lonestar-lemmy
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Nemeski@lemm.ee to Bitwarden@discuss.tchncs.deEnglish · 5 months ago

How long should a password be?

bitwarden.com

external-link
message-square
19
link
fedilink
37
external-link

How long should a password be?

bitwarden.com

Nemeski@lemm.ee to Bitwarden@discuss.tchncs.deEnglish · 5 months ago
message-square
19
link
fedilink
How long should a password be? | Bitwarden
bitwarden.com
external-link
Ever wondered how long your passwords should be for strong security? Experts recommend a random mix of at least 14 to 16 characters for every unique password.
alert-triangle
You must log in or # to comment.
  • noride@lemm.ee
    link
    fedilink
    English
    arrow-up
    21
    ·
    5 months ago

    correct horse battery staple

    • Alk@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      7
      ·
      5 months ago

      How did you steal my password??

      • UndulyUnruly@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        5 months ago

        Witchcraft! Get them!

  • fxomt's on dbzer0@lemm.ee
    link
    fedilink
    English
    arrow-up
    6
    ·
    edit-2
    4 months ago

    deleted by creator

    • einkorn@feddit.org
      link
      fedilink
      English
      arrow-up
      6
      ·
      5 months ago

      And then there are those services that let you enter arbitrarily long passwords in the registration form but only save something like 16 characters.

      • Mike Wooskey@lemmy.thewooskeys.com
        link
        fedilink
        English
        arrow-up
        5
        ·
        5 months ago

        I hate this situation. What horrible design choices in their code!

      • fxomt's on dbzer0@lemm.ee
        link
        fedilink
        English
        arrow-up
        3
        ·
        edit-2
        4 months ago

        deleted by creator

        • einkorn@feddit.org
          link
          fedilink
          English
          arrow-up
          2
          ·
          5 months ago

          Amen

        • amorpheus@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          5 months ago

          How would you know?

          • fxomt's on dbzer0@lemm.ee
            link
            fedilink
            English
            arrow-up
            1
            ·
            edit-2
            4 months ago

            deleted by creator

            • amorpheus@lemmy.world
              link
              fedilink
              English
              arrow-up
              2
              ·
              edit-2
              5 months ago

              No, that’s the point, you’d never know whether they only validate a subset of the password. Only by testing different variations you would know that less than the whole string still works.

              • fxomt's on dbzer0@lemm.ee
                link
                fedilink
                English
                arrow-up
                1
                ·
                edit-2
                4 months ago

                deleted by creator

                • amorpheus@lemmy.world
                  link
                  fedilink
                  English
                  arrow-up
                  2
                  ·
                  5 months ago

                  I wouldn’t speculate on how common it is but limiting passwords seems to happen more than it should. So maybe many are taking the stealth approach.

                  One site I know where this happens (at least I experienced it some years ago) was Blizzard. Found out by sheer luck after I clearly fumbled the end of my password and was logged in regardless.

  • nutbutter@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    5
    ·
    5 months ago

  • Toes♀@ani.social
    link
    fedilink
    English
    arrow-up
    9
    arrow-down
    4
    ·
    5 months ago

    People gotta stop doing QkFEcEEkJFcwUkQ=

    aQuickBrownFoxJumpedOverALazyDog$nuggle9 is far easier to remember and secure.

    • Deebster@infosec.pub
      link
      fedilink
      English
      arrow-up
      13
      ·
      5 months ago

      The article is from Bitwarden, which is a password manager - using them you don’t need to remember individual passwords (or type them, normally).

      Bitwarden does have an option to use passphrases, I just tried it and it gave me washtub-moocher-dominoes.

      • cynar@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        5 months ago

        I use auto generated passphrases. It’s mostly for the occasions where I need to give the password to someone, without logging into my bitwarden account, on the device. It’s a lot easier, for comparable levels of security.

    • fxomt's on dbzer0@lemm.ee
      link
      fedilink
      English
      arrow-up
      6
      ·
      edit-2
      4 months ago

      deleted by creator

      • Toes♀@ani.social
        link
        fedilink
        English
        arrow-up
        4
        ·
        5 months ago

        Not really, you have a better chance if you use a completely random set of words. I remember hearing of someone getting their bitcoin stolen from their wallet despite their password being from an obscure Afrikaans poem.

        Precisely why I salted it.

        • fxomt's on dbzer0@lemm.ee
          link
          fedilink
          English
          arrow-up
          1
          ·
          edit-2
          4 months ago

          deleted by creator

          • Toes♀@ani.social
            link
            fedilink
            English
            arrow-up
            2
            ·
            5 months ago

            Always something a bit unique, can’t make it predictable if someone managed to dump a list of em. This also isn’t the formula I used just an example. Random words is also better if your memory is decent, they can even be your salt.

    • swab148@lemm.ee
      link
      fedilink
      English
      arrow-up
      4
      ·
      5 months ago

      I’m more of a SphinxOfBlackQuartz,JudgeMyVow:3 kinda guy

    • criitz@reddthat.com
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      5 months ago

      I switched to using word phrases after having to type in these Qjdu37hYdu4sjdh&) |] >[vry monstrosities or communicate them to someone else one too many times.

  • Tempo [he/him]@hexbear.net
    link
    fedilink
    English
    arrow-up
    4
    ·
    5 months ago

    if you have to ask, not enough. i once had a bank whose system didn’t accept any password longer than 10 characters, and that was only after i called them up and asked why i couldn’t log in

  • smeg@feddit.uk
    link
    fedilink
    English
    arrow-up
    3
    ·
    5 months ago

    Interesting to see the linked list of the top 100,000 passwords from the Have I Been Pwned data set

  • LOOOOOWTAPERFADE@discuss.tchncs.deBanned
    link
    fedilink
    English
    arrow-up
    2
    ·
    edit-2
    5 months ago

    Removed by mod

Bitwarden@discuss.tchncs.de

bitwarden@discuss.tchncs.de

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !bitwarden@discuss.tchncs.de

Discuss the Paswordmanager Bitwarden.

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 1 user / day
  • 15 users / week
  • 15 users / month
  • 285 users / 6 months
  • 0 local subscribers
  • 1.02K subscribers
  • 53 Posts
  • 112 Comments
  • Modlog
  • mods:
  • wuffa@discuss.tchncs.de
  • BE: 0.19.12
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org