Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

mfcorey1

(11,001 posts)
Wed Aug 9, 2017, 06:03 AM Aug 2017

Creator of Password Rules Regrets His Advice

http://www.msn.com/en-us/money/technology/creator-of-password-rules-regrets-his-advice/ar-AApJ0ps?li=BBnb7Kz&ocid=mailsignout


Was it m@nk3yP@$$w01rd or m0nk3yp@ssw0!rd?

For 20 years, the standard advice for creating a "strong" password that is hard to crack has been to use a mix of letters, numbers and symbols.

It's so ingrained that when you go to create a new email account you'll frequently get praising or finger-wagging feedback from the computer on how well your secret code adheres to these guidelines.

And you're supposed to change it every 90 days.

Now, the man who laid down these widely followed rules says he got it all wrong.


"Much of what I did I now regret," Bill Burr, a 72-year-old retired former manager at the National Institute of Standards and Technology told the Wall Street Journal.

In 2003, the then-mid-level NIST manager was tasked with the job of setting rules for effective passwords. Without much to go on he sourced a whitepaper written in the 1980s. The rules his agency published ended up becoming the go-to guides for major institutions and large companies.

The result is that people create odd-looking passwords and then have to write them down, which is of course less secure than something you can memorize. Users also lean on common substitutions, like "zeroes" for the letter O, which a smart hacker could program their password cracker to look for. Or they pick one "base" password that they can memorize and only change a single number. That's also not as safe.

"It just drives people bananas and they don't pick good passwords no matter what you do," Burr said.
41 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Creator of Password Rules Regrets His Advice (Original Post) mfcorey1 Aug 2017 OP
Create a double password protected spreadsheet underpants Aug 2017 #1
I create nonsensical ones.. like... SoCalDem Aug 2017 #2
I use movie quotes volstork Aug 2017 #9
how do you remember the passwords to the double password protected spreadsheet. boston bean Aug 2017 #13
I use a set of 4 numbers in most of my pass words underpants Aug 2017 #14
What happens when you forget the password to your spreadsheet? Yavin4 Aug 2017 #23
Then you're screwed underpants Aug 2017 #24
Seems like it is more likely that your PW gets stolen from a company's database n2doc Aug 2017 #3
True. You would be surprised to know that one site, beginning with G keeps passwords in clearkey. TheBlackAdder Aug 2017 #26
Full sentences are the best way to roll Lee-Lee Aug 2017 #4
I can't remember the site but I had the same 8 character, 1 number and 6 spec characters TexasProgresive Aug 2017 #5
Yes. This is what I do too marybourg Aug 2017 #30
That's why I use hunter2 as my password. nt Xipe Totec Aug 2017 #6
Lol. MrsCoffee Aug 2017 #10
Kind of amusing rpannier Aug 2017 #7
XKCD on an easy system with great password strength Bernardo de La Paz Aug 2017 #8
XKCD always manages to hit exactly jimlup Aug 2017 #11
Of course, all of this is academic if the userid suspends after 10 invalid password attempts. TheBlackAdder Aug 2017 #28
Often it will suspend after 5 failed attempts and re-allow after 15 minutes. Bernardo de La Paz Aug 2017 #33
My son told me the secret. Baitball Blogger Aug 2017 #12
That's what I do. central scrutinizer Aug 2017 #35
Great idea. Baitball Blogger Aug 2017 #38
I did that on a Friday and couldn't remember it on Monday. Thor_MN Aug 2017 #40
Another great idea! Baitball Blogger Aug 2017 #41
Problem is the rules zipplewrath Aug 2017 #15
Yes - that is always a pain in the ass NewJeffCT Aug 2017 #17
I visited an insurance site that I haven't been to in years. CrispyQ Aug 2017 #20
Similar problem with the WaPo zipplewrath Aug 2017 #22
You can put them all into an encrypted file and memorize just that one encryption key. . . nt Bernardo de La Paz Aug 2017 #21
It's insane sometimes Proud Liberal Dem Aug 2017 #27
I use the plate # of my first car crazycatlady Aug 2017 #16
This is why I use a password manager mythology Aug 2017 #18
Yep. Only way to go. klook Aug 2017 #39
I have an easier time with nonsense passwords unique to that site. Phentex Aug 2017 #19
Kick ck4829 Aug 2017 #25
Some password annoyances: Tracer Aug 2017 #29
Take a picture of it central scrutinizer Aug 2017 #36
It's gotten to the point that I won't use anything (new) that requires a password. Coventina Aug 2017 #31
I've been using a similar system. Binkie The Clown Aug 2017 #32
I'm suspicious of any internet site that requires passwords, including this one. hunter Aug 2017 #34
I have combinations that mean something to me Awsi Dooger Aug 2017 #37

