password requirement is a joke - Router Forums
 38Likes
Closed Thread
 
LinkBack Thread Tools Display Modes
post #1 of 23 (permalink) Old 03-08-2017, 09:57 PM Thread Starter
Registered User
 
Join Date: Jun 2014
Country: United States
First Name: N/a
Posts: 67
 
Default password requirement is a joke

This is the worse site I am on for password requirements. My bank, credit card, and 401k are easier.

This is a forum, not a financial institution.

Plus it would be nice if the password they sent you to reset your password was a word you could type in.

Why does the reset password have to be so hard?
Shop guy and Herb Stoops like this.
Zerk is offline  
Sponsored Links
Advertisement
 
post #2 of 23 (permalink) Old 03-08-2017, 10:49 PM
Marine Engineer
 
kp91's Avatar
 
Join Date: Sep 2004
Country: United States
First Name: Doug
Posts: 4,492
 
Default

I definitely understand the frustration!

I have some insane password requirements for work passwords, 16 characters, 3 caps, 3 special, 3 numbers. Change every 90 days and can't use previous 12. The easy way is to make a phrase.

Of course, once you log in here, stay logged in!
Herb Stoops likes this.

Doug
1 John 1:9
Fredericksburg, VA




http://disasterreliefeffort.org/
kp91 is online now  
post #3 of 23 (permalink) Old 03-08-2017, 10:51 PM
Registered User
 
RainMan 2.0's Avatar
 
Join Date: May 2014
Country: Canada
First Name: Rick
Posts: 15,637
 
Default

I had to change my password at work after this commercial premiered. It was easy to remember to


I donít always insulate , but when I do .
Ok ,I never insulate
RainMan 2.0 is online now  
Sponsored Links
Advertisement
 
post #4 of 23 (permalink) Old 03-08-2017, 11:48 PM
Moderation Team
 
MT Stringer's Avatar
 
Join Date: Aug 2012
Country: United States
First Name: Mike
Posts: 5,597
 
Default

Quote:
Originally Posted by Zerk View Post
This is the worse site I am on for password requirements. My bank, credit card, and 401k are easier.

This is a forum, not a financial institution.

Plus it would be nice if the password they sent you to reset your password was a word you could type in.

Why does the reset password have to be so hard?
Keep it simple. Make your password "INVALID". Then when you forget it or miss type it, your computer will tell you "Your password is INVALID"!
OPG3, MEBCWD, tooler2 and 5 others like this.

That's my story and I'm stickin' to it!
MT Stringer is offline  
post #5 of 23 (permalink) Old 03-09-2017, 01:03 AM
Registered User
 
DaninVan's Avatar
 
Join Date: Dec 2011
Country: Canada
First Name: Dan
Posts: 13,831
 
Default

"That password is taken" ....heh
If you use Firefox, their 'Password vault' is supposed to be extremely secure.
https://www.bestvpn.com/blog/27352/f...w.google.ca%2F
DaninVan is offline  
post #6 of 23 (permalink) Old 03-09-2017, 03:02 AM
Moderation Team
 
Cherryville Chuck's Avatar
 
Join Date: Sep 2010
Country: Canada
First Name: Charles
Posts: 14,859
 
Default

Quote:
Originally Posted by Zerk View Post
This is the worse site I am on for password requirements. My bank, credit card, and 401k are easier.

This is a forum, not a financial institution.

Plus it would be nice if the password they sent you to reset your password was a word you could type in.

Why does the reset password have to be so hard?
We were told maybe a year ago now that the forum had been hacked so the owners decided we needed that level of protection to protect our accounts (most likely their liability for protecting our accounts).
Herb Stoops likes this.

Someone I consider a master woodworker once told me that a master woodworker is not someone who never makes mistakes. He is someone who is able to cover them up so that no one can tell.
Cherryville Chuck is offline  
post #7 of 23 (permalink) Old 03-09-2017, 04:43 AM
Registered User
 
Join Date: Jun 2011
Country: United Kingdom
First Name: Andy
Posts: 577
 
Default

Is it documented exactly what the password complexity rules are here now?
I understand the forum owners wanting to cover their potential liability in light of the big password breach last year, but on the other hand the password rules shouldn't be disproportionate to the sensitivity of the account. As the OP points out, an internet forum account isn't a bank or credit card account. If any of the regular members' accounts was taken over by an imposter, I like to think that we'd realise pretty quickly. Like say if someone claiming to be Rick posted pictures of installing insulation in his shop, we'd know something was up right away.

