←back to thread

430 points tambourine_man | 2 comments | | HN request time: 0s | source
Show context
calgoo ◴[] No.41879171[source]
I always liked the 1Password word passwords… you select the number of words and it generates each word in upper OR lowercase, and connect them with symbols or numbers. Easy to memorize, and better then keepass or others that use more fixed formats: same characters between words and words are just in title format where the first letter is upper case and rest is lowercase.
replies(5): >>41879306 #>>41879343 #>>41879408 #>>41879433 #>>41879512 #
jorvi ◴[] No.41879408[source]
The problem is that many sites still use archaic password rules.

1Password should by default just always capitalize one word, and add “1” at the end of the memorable password. Since the words are separated by “-“ or “.”, you already hit the “at least one symbol” rule.

replies(3): >>41879566 #>>41880012 #>>41883980 #
dark-star ◴[] No.41879566[source]
I especially like sites that disallow pasting into password fields.... Yes, that is apparently a thing, especially for banking or finance related sites (from my experience)
replies(7): >>41879659 #>>41879830 #>>41880113 #>>41880189 #>>41880542 #>>41881749 #>>41881852 #
yojo ◴[] No.41879659[source]
For a while, the login for TreasuryDirect (the gov site for buying US bonds) disabled paste and typing! It required you to click out your password on an onscreen keyboard.

I pity the folks who don’t know how to use dev tools.

replies(2): >>41879902 #>>41880725 #
1. commandersaki ◴[] No.41879902[source]
Good on 'em for doing a complete 180 on that. Bank of Melbourne has stated that using a Password Manager is a violation of their Terms of Service (as people have complained about the non-pasteable/autofill fields).
replies(1): >>41911262 #
2. magnetowasright ◴[] No.41911262[source]
Last time I had the sincere displeasure of having to use bank of Melbourne, their password rules included that you couldn't have repeated letters, so if you were trying to use a passphrase like correct-horse-battery-staple it would not allow the double r in correct or double t in battery. The rest of their password rules were abhorrent like all financial institutions but that one in particular irritated me to no end.