underpants

(182,829 posts)
1. Create a double password protected spreadsheet
Wed Aug 9, 2017, 06:21 AM
Aug 2017

You can have a list of current passwords as well as your history with a given log in.
Give the spreadsheet a good name and hide it in your home drive.

I have about 30 passwords I have to keep track off.

SoCalDem

(103,856 posts)
2. I create nonsensical ones.. like...
Wed Aug 9, 2017, 06:40 AM
Aug 2017

I avoid passwords near the caplock key...for obvious reasons..

favorite animal...a food....period or comma...number ...best friend's birth year..

this is not my password....


zebracookie.21954

boston bean

(36,221 posts)
13. how do you remember the passwords to the double password protected spreadsheet.
Wed Aug 9, 2017, 08:44 AM
Aug 2017

What if you can't and then you don't have record of any of your passwords.

underpants

(182,829 posts)
14. I use a set of 4 numbers in most of my pass words
Wed Aug 9, 2017, 09:04 AM
Aug 2017

And then do letters before and after. I tend to stick with the same special character as well as passwords tend to need changing at about the same time.

Those 4 numbers are my way into the spreadsheet and I have a second simple set off two for the second password to get into the spreadsheet.

Probably not the most secure system using the same core numbers but it works for me.

Yavin4

(35,442 posts)
23. What happens when you forget the password to your spreadsheet?
Wed Aug 9, 2017, 11:31 AM
Aug 2017

Or what happens when someone hacks into your spreadsheet?

n2doc

(47,953 posts)
3. Seems like it is more likely that your PW gets stolen from a company's database
Wed Aug 9, 2017, 06:54 AM
Aug 2017

with thousands of others, than someone deliberately trying to crack a specific one. (unless you are targeted by a 3 letter agency)

TheBlackAdder

(28,209 posts)
26. True. You would be surprised to know that one site, beginning with G keeps passwords in clearkey.
Wed Aug 9, 2017, 12:11 PM
Aug 2017

Not only that, their employees have access to view them.

 

Lee-Lee

(6,324 posts)
4. Full sentences are the best way to roll
Wed Aug 9, 2017, 06:58 AM
Aug 2017

Multiple words stuing together for an extra long one that is still easy to remember.

Something like:

45IsTheWorstPresidentEver!

You get numbers, letters and caps for systems tht demand it and an ultra long password compared to most that is still easy to remember.

The worst site I ever worked with was one US Government one that demanded your password by EXACTLY 8 characters, no more no less, with a number and a special character but only one of 6 allowable special characters. The literally narrowed the possibilities way down for any hackers by being so restrictive.

TexasProgresive

(12,157 posts)
5. I can't remember the site but I had the same 8 character, 1 number and 6 spec characters
Wed Aug 9, 2017, 07:22 AM
Aug 2017

I hated coming up with a PW for it.

marybourg

(12,633 posts)
30. Yes. This is what I do too
Wed Aug 9, 2017, 12:27 PM
Aug 2017

using a sentence with personal meaning to me alone, leaving out the vowels for brevity and incorporating an appropriate year or digit

rpannier

(24,330 posts)
7. Kind of amusing
Wed Aug 9, 2017, 07:41 AM
Aug 2017

I was watching the John Oliver - Snowden interview and they were talking about passwords
Snowden recommended using phrases you could remember and then threw out 'Margaret Thatcher is so SEXY' as an example
Jon Oliver stared and said something like "That's probably a good one because no one would ever use it."

Bernardo de La Paz

(49,007 posts)
33. Often it will suspend after 5 failed attempts and re-allow after 15 minutes.
Wed Aug 9, 2017, 01:10 PM
Aug 2017

Anything more draconian than that is an error in user interface, notwithstanding exceptional systems with exceptional requirements.

