247
submitted 11 months ago by L4s@lemmy.world to c/technology@lemmy.world

The worst passwords of 2023 are also the most common, "123456" comes in first::undefined

you are viewing a single comment's thread
view the rest of the comments
[-] JustAnotherRando@lemmy.world 13 points 11 months ago* (last edited 11 months ago)

The most infuriating thing is websites that actually limit secure passwords (e.g. "password must be between 6 and 12 characters"). Preventing longer passwords makes little sense if they're salting and hashing; and if they're storing the passwords in plain text (which is just about the only reason to limit the max length to anything less than what a person would reasonably remember), that's even worse.

[-] ricecake@sh.itjust.works 8 points 11 months ago

There was a belief, before the advent of ubiquitous password managers, that allowing passwords to be "too long" would result in people forgetting their password more often, entering it wrong, or some combination which would increase reset requests and ultimately cause people to use worse passwords. Basically "you can't remember a 54 character random password, and you're gonna get pissed and switch to a six character predictable word".

This is now obviously a terrible line of reasoning, but it was only middling bad at the time.

[-] JustAnotherRando@lemmy.world 4 points 11 months ago

Oh, i guess that makes some sort of sense - obviously I disagree with the conclusion, but I understand it - but it's beyond frustrating when you think "maybe I'll pay this bill online" and see that limit. And even if that is the reasoning for the limit, if they haven't updated their requirements in all that time, I have little faith that they're storing my sensitive information securely.

[-] __init__@programming.dev 2 points 11 months ago

I feel like most of the sites I’ve seen password limits like this on are financial in nature, where it’s all theatrics - the appearance of security takes precedence over (and in some cases comes at the expense of) actual security.

this post was submitted on 17 Nov 2023
247 points (96.6% liked)

Technology

59020 readers
3635 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS