• Please take a moment to look over the Suggestions & Feedback rules before making a post: READ RULES HERE

Password change every 46 days? really?

Status
Not open for further replies.

eried

Newbie
Joined
Jan 17, 2013
Messages
14
Reaction score
10
I just end using crappy passwords like qwerty123456, and ciclying between them. Struggling to re-login.

What is the point of this?
 
If you pay attention you will see multiple people experiencing brute force attacks on their accounts.
Resetting your password is for your security and make sure you use some special characters.
 
I don't see the logic in your answer, a normal secure password (one that I can remember) like qwerty12345$ has more than 10 million combinations, impossible to get via bruteforce if the attempts are limited to a couple dozen a day, not in a millenium.

Now, having to change every 46 days my password for A DIFFERENT one that I can remember, will only weaken that possibility, the bruteforce attack does not needs to change, he only gets mathematically more chances to get the password every 46 days. Do not tell me that you elaborate a very complex password every 46 days instead using a password with incremental info just to ease your reminder of the last one you used, or even less secure; you write down them.

This only makes sense where there is a hash leak and that's is another history.

References:
pcmag.com/article2/0,2817,2362692,00.asp
cryptosmith.com/node/218
sepago.de/e/helge/2009/06/22/how-forcing-password-changes-actually-weakens-security
 
Last edited:
For peace of mind, 46 days really isn't an issue for me. There's plenty of similar combinations that can be used with special characters added.
 
Yes, extremely annoying, "your password is 3 seconds old and therefore has expired". Then I have to try 5 times to see which one I changed it to last time. If this is so beneficial to security how come big sites (fb) never do it.
 
OP, have you ever heard of:


  • Roboform
  • Lastpass
  • Excel spreadsheet

I haven't typed in a single password since 2005; it sounds like you need to get with modern times.

Exits thread...

You forget "All my passwords in plaintext.txt", space age guy. I use chrome sync for the forms and keepass for the bank accounts, but that not my point, you still have to change the password manually.
 
I know, I find this very annoying too. Thought there was a setting in my settings that I could changes but doesn't seem to be.
 
I hear you, I use Roboform too and almost never manually type in passwords. Changing my PW every 46 days isn't a problem for me, I welcome it.

OP, have you ever heard of:


  • Roboform
  • Lastpass
  • Excel spreadsheet

I haven't typed in a single password since 2005; it sounds like you need to get with modern times.

Exits thread...
 
While this can be annoying, It's for your own safety. We change the number every now and then and Newbies have the lowest number. Consider becoming a Jr VIP or even donor to extend this time. We don't go out of our way to be awkward, it just minimizes the risks of hacked accounts which in turn lead onto threads being created asking for more security.

Having said all that, based on feedback, we have now extended the amount of time needed before a password reset is forced for newbies.

Hope this helps.
 
I don't see the logic in your answer, a normal secure password (one that I can remember) like qwerty12345$ has more than 10 million combinations, impossible to get via bruteforce if the attempts are limited to a couple dozen a day, not in a millenium.

This is NOT a secure password, it 's easily crackable via a hybrid dictionary attack.
 
Status
Not open for further replies.
Back
Top