Spyke

Thanks for mentioning it. I never finished it though

7
mrsemireply
lemmy.world

I just recently had to make a password for some website.

The requirements were to use at least one capital letter, at least one number, and EXACTLY ONE of a short list of special characters in your password. It also could be no longer than 10 characters.

Major wtf moment.

23
mangaskahnreply
lemmy.world

It was a financial site wasn't it. They're the worst for not updating security guidelines.

5

There are various reasons I hate the banks I use. One of the top reason is this ancient obsolete password rule.

The biggest reason to hate my banks is they're forcing to use their android app and policing how I can use my phone by refusing to run if I have accessibility service on, and developers options enabled.

I just keep updating my reviews as they are anti disabled people[1].

[1]Please correct me on the proper term because I'm ESL and I forgot.

7

FixUrSh1t!

When the plaintext-stored password inevitably get leaked at some point, I hope whoever actually reads through that list gets a laugh out of it.

2

That's means they're storing your password directly in a database somewhere. Not even hashing it. Super lazy coding.

1
cronreply
feddit.org

I don't use KeePass anymore, but from this screenshot and the documentation I believe that it does not generate passphrases as defined by this xkcd comic.

3
sh.itjust.works

I've configured this for KeePassXC iirc, but you're right, the default config does not generate XKCD passwords. Just saying it's not impossible.

4

Bitwarden does this out of the box.

Just adding if someone reading wants to use passphrase generation that's built in.

3
  • cannot be one of the last 10 passwords you used
  • cannot be any password you have used in the last 15 years
  • must contain all of the following characters 𐌐𐌔ቹ𐌕ፕ𐌀 𐌔ፕክ𐌄
  • can only consist of lowercase letters
  • must contain at least nine numbers that sum to be no more than 11 and no less than 9
  • numbers cannot repeat
  • must contain one uppercase letter
  • must end with '.jpg'
  • first four characters hex values must be the same summed value as the last nine characters
  • signal each character with the tone of a virgin bell towards the heavens
15

My favorite was a biweekly password change, on the payroll portal that was also biweekly.

3
cronreply
feddit.org

Thanks for pointing out the typo. I made you the co-author to thank you for your significant contribution.

7

You reached the end

Password Policies | Spyke