this post was submitted on 27 Jul 2023
1471 points (98.2% liked)

Memes

45661 readers
1790 users here now

Rules:

  1. Be civil and nice.
  2. Try not to excessively repost, as a rule of thumb, wait at least 2 months to do it if you have to.

founded 5 years ago
MODERATORS
 
you are viewing a single comment's thread
view the rest of the comments
[–] FlexibleToast@lemmy.world 47 points 1 year ago (7 children)

Who still isn't using a password manager?

[–] jetsetdorito@lemmy.world 57 points 1 year ago (1 children)

The most infuriating part is when this happens while using a password from a password manager

[–] TheGoldenGod@lemmy.world 15 points 1 year ago (1 children)

The fact this happens is infuriating. 😣

[–] pulverizedcoccyx@lemmy.ca 5 points 1 year ago (1 children)

Then you finally do the password change, go to login and now the new password doesn't work because you copied it to clipboard and overwrote it somehow in that small time frame goddamn shit! I always win+r and put it there until I know everything is all good.

[–] sockmedic@lemmy.world 3 points 1 year ago (1 children)

Maybe use the clipboard history on Windows? (Win+V)

[–] codapine@lemm.ee 5 points 1 year ago

Coming from a Linux background and being forced to use windows 10/11 at work, this was a game changer for me when i accidentally mis-keyed this shortcut and turned on the history feature. Now I use it literally dozens or hundreds of times each day.

Task failed successfully!

[–] Thassodar@lemm.ee 21 points 1 year ago (3 children)

What if I were to tell you my password manager password is the most vulnerable of all?

Nobody would guess it's hunter2.

[–] criticon@lemmy.ca 15 points 1 year ago (1 children)

I only see ******* when you type hunter2

[–] Thassodar@lemm.ee 5 points 1 year ago
[–] jetsetdorito@lemmy.world 12 points 1 year ago (1 children)

You should really upgrade to hunter3

[–] Thassodar@lemm.ee 8 points 1 year ago

But how did you see it? I used the spoiler tag

/s

[–] circuitfarmer@lemmy.sdf.org 5 points 1 year ago (2 children)

Mine is bigboipassword123. Can't dictionary attack it cuz boi isn't in the dictionary.

[–] TimeSquirrel@kbin.social 1 points 1 year ago

Who says they won't be including Urban Dictionary in their attack?

[–] totallynotarobot@lemmy.world 7 points 1 year ago (2 children)

I promise you that does not help.

I suspect a large number of these incidents are due to the password field in the login page allowing fewer characters than the field in the sign up page, so the password gets truncated. A couple of help desk meat shields have confirmed that for me, but mostly I think this because it seems to fix itself if I use a shorter password.

How short, you ask? Who tf knows! They sure as shit won't tell you! Just spend the next 20 minutes trying shit til it works, because you have nothing better to do with your time!

[–] codapine@lemm.ee 6 points 1 year ago (1 children)

My company doesn't tell you what the AD policy is for changing your domain logon password but windows will just tell you that it doesn't meet the policy. What IS the password policy you ask?

Well it's uh... 🤷‍♂️

Try again!

[–] totallynotarobot@lemmy.world 4 points 1 year ago (1 children)

I am annoyed on your behalf.

I've had goons tell me they can't tell me the character max because of "security"

[–] codapine@lemm.ee 2 points 1 year ago (1 children)

Ah, of course! Security through obscurity.

[–] EtherealZucchini@lemmy.world 2 points 1 year ago (1 children)

Yeah I’ve noticed this a few times as well. It’s pretty bad.

[–] totallynotarobot@lemmy.world 3 points 1 year ago

Thank you for validating my self-indulgent rant :)

[–] pulverizedcoccyx@lemmy.ca 5 points 1 year ago (2 children)

My parents. All written down on paper in handy notebooks for anyone that breaks in. Two entire lives and everything in them just there for the taking.

[–] abraxas@lemmy.ml 4 points 1 year ago* (last edited 1 year ago)

If I recall, a few (most) security experts now support written-on-paper passwords. Why? Because it is the solution for users who would otherwise commit far a more egregious security faux pas otherwise.

In most circumstances, it is easier to keep the notebook secure than your wallet, your car, etc. And let's be honest, the list of suspects are REALLY short if someone breaks into your house, opens the third drawer, grabs the notebook and runs. And if it's more than that and somebody ransacks your entire house, I guarantee having to change your passwords is the least of your headaches.

Ultimately, physical compromise is the lowest possible security risk for most people throughout their lives. Yes, it happens. Yes, it sucks. But having your bank password out in the wild with nobody realizing it is possibly far more dangerous.

[–] Gormadt@lemmy.blahaj.zone 2 points 1 year ago (1 children)

My grandma does this, but they're in one of the many Bibles she has in her home.

[–] sawdustprophet@midwest.social 2 points 1 year ago

My grandma does this, but they're in one of the many Bibles she has in her home.

"They stamped it, didn't they? Those damn Gideons."

[–] Psythik@lemm.ee 3 points 1 year ago (1 children)

I do use a password manager but this shit still happens. Does anyone know why? Something to do with a "password hash", I think...

[–] Agent641@lemmy.world 1 points 1 year ago* (last edited 1 year ago)

They are just gaslighting you. Its a global conspiracy in tech industry

[–] SamboT@lemm.ee 3 points 1 year ago (1 children)

1 week later: EZ Pass has majority of user passwords compromised, giving hackers access to bank records of 8 million Americans.

[–] FlexibleToast@lemmy.world 3 points 1 year ago (1 children)

That's even more reason to use a password manager. You're far more likely to have unique passwords per site. If one gets compromised, others don't.

[–] SamboT@lemm.ee 3 points 1 year ago (2 children)

Idk who is safe to use for password mgmt. I haven't seen data leaks for my banking institutions who probably have enforced regulations for IT security. Are there standards in place for password manager products? What brands are reputable?

[–] FlexibleToast@lemmy.world 1 points 1 year ago

Yourself. I use Vaultwarden on a Raspberry Pi. Lots of people use something like KeePass and sync it with Dropbox or something similar. As far as someone else hosting it, Bitwarden seems like the go to (and is the project that Vaultwarden is based on).

[–] codapine@lemm.ee 2 points 1 year ago

You must be using double-strength ROT13 encryption.