How long should a password be?

https://bitwarden.com/blog/how-long-should-my-password-be/

36 points · 19 comments · view on lemmy.world

19 Comments

noride@lemm.ee · 19 pts · 1y (2 replies)

correct horse battery staple

Alk@sh.itjust.works · 7 pts · 1y (1 reply)

How did you steal my password??

UndulyUnruly@lemmy.world · 4 pts · 1y

Witchcraft! Get them!

fxomt@lemm.ee · 6 pts · 1y (10 replies)
[ removed ]
einkorn@feddit.org · 6 pts · 1y (9 replies)

And then there are those services that let you enter arbitrarily long passwords in the registration form but only save something like 16 characters.

mike_wooskey@lemmy.thewooskeys.com · 5 pts · 1y

I hate this situation. What horrible design choices in their code!

fxomt@lemm.ee · 3 pts · 1y (7 replies)
[ removed ]
amorpheus@lemmy.world · 2 pts · 1y (5 replies)

How would you know?

fxomt@lemm.ee · 1 pts · 1y (4 replies)
[ removed ]
amorpheus@lemmy.world · 2 pts · 1y (3 replies)

No, that's the point, you'd never know whether they only validate a subset of the password. Only by testing different variations you would know that less than the whole string still works.

fxomt@lemm.ee · 1 pts · 1y (2 replies)
[ removed ]
amorpheus@lemmy.world · 2 pts · 1y

I wouldn't speculate on how common it is but limiting passwords seems to happen more than it should. So maybe many are taking the stealth approach.

One site I know where this happens (at least I experienced it some years ago) was Blizzard. Found out by sheer luck after I clearly fumbled the end of my password and was logged in regardless.

einkorn@feddit.org · 2 pts · 1y

Amen

nutbutter@discuss.tchncs.de · 5 pts · 1y

Toes@ani.social · 5 pts · 1y (8 replies)

People gotta stop doing QkFEcEEkJFcwUkQ=

aQuickBrownFoxJumpedOverALazyDog$nuggle9 is far easier to remember and secure.

Deebster@infosec.pub · 12 pts · 1y (1 reply)

The article is from Bitwarden, which is a password manager - using them you don't need to remember individual passwords (or type them, normally).

Bitwarden does have an option to use passphrases, I just tried it and it gave me washtub-moocher-dominoes.

cynar@lemmy.world · 2 pts · 1y

I use auto generated passphrases. It's mostly for the occasions where I need to give the password to someone, without logging into my bitwarden account, on the device. It's a lot easier, for comparable levels of security.

fxomt@lemm.ee · 5 pts · 1y (3 replies)
[ removed ]
Toes@ani.social · 4 pts · 1y (2 replies)

Not really, you have a better chance if you use a completely random set of words. I remember hearing of someone getting their bitcoin stolen from their wallet despite their password being from an obscure Afrikaans poem.

Precisely why I salted it.

fxomt@lemm.ee · 1 pts · 1y (1 reply)
[ removed ]
Toes@ani.social · 1 pts · 1y

Always something a bit unique, can't make it predictable if someone managed to dump a list of em. This also isn't the formula I used just an example. Random words is also better if your memory is decent, they can even be your salt.

swab148@lemm.ee · 3 pts · 1y

I'm more of a SphinxOfBlackQuartz,JudgeMyVow:3 kinda guy

criitz@reddthat.com · 2 pts · 1y

I switched to using word phrases after having to type in these Qjdu37hYdu4sjdh&) |] >[vry monstrosities or communicate them to someone else one too many times.

smeg@feddit.uk · 3 pts · 1y (1 reply)
Rampyok151@lemmy.dbzer0.com · 2 pts · 1y

Looks like the link is broken now.

Edit: A part of the list can be found here and here.

LOOOOOWTAPERFADE@discuss.tchncs.de · 2 pts · 1y
[ removed ]