Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> I've had my auto-generated, 20-char digit/char/symbol PW from keepass get rejected for such things.

Huge pet peeve of mine. Really? "(uJgP6h9=8Uc6x?}#B6Q" isn't enough for you?



> Really? "(uJgP6h9=8Uc6x?}#B6Q" isn't enough for you?

Not after you've posted it on HN. That's only half joking...the biggest vulnerability in any password system is the humans involved. Security advisors should design around the natural behavior of their users, not try to force users into acting unnaturally. Otherwise, users will figure out how to introduce vulnerabilities that get around the constraints imposed upon them (the oft-cited writing passwords down).


Memo: ATTN All Employees

The password "(uJgP6h9=8Uc6x?}#B6Q" (no quotation marks) has been scientifically determined to be the most complex password. Please make sure to change every password to this new password within 24 hours.

Signed, The Mgt.


Obviously not, there is not e that could be replaced with a 3.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: