Author Topic: How Complex Does Your Password Have To Be?  (Read 6928 times)

Offline stooges44

  • Dansdeals Lifetime Presidential Platinum Elite
  • *********
  • Join Date: Jan 2017
  • Posts: 6567
  • Total likes: 2765
  • DansDeals.com Hat Tips 269
    • View Profile
How Complex Does Your Password Have To Be?
« on: October 26, 2017, 09:14:11 AM »
One of my hosting sites just went through an upgrade and now they are forcing a reset on all FTP passwords and these are the new requirements:
  • 6 to 20 characters
  • Must start with a letter
  • Must contain at least one uppercase letter
  • Must contain at least one lowercase letter
  • Must contain at least one digit or one of the following non-alphabetic characters: !, $, *, %, -, #, @, ^, +
    e.g. My-Pa55word
  • Not allowed to contain parts of the username that exceed two consecutive characters.
Most of these are the new norm but that last one threw me off and now I have to make something that I certainly wont remember and I'll have to lookup each time

 :o
If it's not free shipping it's not worth it.

Offline Boruch999

  • Dansdeals Lifetime Platinum Elite
  • *******
  • Join Date: Jun 2014
  • Posts: 2164
  • Total likes: 186
  • DansDeals.com Hat Tips 0
    • View Profile
Re: How Complex Does Your Password Have To Be?
« Reply #1 on: October 26, 2017, 09:19:57 AM »
One of my hosting sites just went through an upgrade and now they are forcing a reset on all FTP passwords and these are the new requirements:
  • 6 to 20 characters
  • Must start with a letter
  • Must contain at least one uppercase letter
  • Must contain at least one lowercase letter
  • Must contain at least one digit or one of the following non-alphabetic characters: !, $, *, %, -, #, @, ^, +
    e.g. My-Pa55word
  • Not allowed to contain parts of the username that exceed two consecutive characters.
Most of these are the new norm but that last one threw me off and now I have to make something that I certainly wont remember and I'll have to lookup each time

 :o

As computers get more powerful,  passwords must get more complex to avoid being crackable by brute force trial and error programs.  It is not so hard, if you put your mind to it, to remember a long password.  What I do from time to time is spend a minute composing a new password.  Here's an example of something I might use : [3vvA45f70sak#42.  I write it down on a paper I will carry with me for a few days.  For the first 10 or 20 times I need the pw, I'll need to look it up.  After that, it's memorized.


Offline ChaimMoskowitz

  • Dansdeals Lifetime Presidential Platinum Elite
  • *********
  • Join Date: Jun 2014
  • Posts: 7232
  • Total likes: 1097
  • DansDeals.com Hat Tips 1
  • Gender: Female
    • View Profile
Re: How Complex Does Your Password Have To Be?
« Reply #2 on: October 26, 2017, 09:29:51 AM »
Use a password manager and generate as complex as allowed. Every login you use should be different.
I just found a new supply of forks!

Offline aygart

  • Dansdeals Lifetime 10K Presidential Platinum Elite
  • *******
  • Join Date: May 2008
  • Posts: 18423
  • Total likes: 14594
  • DansDeals.com Hat Tips 14
    • View Profile
    • Lower Watt Energy Brokers
  • Programs: www.lowerwatt.com
Re: How Complex Does Your Password Have To Be?
« Reply #3 on: October 26, 2017, 10:46:10 AM »
I often use various mixes of Hebrew words and gematria. Sometimes is tranliterate and sometimes use the keys of the Hebrew keyboard to type English for the corresponding gibberish.
Feelings don't care about your facts

Offline yuneeq

  • Dansdeals Lifetime Presidential Platinum Elite
  • *********
  • Join Date: Jan 2013
  • Posts: 8880
  • Total likes: 4047
  • DansDeals.com Hat Tips 10
  • Gender: Male
    • View Profile
  • Location: NJ
Re: How Complex Does Your Password Have To Be?
« Reply #4 on: October 26, 2017, 11:00:30 AM »
    • Must start with a letter
    • Not allowed to contain parts of the username that exceed two consecutive characters.
    Most of these are the new norm but that last one threw me off and now I have to make something that I certainly wont remember and I'll have to lookup each time

     :o

    Judging by how stupid some of these are, I can almost guarantee the site stores your password in plaintext.

