realn2s, (edited ) to microsoft

I'm not sure if I get something wrong, but I think ID Protection is complete rubbish. E.g. when ban weak passwords with the ominous 5 points rule the results seem to be completely arbitrary.

Microsoft speaks of including commonly used weak or compromised passwords in their Global banned password list. But the list isn't based on any external data source, so leaked passwords not leaked by Microsoft are not included 🤡​.

This leads to:
Known leaked passwords are accepted. Location name plus year is accepted. Dictionary word plus year is accepted!!!

Not sure if this applies only to German dictionary words.

It gets even worse. Reading the documentation, I found "Characters not allowed: Unicode characters" WTF

Coming back to the weird point system. A banned password is not really banned, it gives you "only" 1 point (and you need five).

This leads to the question how many points do none-banned words give?

If you think it can't get worse, you're wrong! It looks like each character of a none-banned word gives one point. Meaning "password1234" is an accepted password. (1 point for password and 4 for each digit)

Or a real life example: The attach which affected Microsoft, US government agency and countless other organizations world wide, was cause by a weak FTP server password.
Namely "solarwinds123", which would be accepted by ID Protection (1 point each for "solar" and "wind", 3 points for the numbers. If "solarwinds" would be on the custom banned list, "solarwind1234" would have been enough.

And you can't do anything against it.

I actually hope that the documentation is somewhat wrong and that "123" is not 3 points but 1 as it are consecutive numbers. But this would make it only marginal better (2023

realn2s,

@Hawkwinter
😅
Funny enough i give it easier to memorise a randomly generated password (with practice) than to think of a good password/passphrase and memorize (and type that correctly)

E.g. coming from association's to a password like CorrectHorseBatteryStaple for me leads to the problem that there are so many associations. Was it 'correct' or 'right', 'pony' or 'horse', 'stapler' or 'puncher'?
I give it easier to remember correctly if i get the password first (e.g. ) and then create/find the association.

But there is a second problem for me with passphrases. I hardly ever can enter them correctly on mobile. Fast fingering stuff and only seeing the last typed character die a fraction of a second doesn't play well for me

RedForkian, to random

This was written in 2015, but it is just as correct today as it was then. Passphrase generation is just as important as the method.

https://theintercept.com/2015/03/26/passphrases-can-memorize-attackers-cant-guess/

epixoip, to random

Happy !

I've cracked billions of from tens of thousands of in the past 12+ years, and because of this, I likely know at least one for 90% of people on the Internet. And I'm not alone! While I primarily crack breached passwords for research purposes and the thrill of the sport, others are selling your breached passwords to criminals who leverage them in and attacks.

How can you keep your accounts safe?

  • Use a ! I recommend @bitwarden and @1password

  • Use a style - four or more words selected at random - for passwords you have to commit to memory, like your master password!

  • Enable MFA for important online accounts, including cloud-based password managers!

  • Harden your master password by tweaking your password manager's KDF settings! For , use Argon2id with 64MB memory, 3 iterations, 4 parallelism. For and other PBKDF2 based password managers, set the iteration count to at least 600,000.

  • Use unique, randomly generated passwords for all your accounts! Use your password manager to generate random 14-16 character passwords for everything. Modern password cracking is heavily optimized for human-generated passwords, because humans are highly predictable. Randomness defeats this and forces attackers to resort to incremental brute force! There's no trick you can do to make a secure, uncrackable password on your own - your meat glob will only betray you.

  • Use an ad blocker like Origin to keep you safe from password-stealing and other browser based threats!

  • Don't fall for attacks and other social engineering attacks! Browser-based password managers help defend against phishing attacks because they'll never autofill your passwords on fake login pages. Think before you click, and never give your passwords to anyone, not even if they offer you chocolate or weed.

  • : require ad blockers, invest in an enterprise password management solution, audit password manager logs to ensure employes aren't sharing passwords outside the org, implement a Fine Grained Password Policy that requires a minimum of 20 characters to encourage the use of long passphrases, implement a password filter to block commonly used password patterns and compromised passwords, disable authentication and disable RC4 for , disable legacy broadcast protocols like LLMNR and NBT-NS, require mandatory signing, use Group Managed Service Accounts instead of shared passwords, monitor public data breaches for employee credentials, and crack your own passwords to audit the effectiveness of your password policy and user training!

Septem9er, to random German
@Septem9er@chaos.social avatar

How did I end up making calculations in a spreadsheet instead of studying now?

I just quickliy wanted to check what the picture about password security, that is currently shared a lot means for the security of / .

Ehm, the Internet in the train was shitty, so I couldn't study! Let's use that as excuse. (He says, hours after exiting the train.)

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • rosin
  • ngwrru68w68
  • everett
  • DreamBathrooms
  • mdbf
  • magazineikmin
  • thenastyranch
  • Youngstown
  • tacticalgear
  • ethstaker
  • slotface
  • Durango
  • kavyap
  • provamag3
  • cisconetworking
  • Leos
  • GTA5RPClips
  • osvaldo12
  • InstantRegret
  • cubers
  • modclub
  • khanakhh
  • anitta
  • tester
  • normalnudes
  • megavids
  • lostlight
  • All magazines