי מלאה בצלופחים
October 03, 2024, 10:31 AM
trapper189
quote:
Originally posted by egregore:
Why not just write them down on sticky notes?

Go ahead and let the Ruskie and Chinese hackers try and figure out what's on my sticky notes!
October 03, 2024, 10:34 AM
V-Tail
Simplify your life. Use the same password for everything. Write it on a Post-It note and stick it on the side of your monitor, or for extra security, put it on the bottom of your keyboard.



הרחפת שלי מלאה בצלופחים
October 03, 2024, 11:12 AM
RogueJSK
quote:
Originally posted by V-Tail:
Simplify your life. Use the same password for everything.




No.

Just no.
October 03, 2024, 11:57 AM
parabellum
My suggestion is to use a password manager.

.

Or, just use one password for everything.
October 03, 2024, 11:59 AM
dsiets
quote:
Originally posted by V-Tail:
Simplify your life. Use the same password for everything. Write it on a Post-It note and stick it on the side of your monitor,

I remember watching an early show of ZDNet where people would call in w/ computer questions.
Someone called in to tell the host that his password on the sticky note on the montior was being shown on TV.
And that guy was supposed to be the expert. Big Grin
October 03, 2024, 05:12 PM
gjgalligan
What guarantee is there that pass word managers can't be hacked?


Integrity is doing the right thing, even when nobody is looking.
October 03, 2024, 06:00 PM
4MUL8R
I am slowly converting from Dashlane, a "password manager" to Apple Passwords. I cannot wait to be 100% within the Apple eco-verse. Dashlane (and other PW managers) require integration with my browser, extra steps, and do not work with my Apple hardware biometric scanner (fingerprint or face ID).


-------
Trying to simplify my life...
October 03, 2024, 06:40 PM
V-Tail
quote:
Originally posted by 4MUL8R:

I am slowly converting from Dashlane, a "password manager" to Apple Passwords. I cannot wait to be 100% within the Apple eco-verse. Dashlane (and other PW managers) require integration with my browser, extra steps, and do not work with my Apple hardware biometric scanner (fingerprint or face ID).
1Password works seamlessly with Apple's Safari browser on my MacBook. It opens with fingerprint on the computer and iPad, and Face ID on the iPhone. It seems to be 100% integrated with the Apple eco-verse.



הרחפת שלי מלאה בצלופחים