Baitball Blogger

(46,736 posts)
12. My son told me the secret.
Wed Aug 9, 2017, 08:42 AM
Aug 2017

Use a phrase that will stick in your mind and use the first letter of each word and allowable exclamation marks. I'm guessing though that the downside of that is that there will be a spike on this password:

hiipthsaINB45itWH!!!!!

How Is It Possible To Have Such an Incompetent Narcassitic Bastard 45 in the White House!!!!!

central scrutinizer

(11,652 posts)
35. That's what I do.
Wed Aug 9, 2017, 06:34 PM
Aug 2017

Some song lyric or Firesign Theatre line. Use the first letter of each word, throw in a couple of numeric characters and some other special character. I tend to use # since some foreign keyboards are very different. I couldn't check email in Costa Rica since my password used the $ sign.

I learned the first character trick from my sister in law who was a systems administrator. Her office changed passwords often. She would stick a cartoon on her door. Take the first letter of each word in the caption and voila. Her coworkers knew how to find the password if she was out.

 

Thor_MN

(11,843 posts)
40. I did that on a Friday and couldn't remember it on Monday.
Wed Aug 9, 2017, 10:37 PM
Aug 2017

The sysadmin was a friend and could get what I had set for a password. She told me and I still could not remember what phrase I had used to create that acronym.

Never change your password on a Friday.

Where I work now, there is a system account to be used in the development environment that is needed by all the programmers. They now set them as a random 30-45 character mess of lower case letters, upper case letters, numbers, and symbols. Then share it with 300 programmers....

zipplewrath

(16,646 posts)
15. Problem is the rules
Wed Aug 9, 2017, 09:13 AM
Aug 2017

I've come up with "strong" passwords that I can remember. The problem is that I can't necessarily remember what the rules for each site are. Some sites insist on characters that other sites won't accept. When I started, I had a nice 7 character password that could be constantly updated. Then they wanted 8. Some now insist on 12. Some have limited "special characters". Some insist on BOTH upper and lower case. I've given up. I have one "weak" password for sites I don't care if they get hacked. After that, I have to write them down in a small book I keep in the desk. Which of course is a problem if I'm on the road. Then I have to go through the whole "forgotten password" process. Which means I have to remember what email I gave them.

NewJeffCT

(56,828 posts)
17. Yes - that is always a pain in the ass
Wed Aug 9, 2017, 09:21 AM
Aug 2017

I used to have a small group of standard passwords that I would use. (standard to me for most sites, not standard in general) Then, when they started requiring symbols, I added a few standard symbols - but, some sites won't accept any symbols, while others require only certain ones or exclude certain ones.

CrispyQ

(36,478 posts)
20. I visited an insurance site that I haven't been to in years.
Wed Aug 9, 2017, 10:29 AM
Aug 2017

I had my login & password - signed in no problem. Then it told me, "You're password is too old. We've reset & sent the new password it to your email," & it logged me off. Guess what? It's an old email account that I no longer have. I tried to create a new account, it said that policy number already has an account. I have no way to get into my account now because I have no way to update my email.

I inherited an authenticated app from a programmer & he didn't code anyway for the users to reset their password & get a new one. The first day I had three calls from employees who were locked out. I couldn't believe when I discovered what he'd done! Or rather, hadn't done.

zipplewrath

(16,646 posts)
22. Similar problem with the WaPo
Wed Aug 9, 2017, 11:29 AM
Aug 2017

I signed up for them in the '90s. Last time I was there they wanted me to update my information. So I did. It immediately sent an email to the original address to confirm the "changes" (info they never had before). Problem is, the original address doesn't even exist anymore.

Proud Liberal Dem

(24,414 posts)
27. It's insane sometimes
Wed Aug 9, 2017, 12:13 PM
Aug 2017

I'm glad that I have a password manager (Dashlane/Last Pass) because I would literally be screwed by the amount of logins that I have to keep track of otherwise.

crazycatlady

(4,492 posts)
16. I use the plate # of my first car
Wed Aug 9, 2017, 09:19 AM
Aug 2017

I remember when passwords used to be 6 characters (which the plate # was). I since added the state in there to make it longer.