Doug, your employer might be interested in the password guidance that the British government is issuing here now.
https://www.gov.uk/government/upload...r_approach.pdf
One of the key passages is:
"Regular password changing harms rather than improves security, so avoid placing this burden on users. However, users must change their passwords on indication or suspicion of compromise".
Most people when they're forced to change a password, just increment a number on the end. Well guess what, an attacker can add 1 as well. It's good that we're finally realising that inventing and remembering secure passwords is really hard, and the more often you make people do it, the worse job they'll make of it.
AndyL is offline  
post #8 of 23 (permalink) Old 03-09-2017, 08:29 AM
Registered User
 
schnewj's Avatar
 
Join Date: Nov 2013
Country: United States
First Name: Bill
Posts: 2,323
 
Default

Quote:
Originally Posted by DaninVan View Post
"That password is taken" ....heh
If you use Firefox, their 'Password vault' is supposed to be extremely secure.
https://www.bestvpn.com/blog/27352/f...w.google.ca%2F
Last Pass is, also, a very good program that is free. It will even fill in online forms for you.
furboo likes this.

Hi, sorry I missed you. I have gone to find myself, but if I return before I get back, please ask me to wait.

Nothing ever gets built on schedule or within budget.

Tool Storage Bait and Tackle, LLC.
schnewj is offline  
post #9 of 23 (permalink) Old 03-09-2017, 08:49 AM Thread Starter
Registered User
 
Join Date: Jun 2014
Country: United States
First Name: N/a
Posts: 67
 
Default

What liability? It is a free to use forum. My bank and financial accounts are not as strict. The 10 character limit is required by my credit card either.

Worse is when you ask for a new password they give you a goofy one. Some places give you a simple one that is only good for short time and must be changed
Zerk is offline  
post #10 of 23 (permalink) Old 03-09-2017, 09:34 AM
Administrator
 
Cricket's Avatar
 
Join Date: Jan 2014
Country: United States
First Name: Cricket
Posts: 1,970
 
Default

Quote:
Originally Posted by Zerk View Post
This is the worse site I am on for password requirements. My bank, credit card, and 401k are easier.

This is a forum, not a financial institution.

Plus it would be nice if the password they sent you to reset your password was a word you could type in.

Why does the reset password have to be so hard?
Unfortunately, a lot of people use the same password on multiple sites. The reason our password requirements are strong, is to help make member passwords more secure.

You don't have to keep the one you are assigned when you do a password reset though. You can change it to something easier for you to remember, while still using a more secure password.

A good piece of advice, to help in remembering the more complex password, is to do a phrase instead of just randomly adding in the extra requirements.

Example: BoiledCabbageis#1!

How To Change Your Password
JFPNCM, Danman1957 and MT Stringer like this.

Need admin assistance? Post here so we can help you!
Cricket is offline  
Closed Thread

Quick Reply
Message:
Options

Register Now



In order to be able to post messages on the Router Forums forums, you must first register.
Please enter your desired user name, your email address and other required details in the form below.

User Name:
Password
Please enter a password for your user account. Note that passwords are case-sensitive.

Password:


Confirm Password:
Email Address
Please enter a valid email address for yourself.

Email Address:
OR

Log-in











Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Show Printable Version Show Printable Version
Email this Page Email this Page
Display Modes
Linear Mode Linear Mode



Similar Threads
Thread Thread Starter Forum Replies Last Post
Pass word hassle mgmine Lobby 20 09-19-2016 08:33 AM
Attention - Password And Security Update Admin Site Help and Suggestions 251 06-30-2016 12:49 PM
How To Change Your Password Cricket Getting Started With RouterForums.com 0 06-25-2016 12:22 PM
How To Reset Forgotten Password Cricket Getting Started With RouterForums.com 0 06-08-2016 12:29 PM
How To Reset Forgotten Password Cricket Site Help and Suggestions 0 06-08-2016 12:29 PM

Posting Rules  
You may post new threads
You may post replies
You may post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are On

 
For the best viewing experience please update your browser to Google Chrome