← Back to context

Comment by n0rdy

8 hours ago

Unfortunately, the humans' laziness (or lack of long-term thinking) was, is and will be a bottleneck.

If we technically restrict the minimum length to, let's say, 12 chars, the default passwords will be smth like `123456789012`. If we add the requirement to have 1 letter, at least, the passwords will be `12345678901a`. If we require a special character, we'll get smth like `1234567890a!`.

I believe the issue is not technical, and it's not about the one particular guy. It is about accountability and understanding the impact and responsibility of the "I don't care"/"whatever"/"ship fast" mindsets.

We need a proper social agreement for that, as this goes far beyond the passwords, especially these days when the quantity and speed are valued over quality.

There was a time when you would get a truly random password sent, every X months.

  • Sorry, I might be too young to remember those times. Can you tell me more, please? I'm genuinely curious.

    Because from the sound of that, it feels that it would patch the `123456` problem, but opens up a new vulnerability - the password is known / being sent through / printed, so it can be leaked from that source.

    • It was just that. And email with the new password. Hard to remember at first but then, somehow, I could type it from memory. Not sure how they got rid of the emails after they sent them but there are ways. It can be leaked from the source, true, but people with better technical skills were handling that source. So I guess overall it was better. The big insight might be that you can't evaluate the security of a system only from the technical aspect. You have to take into consideration also the human aspect. And that's a very weak point. Even Communism failed because they didn't take into consideration the human aspect (people don't want to work more if they get what everybody else gets anyway).

How about making the passords longer but easier to memorize? (no digit / letter / special character requirement)

https://xkcd.com/936

  • That would work from the technical point of view, I do agree.

    On the other hand, how would we make "lazy" people use those? And ensure that won't reuse the same password on some vibe coded forum that will store them in the plain text and get hacked in a few weeks =)

    That's why I mentioned that mindset shift as the prerequisite.