Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The fun part is that password complexity makes this problem worse, not better.

People use the same user/pass combo for every site they visit, except when one of them forces them to use a complicated password that they can't remember. So they send themselves an email with the site name, username and password so that they can find it next time they need to log into their bank.

So once your registry cleaning website has their email password, you also have a nice list of all their strong passwords too.

Adding to the irony, most people know that they need a different password for their bank, so if you just let them pick one without forcing complexity, they'll choose something they can remember, and their bank account will be safe.



But letting them pick a password without forced complexity makes it significantly easier to crack their password using one of the various, comprehensive, easy to find and download wordlists or dictionaries.


In the real world though, passwords aren't cracked nearly as often as they're read off a post-it note stuck to somebody's monitor.

Loosen complexity and you can eliminate that post-it. That's a huge overall win.

Complexity in itself isn't actually that bad. It's arbitrary complexity that spawns all those post-its. You can come up with a strong password that you and only you can remember, but it's useless if your bank rejects it due to its own silly complexity policy. There are sites out there that I regularly fail to log in with using my standard "strong" passwords, and it's not until I make it all the way through the Reset Password process to where it tells me its complexity requirement that I'm reminded which password I must have used last time I went through the process.

The only real solution is to let people use the word "password" if they really want. It's still orders of magnitude safer than having them keep a file/email/post-it full of plain text passwords sitting around in plain view.


Fully agree with the first post-it point, but I disagree with:

> The only real solution is to let people use the word "password" if they really want. It's still orders of magnitude safer than having them keep a file/email/post-it full of plain text passwords sitting around in plain view.

If I have "password" as password for my work webmail/remote login, it can be broken by any yokel on the internet with five minutes free time. If I have "ge.9u30!ey0" written on a post-it note on my desk, it can only be "cracked" people with physical access to my office.

Also note that people who have physical access to my office already have security privileges similar to mine own, mitigating the actual risk - they can't do much more damage with my password than they could without. And if they wanted my private stuff, they could just as well nab my harddisk.

Not that I'm justifying passwords on post-its in any means whatsoever, by the way. :-)


I believe you're right. But do you have any empirical evidence to support this claim?


If you have a good bank, they should be limiting it to y wrong tries every x minutes, and have good fraud detection mechanisms in place. So the viability of brute forcing bank passwords should be rather low. So the risk looks rather minimal compared to the large scale exploitation that is possible with the other method.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: