news.volyx.in

I hate password rules (schneier.com)

564 points by CapitalistCartr · 1769 days ago · 435 comments on HN

Article summary

The article discusses the frustration of dealing with varying password rules across different websites, which can lead to secure passwords being rejected. The author argues that these rules are often inconsistent and can hinder the use of strong, generated passwords. This can result in users creating weaker passwords to accommodate the rules. The article highlights the need for standardized password rules or alternative authentication methods.

Main themes

  • password security
  • inconsistent rules
  • user frustration
  • authentication methods
  • password managers
  • security standards
  • usability vs security

What commenters say

  • Password rules are often inconsistent and frustrating for users, leading to weaker passwords.
  • Standardized password rules or a common encoding standard could improve the situation.
  • Disabling paste functionality in password fields can be particularly annoying and insecure.
  • Some argue that having different password rules across sites can provide a form of hybrid vigor and make it harder for attackers to formulate brute force attacks.
  • Others believe that password rotation and complex rules are ineffective and can lead to insecure practices like writing down passwords.
  • The use of password managers can help generate strong passwords that fit specific rules, but requiring their use may not be practical for all users.
  • Alternative authentication methods, such as decentralized SSO solutions, may be a better option than relying on passwords.
  • Character limits on passwords can be a symptom of insecure password storage practices, rather than a legitimate security measure.