    Just use lastpass and never look back.
    Visibly Jewish

    Offline whYME

    • Dansdeals Presidential Platinum Elite
    • ********
    • Join Date: May 2008
    • Posts: 3370
    • Total likes: 1241
    • DansDeals.com Hat Tips 3
    • Gender: Male
      • View Profile
    Re: How Complex Does Your Password Have To Be?
    « Reply #5 on: October 26, 2017, 11:08:05 AM »
    One of my hosting sites just went through an upgrade and now they are forcing a reset on all FTP passwords and these are the new requirements:
    • 6 to 20 characters
    • Must start with a letter
    • Must contain at least one uppercase letter
    • Must contain at least one lowercase letter
    • Must contain at least one digit or one of the following non-alphabetic characters: !, $, *, %, -, #, @, ^, +
      e.g. My-Pa55word
    • Not allowed to contain parts of the username that exceed two consecutive characters.
    Most of these are the new norm but that last one threw me off and now I have to make something that I certainly wont remember and I'll have to lookup each time

     :o
    I just wish most sites would tell you what the password requirements are in their "incorrect password" error.

    Offline ckmk47

    • Dansdeals Lifetime Presidential Platinum Elite
    • *********
    • Join Date: Aug 2012
    • Posts: 8031
    • Total likes: 1065
    • DansDeals.com Hat Tips 3
    • Gender: Female
      • View Profile
    • Location: brooklyn
    Re: How Complex Does Your Password Have To Be?
    « Reply #6 on: October 26, 2017, 11:32:44 AM »
    I make up a sentence and use the first letter of each word as the password.
    My Amazon password might be:  IhA4totw
    = I hate Amazon 4 taking over the world.    It has a natural capital and number and is unique for Amazon.


    My Chase might be:  chmb48Ya           chase has my back for 8 years already

    My favorite cause: cssy.org

    Offline 1234567

    • Dansdeals Bronze Elite
    • *
    • Join Date: Jul 2012
    • Posts: 34
    • Total likes: 7
    • DansDeals.com Hat Tips 1
      • View Profile

    Offline yitrap

    • Dansdeals Presidential Platinum Elite
    • ********
    • Join Date: Apr 2014
    • Posts: 3315
    • Total likes: 56
    • DansDeals.com Hat Tips 1
    • Gender: Male
      • View Profile
    Re: How Complex Does Your Password Have To Be?
    « Reply #8 on: October 26, 2017, 01:15:46 PM »
    There was an article saying that most people just end up putting in 1! At the end to make it a valid password... Making it a lot easier to crack

    Offline ChaimMoskowitz

    • Dansdeals Lifetime Presidential Platinum Elite
    • *********
    • Join Date: Jun 2014
    • Posts: 7232
    • Total likes: 1097
    • DansDeals.com Hat Tips 1
    • Gender: Female
      • View Profile
    Re: How Complex Does Your Password Have To Be?
    « Reply #9 on: October 26, 2017, 01:17:35 PM »
    There was an article saying that most people just end up putting in 1! At the end to make it a valid password... Making it a lot easier to crack
    That's why I use "2".
    I just found a new supply of forks!

    Offline skyguy918

    • Dansdeals Presidential Platinum Elite
    • ********
    • Join Date: Mar 2011
    • Posts: 4077
    • Total likes: 835
    • DansDeals.com Hat Tips 1
    • Gender: Male
      • View Profile
    • Location: Queens, NY
    Re: How Complex Does Your Password Have To Be?
    « Reply #10 on: October 26, 2017, 01:22:27 PM »
    There was an article saying that most people just end up putting in 1! At the end to make it a valid password... Making it a lot easier to crack
    Not really. If your actual password is hard to crack (but doesn't fit the rules), adding 1! doesn't make it easier to crack. Actually using all 20 characters (the max in OP's example) makes it much harder than most of the other tricks. Make up an easy to remember phrase that's 18 characters long, and then add 1! - it actually says digit or other mark, so you can really just add the 1.

    Offline hachover

    • Dansdeals Platinum Elite + Lifetime Silver Elite
    • *****
    • Join Date: Feb 2016
    • Posts: 517
    • Total likes: 102
    • DansDeals.com Hat Tips 0
    • Gender: Male
      • View Profile
    • Location: Sector ZZ9 Plural Z Alpha
    Re: How Complex Does Your Password Have To Be?
    « Reply #11 on: October 26, 2017, 01:34:25 PM »
    The US government is trying to come up with replacements for SSN and public/private key is one idea that's been presented as a substitute. The technology to store and secure the keys is getting to be very cheap and accessible, so it's not unreasonable to propose giving everyone a USB drive that's secured by biometrics instead of a social security card. This would be great for password security too (until quantum computers are invented)
    I'm an optimist; but only because life isn't going to give me any other good choices.

    Offline ADG

    • Dansdeals Lifetime Platinum Elite
    • *******
    • Join Date: Apr 2015
    • Posts: 1469
    • Total likes: 79
    • DansDeals.com Hat Tips 0
      • View Profile
    • Location: BK
    Re: How Complex Does Your Password Have To Be?
    « Reply #12 on: October 26, 2017, 02:31:36 PM »
    The US government is trying to come up with replacements for SSN and public/private key is one idea that's been presented as a substitute. The technology to store and secure the keys is getting to be very cheap and accessible, so it's not unreasonable to propose giving everyone a USB drive that's secured by biometrics instead of a social security card. This would be great for password security too (until quantum computers are invented)

    They already are!

