[a / b / c / d / e / f / g / gif / h / hr / k / m / o / p / r / s / t / u / v / vg / vm / vmg / vr / vrpg / vst / w / wg] [i / ic] [r9k / s4s / vip] [cm / hm / lgbt / y] [3 / aco / adv / an / bant / biz / cgl / ck / co / diy / fa / fit / gd / hc / his / int / jp / lit / mlp / mu / n / news / out / po / pol / pw / qst / sci / soc / sp / tg / toy / trv / tv / vp / vt / wsg / wsr / x / xs] [Settings] [Search] [Mobile] [Home]
Board
Settings Mobile Home
/g/ - Technology


Thread archived.
You cannot reply anymore.


[Advertise on 4chan]


File: 1774939288529774.png (34 KB, 729x347)
34 KB
34 KB PNG
Can we PLEASE for the LOVE OF ALL THAT IS HOLY just STOP IT with the password complexity criteria already? We all know the highest risk is that the service itself leaks the password in a security breach, and then what use is the complexity?
>>
>Do NOT use spaces
That's some retarded coding right there
>>
>>108574036
for the end user that insists on "password", "123456", "qwertyuiop" etc.
>>
https://x.com/JCOviedo6/status/2042246885675549170/video/1

ahh shit
>>
>>108574036
Who cares? It takes only a couple more clicks for keepass to generate an autistically complex and long password compared to a basic one and one generated you can just copy paste it forever.
You are using a password manager in the year of our lord 2026, right?
>>
>>108574091
>Who cares?
People who actually researched it.
>Composition rules are commonly used in an attempt to increase the difficulty of guessing user-chosen passwords. However, research has shown that users respond in very predictable ways to the requirements imposed by composition rules [Policies]. For example, a user who might have chosen “password” as their password would be relatively likely to choose “Password1” if required to include an uppercase letter and a number or “Password1!” if a symbol is also required.
https://pages.nist.gov/800-63-4/sp800-63b.html#appA
>>
use a keepassxc and you wont have this issue
>>
>>108574091
what would really be nice if keepass had an option to guarantee that the generated password contained "at least one X" from different categories - numbers, special characters, etc.
obviously this would reduce the cryptographic strength or whatever but it would make it a lot easier to satisfy these ridiculous complexity requirements. i regularly encounter sign up forms that cannot be completed with a sufficiently random password just because it happens to not have a digit in it or something.
>>
>>108574084
>MMIWG2SLGBTQQIA+
kek

they keep adding all these new alphabets
>>
>>108574091
>You are using a password manager in the year of our lord 2026, right?
I am, but an offline one I can't access on my phone.
So I often have to type passwords in my phone and switching case/symbols on a phone is a pain.

So I just generate a pasword with only lower case letters and numbers, then add '1!" to the end to make Pajeet happy.
>>
>>108574187
why don't you just make it so you can access it on your phone then
>>
>>108574190
Security reasons
>>
>>108574197
what security reason says it's okay to have your database on your PC but not on your phone?
>>
>>108574203
I control the operating system on my PC (Arch Linux)
My phone runs Android which is backdoored.
>>
>>108574036
>We all know the highest risk is that the service itself leaks the password in a security breach
No you faggot it isn't
>But it is because I say so
Tell us you don't work in an org large enough to require LDAP without telling us
>Waaaahhh it HAWD to make and remember passphrase where are muh programmer socks
>>
>>108574223
why do you run a backdoored operating system on your phone?
>>
>>108574144
Let them get raped until they learn
>>
>>108574232
Because I can't use my banking app on a secure phone OS.
>>
>>108574223
>I believe scary things to feel elite
And you have no 2fa whatsoever right
>>
>>108574240
>Because it turns out rooting my phone makes it fucking useless for enterprise applications, why did I drink the Kool-Aid
>>
File: 2fa(ggot).jpg (58 KB, 750x1000)
58 KB
58 KB JPG
>>108574036
>ENTER THE EIGHT DIGIT 2FA CODE
>YOU HAVE TO VERIFY WITH A 2FA CODE
>I NEED THE 2FA CODE TO CONTINUE
>EMAIL OR PHONE NUMBER, PICK ONE
>SORRY, CAN'T DO ANYTHING WITHOUT THE 2FA CODE
>>
>>108574036
>Mommy it's my God given right to use my birthday or the word "pencil" as my password
It's also a service's right to bar retards from using it
>>
>>108574240
this nigga is afraid the CIA is going to get a copy of his encrypted keepass database, but logs into an app for his bank
>>
File: s-l1200.png (348 KB, 1200x1200)
348 KB
348 KB PNG
>>108574263
What codes
>>
>>108574036
>We all know the highest risk is that the service itself leaks the password
lol no
>>
>>108574036
why can't pajeets handle \s characters?
>>
File: smug.png (21 KB, 800x800)
21 KB
21 KB PNG
>>108574281
>What codes
>>
File: 1771911164915388.png (91 KB, 740x601)
91 KB
91 KB PNG
>>108574036
>>
>>108574036
is that cdbaby?
>>
>>108574367
i'd add another four words to that but yeah this is basically true
>>
>>108574329
One password for the entire device when you're adding new credentials
Go run to your soijak reaction folder to try to sound smug
>>
>>108574203
Someone taking your phone or losing your phone is far more likely than someone breaking into your house and stealing your PC
>>
>>108575367
is your phone not encrypted?
>>
My password system is this:

[word I use for every password] + [word that is someone what related to that specific website/service]
>>
>>108575390
so your gmail password is
password gmail
?
>>
>>108574237
it's just the normiecattle that is being tortured for basically no reason
advanced users also suffer from rules that slightly inconvenience them for no reason
nobody will learn anything from this



[Advertise on 4chan]

Delete Post: [File Only] Style:
[Disable Mobile View / Use Desktop Site]

[Enable Mobile View / Use Mobile Site]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.