Post #448301
2026-01-05 10:30 UTC
Replies (21)
-
@WTL@mastodon.social 2026-01-05 11:11
@diffrentcolours @GossiTheDog 🤣
-
@khleedril@cyberplace.social 2026-01-05 11:13
@diffrentcolours Tomorrow you'll forget the '2' on the end.
-
@matth@techhub.social 2026-01-05 11:13
@diffrentcolours No password should be considered secure without a final exclamation mark.
-
@yadt@tech.lgbt 2026-01-05 11:20
@diffrentcolours I think the NCSC also advises against posting your excellent passwords on Mastodon. (Which is annoying sometimes, when I want to comment on some feature of my password...)
-
@GroupNebula563@mastodon.social 2026-01-05 11:27
@diffrentcolours actually probably a pretty good password
-
@Fishd@infosec.exchange 2026-01-05 11:53
@diffrentcolours
-
@CryogenicIce9@mastodon.online 2026-01-05 12:26
@diffrentcolours Where's the special character though? wait the quote marks are part of the password, that's genius
-
@fbarton@infosec.exchange 2026-01-05 12:51
@diffrentcolours true story… a while back the trouble ticket platform $pastjob used didn’t have the ability for their support to assume identity… but they could see our passwords, and sign in as us I set my password to “plainTextPasswordsSuck”… The next time I had to call support, I waited… and the tech burst out laughing Their next update included password hashing, and the ability for their support (and our admins) to assume identity
-
@silvermoon82@wandering.shop 2026-01-05 13:05
@diffrentcolours "Your password policy continues to be bad even in January 2026 battery staple"
-
@log@mastodon.sdf.org 2026-01-05 14:49
@diffrentcolours I'm up to "ExpiringPasswords55IsDumb" mainly because I need two numeral characters.
-
@xinit@mastodon.coffee 2026-01-05 15:01
@diffrentcolours "ERROR: Password must be between 12-14 characters in length in include a symbol." @GossiTheDog
-
@MennoWolff@ohai.social 2026-01-05 15:04
@diffrentcolours Do you use the quotes? Because otherwise I'm pretty sure it won't be accepted, because it has neither numbers nor special characters. You gotta have at least one of those, otherwise your 40+ character password is not strong enough. 😁
-
@jargoggles@kolektiva.social 2026-01-05 15:05
@diffrentcolours I'm up to hunter20 at this point.
-
@DamonHD@mastodon.social 2026-01-05 15:08
@diffrentcolours All I can see is ****************
-
@benjohn@todon.nl 2026-01-05 15:09
@diffrentcolours not “2!” To cover the symbol requirement?
-
@antdude@mastodon.social 2026-01-05 16:17
@diffrentcolours missing symbols ;)
-
@Jamessocol@indieweb.social 2026-01-05 17:21
@diffrentcolours also NIST SP800-63B §5.1.1.2 if you need those special chars
-
@Mark62@cupoftea.social 2026-01-05 19:41
@diffrentcolours @HowardGees My brother was head of IT and says constantly requiring a password change is actually very insecure as people tend to write it down to remember.
-
@greatlaketrout@noc.social 2026-01-06 00:15
@diffrentcolours I argue about this ALL the f’ing time. Ours expire every 90 days, which by the way was the general guidance prior to 2015. Now every major cybersecurity expert says don’t force random changes, make them really strong and hold onto them. Guess our IT department is a bit behind on their best practices.
-
@nxskok@cupoftea.social 2026-01-06 02:29
@diffrentcolours "cannot be the same as any of your previous 37 passwords". All right then, "NCSC advises against regular password expiry38"
-
@ananas@social.linux.pizza 2026-01-06 05:06
@diffrentcolours Source, for those who want it: https://www.ncsc.gov.uk/collection/passwords/updating-your-approach