    Offline yelped

    • Dansdeals Lifetime 10K Presidential Platinum Elite
    • *******
    • Join Date: Mar 2015
    • Posts: 10969
    • Total likes: 3984
    • DansDeals.com Hat Tips 43
      • View Profile
    Re: How Complex Does Your Password Have To Be?
    « Reply #13 on: October 26, 2017, 02:38:17 PM »
    I make up a sentence and use the first letter of each word as the password.
    My Amazon password might be:  IhA4totw
    = I hate Amazon 4 taking over the world.    It has a natural capital and number and is unique for Amazon.


    My Chase might be:  chmb48Ya           chase has my back for 8 years already
    This is the right way to do it. Great random gibberish, yet you can remember it due to it being based on a passphrase.

    Offline skyguy918

    • Dansdeals Presidential Platinum Elite
    • ********
    • Join Date: Mar 2011
    • Posts: 4077
    • Total likes: 835
    • DansDeals.com Hat Tips 1
    • Gender: Male
      • View Profile
    • Location: Queens, NY
    Re: How Complex Does Your Password Have To Be?
    « Reply #14 on: October 26, 2017, 02:41:08 PM »
    This is the right way to do it. Great random gibberish, yet you can remember it due to it being based on a passphrase.
    It's only 8 characters. It's still much easier to crack than almost anything you do that uses the max characters allowed.

    Offline aygart

    • Dansdeals Lifetime 10K Presidential Platinum Elite
    • *******
    • Join Date: May 2008
    • Posts: 18423
    • Total likes: 14594
    • DansDeals.com Hat Tips 14
      • View Profile
      • Lower Watt Energy Brokers
    • Programs: www.lowerwatt.com
    Re: How Complex Does Your Password Have To Be?
    « Reply #15 on: October 26, 2017, 02:44:55 PM »
    I would guess that right now a short password would be the safest since no one has it.
    Feelings don't care about your facts

    Offline Boruch999

    • Dansdeals Lifetime Platinum Elite
    • *******
    • Join Date: Jun 2014
    • Posts: 2164
    • Total likes: 186
    • DansDeals.com Hat Tips 0
      • View Profile
    Re: How Complex Does Your Password Have To Be?
    « Reply #16 on: October 26, 2017, 04:19:32 PM »
    I would guess that right now a short password would be the safest since no one has it.

    I believe not.  I don't precisely know how passwords/encryption work but those who work on cracking them do not sit and manually enter guesses.  They write programs that start at 0 and work their way up.  Short passwords will get cracked before long ones.

    Offline Boruch999

    • Dansdeals Lifetime Platinum Elite
    • *******
    • Join Date: Jun 2014
    • Posts: 2164
    • Total likes: 186
    • DansDeals.com Hat Tips 0
      • View Profile
    Re: How Complex Does Your Password Have To Be?
    « Reply #17 on: October 26, 2017, 04:28:50 PM »
    I believe not.  I don't precisely know how passwords/encryption work but those who work on cracking them do not sit and manually enter guesses.  They write programs that start at 0 and work their way up.  Short passwords will get cracked before long ones.

    https://www.technologyreview.com/s/542576/youve-been-misled-about-what-makes-a-good-password/

    According to this, my above explanation is outdated.  Never-the-less, they don't recommend short.

    Offline hachover

    • Dansdeals Platinum Elite + Lifetime Silver Elite
    • *****
    • Join Date: Feb 2016
    • Posts: 517
    • Total likes: 102
    • DansDeals.com Hat Tips 0
    • Gender: Male
      • View Profile
    • Location: Sector ZZ9 Plural Z Alpha
    Re: How Complex Does Your Password Have To Be?
    « Reply #18 on: October 26, 2017, 04:43:46 PM »
    They already are!

    Who is already doing what?
    I'm an optimist; but only because life isn't going to give me any other good choices.

    Offline aygart

    • Dansdeals Lifetime 10K Presidential Platinum Elite
    • *******
    • Join Date: May 2008
    • Posts: 18423
    • Total likes: 14594
    • DansDeals.com Hat Tips 14
      • View Profile
      • Lower Watt Energy Brokers
    • Programs: www.lowerwatt.com
    Re: How Complex Does Your Password Have To Be?
    « Reply #19 on: October 26, 2017, 04:48:07 PM »
    Just got a Firefox notification that LastPass is not compatible with the current version.
    Feelings don't care about your facts