Your password must be at least 10 characters long.
ERROR: INVALID PASSWORD ENTERED!!!
PASSWORD MUST NOT EXCEED 12 CHARACTERS!
Requiring specific characters reduces the number of permutations. The only thing that makes a password more secure is increasing the minimum length. As the OP suggests, enforcing special characters makes most people just put a special character at the end. What you have effectively done is make the last character so easy to guess that it might as well not exist.
My new job has us doing various security trainings every month and they also send out fake phishing emails. I initially ignored the emails prompting me to do the training because they require you to click a personalized link in the email to access the training. Eventually, my manager reached out and asked why I hadn’t done the training, so I explained, but finally clicked through to do it. That month’s training was about how a long passphrase is more secure than a list of character type requirements. Guess whose password requirements are a list of character type requirements?
Fun fact: As an anti-scam measure, if you type your password in a comment, Lemmy will automatically censor it for you.
Like this:
************
Cool, right?
How does mine look?
Hunter2
This is just a css trick. Your full password text is still there in the html.
I just see *'s.
Calm down, Satan.
The FBI training I’m forced to take at work suggests replacing characters in that manner. “Just use a $ instead of S!”
But back in like 2006 I brute forced a dump of 20 Windows passwords in that style on my old Dell single core machine in less than two seconds. Every passing year I’m still shocked people still think this is secure.
It’s also a gigantic red flag when sites say there’s a password limit
Bitch, my password is supposed to be hashed so even if I uploaded the LOTR trilogy extended edition in 4K, it should still come out the same length as any other SHA256 hash
I make my passwords complex phrases with spaces and punctuation included. e.g. “Correct, horse battery staple!”
(obligatory that’s not my password)
I appreciate the enthusiasm but my load balancer will get sad if I let you send more than 1500 bytes.
First round of hashing could be done client-side, and then send that to the server.
Would be cool to also add salt so that the hash couldn’t get re-used across services even with the same source password/file if somehow captured.Idea:
- Enter username
- Server sends salt to client
- Enter password or key file
- Client computes hash of the password or file with salt added (I have no idea how it’s used. If appended, some hashing functions could truncate the data, losing the salt. If prepended along with truncation, you just made the password even shorter. XOR?)
- Client sends hash to server
- Server hashes the hash same way as if it was password
- If it matches, you’re in
Basically, the hash is your password. Data can be whatever.
Most websites already use JavaScript, so why not.
Must be 8 to 14 characters 😡
alphanumeric characters only, and maybe an underscore if we’re feeling extra generous
Clearly you have undiscovered SHA256 collisions that you want to attack the website with.
correct horse battery staple
My last job was at AutoZone and our password requirements were stricter and had to be changed twice as often as my password on our secured computer when I was in the Navy.
You never know when them O’reily boys will try and hack you. You gotta be prepared!
In systems that accept whitespace, “Live, Laugh, Love” is considered a strong password.
With that being said, “In systems that accept whitespace, “Live, Laugh, Love” is considered a strong password.” is an even stronger password.
I love systems that accept “With that being said, “In systems that accept whitespace, “Live, Laugh, Love” is considered a strong password.” is an even stronger password.” as my password.
For those that have full Unicode support, including newline characters and a very high or nonexistent character limit, using:
For those that have full Unicode support, including newline characters and a very high or nonexistent character limit, using:
I love systems that accept “With that being said, “In systems that accept whitespace, “Live, Laugh, Love” is considered a strong password.” is an even stronger password.” as my password.
as your password is an even stronger password.
as your password is an even stronger password.
all fun and games until you find out it strips whitespace/newlines on save without telling you and you gotta go figure out why your passwords not working
The new recommendation is 30 character or more passphrases with some noise.
for real, why is it so hard to count entropy?
I guess it’s too chaotic.