It was my current car when I set the password but it died 10 years ago.

 

mythology

(9,527 posts)
18. This is why I use a password manager
Wed Aug 9, 2017, 09:52 AM
Aug 2017

It means I can have good long random passwords and not have to remember them myself.

klook

(12,157 posts)
39. Yep. Only way to go.
Wed Aug 9, 2017, 10:03 PM
Aug 2017

I use 1Password from AgileBits for Mac and iOS, and some free app for a work Android phone.

There are only a couple of passwords I have to key in:
* the master password for 1Password, which uses a formula that makes sense to me but would be almost impossible for any human or computer to figure out
* a couple for work systems (recorded in 1Password), where I use a) the initials of a long quote I know well but that most people wouldn't, with a little punctuation and capitalization mixed in; and b) an idiosyncratic combination of letters, numbers, and punctuation that I know well by muscle memory

1Password is great, because it not only stores tons of passwords and secure notes, but it will fill in passwords for me using only a 2-key combination when I'm logged in. Huge time saver and very convenient.

It also generates passwords upon request, using various formulas. One of my favorite is the one with words separated by punctuation, for example: templar-lichen-jaywalk-chancery (totally random example that I don't actually use). I'll take one like that and substitute numbers or symbols for a few of the characters, plus some punctuation and capitalization anomalies, plus a couple of symbols. Doesn't matter, really, since 1Password will remember it for me in an encrypted database no matter wacko it is.

I would never rely on my brain to remember the hundreds of passwords (and usernames, disposable email addresses, etc.) I've created.

Phentex

(16,334 posts)
19. I have an easier time with nonsense passwords unique to that site.
Wed Aug 9, 2017, 09:54 AM
Aug 2017

For some reason, I can remember a string of random letters/numbers/symbols easier than I can remember a phrase or word combination. I never use the same password or combo on any site. The times I get confused are for oddball sites like USPS that I rarely use. My library login is my card number and I can remember all 14 digits without looking it up.

The same is true for PIN numbers.


Meanwhile, I can't remember what I ate for breakfast or what's on my to-do list...

Tracer

(2,769 posts)
29. Some password annoyances:
Wed Aug 9, 2017, 12:22 PM
Aug 2017

The sites that reject your password because someone else is using it. Gotta think up a new one.

The sites that reject your log-in TODAY, but accepted it YESTERDAY ---- causing me to ask for a new password. (I'm looking at you Boston Globe).

I have 2 sheets of paper covered with current and former passwords. I'll be outta luck if I lose it!

Binkie The Clown

(7,911 posts)
32. I've been using a similar system.
Wed Aug 9, 2017, 12:57 PM
Aug 2017

I pick three random, unrelated words, and within those word I make the letters at certain fixed positions upper case. Those positions are the same for all my passwords. So let's say I always make the last letter of the first word and the second to last letter in the last word uppercase. Then "blue"+"swelter"+"caramel" would become "bluEswektercaramEl". The scattered uppercase letters makes a dictionary search impractical because the number of possible upper/lower case combinations goes up with the factorial of the password length, and that's more nanoseconds than the age of the universe since the big bang.

hunter

(38,317 posts)
34. I'm suspicious of any internet site that requires passwords, including this one.
Wed Aug 9, 2017, 02:36 PM
Aug 2017

I generate my own passwords using fragments of the incinerated bones of my enemies. It's a process similar to the rolling dice in Yahtzee. I reject the Yahtzees. Given enough time this makes me vulnerable.



 

Awsi Dooger

(14,565 posts)
37. I have combinations that mean something to me
Wed Aug 9, 2017, 06:52 PM
Aug 2017

Rarely have any problem remembering them, or which ones belongs to each site.

Some of them are obscure sports records or stats from 30 or 40 years ago combined with words or phrases that are significant to me but seldom used.

The only problem is when I'm limited. My credit union somehow still only allows 8 characters. They have some other safeguards built in but those shorties are the only ones I'm somewhat worried about.

The long ones flow from memory. I actually enjoy typing them in because they are so bizarre looking if you don't know what the heck it stands for.

Latest Discussions»General Discussion»Creator of Password Rules...