Elektrine lite

← Feed

@gregthemiller@beige.party

2026-03-24 19:38 UTC

passwords should be like “that’s close enough”

Replies (18)

  • @shadowwwind@fosstodon.org 2026-03-24 19:59

    @gregthemiller oh god

    Open ##1403183

  • @uncle_vinny@ohai.social 2026-03-24 20:03

    @gregthemiller "your heart was totally in the right place"

    Open ##1403186

  • @mewsleah@meow.social 2026-03-24 20:35

    @gregthemiller especially for xkcd type passwords. i can't type four words in a row without a typo when i can see them, damn it

    Open ##1403188

  • @OrdRadical@beige.party 2026-03-24 22:34

    @gregthemiller Oh, you had caps lock on. That's ok.

    Open ##1403189

  • @gregthemiller I should be able to decide if my password is good enough, if it needs numbers or special characters. If I want to live dangerously and have my password be "ABCD" they should let me. The lack of personal responsibility these days is worrying to me. If having a "weak" password bothers them so much, they should have a check box that says "I understand someone might spent thousands of hours trying to brute force my password and gain access to my Panfu account and I'm fine with making it easier for them." The lack of personal responsibility these days is worrying to me.

    Open ##1403191

  • @stash@infosec.exchange 2026-03-25 01:40

    @gregthemiller surely we're advanced enough as a species to build cryptographically irreversible vibe checks

    Open ##1403192

  • @gregthemiller@beige.party The amount of time, getting locked out because my fingers just are having a grumpy day, I kind of agree. Except, proper password storage, kind of prevents "close enough" being an option.

    Open ##1403196

  • @phurd@infosec.exchange 2026-03-25 03:46

    @gregthemiller that's absolutely possible technically but the tradeoff is that they can't be stored securely by the service you're entering your password into

    Open ##1403198

  • @hollie@social.coop 2026-03-25 04:30

    @gregthemiller Whenever websites are like “you changed this password two months ago,” I want to yell back, “yes and you already know I have terrible ADHD so let’s just agree to pretend that didn’t happen or or we’ll both be here all day”

    Open ##1403199

  • @futzle@old.mermaid.town 2026-03-25 04:57

    @gregthemiller I came into the replies looking for someone explaining why that isn't cryptographically viable, because this is the Fediverse after all, and I was not disappointed. Personally, I'd like every password to be checked once as if my keystrokes were on Dvorak, and then again as if they were on Qwerty.

    Open ##1403200

  • @vik@mastodon.nzoss.nz 2026-03-25 05:13

    @gregthemiller sowrdfish

    Open ##1403203

  • @haliphax@hachyderm.io 2026-03-25 06:23

    @gregthemiller "Yeah, pretty much. Go ahead."

    Open ##1403204

  • @th@social.v.st 2026-03-25 09:46

    @gregthemiller facebook (used to?) do this -- they would hash your password in a few different forms since mobile input fields make it hard to know if you typed the right one. https://www.youtube.com/watch?v=7dPRFoKteIU&t=960s

    Open ##1403205

  • @ottaross@mastodon.social 2026-03-25 18:27

    @gregthemiller "You're in the right ballpark, I'm going to give it to you."

    Open ##1403206

  • @gregthemiller @cR0w I’m sure they will be soon, thanks to vibe coding.

    Open ##1403208

  • @gregthemiller The UK Department of Work and Pensions does exactly this on their website for claiming government benefits and reporting income!

    Open ##1403209

  • @falcennial@mastodon.social 2026-03-28 15:44

    @gregthemiller 😂😂💯 right. even for the scammers it's like OK, clearly you worked hard on this one. you earned it buddy, here you go

    Open ##1403210

  • @gregthemiller AI passwords - that's not your password, but it fits the general pattern of your passwords.

    Open ##1403211