• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Think your passwords are secure enough?

qubit

Overclocked quantum bit
Joined
Dec 6, 2007
Messages
17,865 (2.99/day)
Location
Quantum Well UK
System Name Quantumville™
Processor Intel Core i7-2700K @ 4GHz
Motherboard Asus P8Z68-V PRO/GEN3
Cooling Noctua NH-D14
Memory 16GB (2 x 8GB Corsair Vengeance Black DDR3 PC3-12800 C9 1600MHz)
Video Card(s) MSI RTX 2080 SUPER Gaming X Trio
Storage Samsung 850 Pro 256GB | WD Black 4TB | WD Blue 6TB
Display(s) ASUS ROG Strix XG27UQR (4K, 144Hz, G-SYNC compatible) | Asus MG28UQ (4K, 60Hz, FreeSync compatible)
Case Cooler Master HAF 922
Audio Device(s) Creative Sound Blaster X-Fi Fatal1ty PCIe
Power Supply Corsair AX1600i
Mouse Microsoft Intellimouse Pro - Black Shadow
Keyboard Yes
Software Windows 10 Pro 64-bit
Watch these two videos and learn why your password for important logins is likely too insecure and just how easy they are to crack with powerful PCs. By important logins I mean things like online banking, online stores like Amazon, PC login at work etc. Change it now.

It should be a minimum of 9 characters, have special characters in it and try not to use dictionary words. Upper and lower case mix really helps too.

Oh and NEVER use the same password on more than one login.

It's all in the videos.


 
Joined
Nov 18, 2010
Messages
7,124 (1.45/day)
Location
Rīga, Latvia
System Name HELLSTAR
Processor AMD RYZEN 9 5950X
Motherboard ASUS Strix X570-E
Cooling 2x 360 + 280 rads. 3x Gentle Typhoons, 3x Phanteks T30, 2x TT T140 . EK-Quantum Momentum Monoblock.
Memory 4x8GB G.SKILL Trident Z RGB F4-4133C19D-16GTZR 14-16-12-30-44
Video Card(s) Sapphire Pulse RX 7900XTX + under waterblock.
Storage Optane 900P[W11] + WD BLACK SN850X 4TB + 750 EVO 500GB + 1TB 980PRO[FEDORA]
Display(s) Philips PHL BDM3270 + Acer XV242Y
Case Lian Li O11 Dynamic EVO
Audio Device(s) Sound Blaster ZxR
Power Supply Fractal Design Newton R3 1000W
Mouse Razer Basilisk
Keyboard Razer BlackWidow V3 - Yellow Switch
Software FEDORA 39 / Windows 11 insider
Well... I will say just one - everything made by man can be broken....
 

Solaris17

Super Dainty Moderator
Staff member
Joined
Aug 16, 2005
Messages
25,867 (3.79/day)
Location
Alabama
System Name Rocinante
Processor I9 14900KS
Motherboard EVGA z690 Dark KINGPIN (modded BIOS)
Cooling EK-AIO Elite 360 D-RGB
Memory 64GB Gskill Trident Z5 DDR5 6000 @6400
Video Card(s) MSI SUPRIM Liquid X 4090
Storage 1x 500GB 980 Pro | 1x 1TB 980 Pro | 1x 8TB Corsair MP400
Display(s) Odyssey OLED G9 G95SC
Case Lian Li o11 Evo Dynamic White
Audio Device(s) Moondrop S8's on Schiit Hel 2e
Power Supply Bequiet! Power Pro 12 1500w
Mouse Lamzu Atlantis mini (White)
Keyboard Monsgeek M3 Lavender, Akko Crystal Blues
VR HMD Quest 3
Software Windows 11
Benchmark Scores I dont have time for that.
Honestly alot of this stuff is irrelevant. I mean not in the way you think, absolutely you should be using stronger passwords changing them every few months and deff use different ones for different things. But that said no one is sitting in there basement brute forcing my TPU account with 4 titans. Most attacks with password theft usually involve a breach of the database itself. At least in high profile things.
 

qubit

Overclocked quantum bit
Joined
Dec 6, 2007
Messages
17,865 (2.99/day)
Location
Quantum Well UK
System Name Quantumville™
Processor Intel Core i7-2700K @ 4GHz
Motherboard Asus P8Z68-V PRO/GEN3
Cooling Noctua NH-D14
Memory 16GB (2 x 8GB Corsair Vengeance Black DDR3 PC3-12800 C9 1600MHz)
Video Card(s) MSI RTX 2080 SUPER Gaming X Trio
Storage Samsung 850 Pro 256GB | WD Black 4TB | WD Blue 6TB
Display(s) ASUS ROG Strix XG27UQR (4K, 144Hz, G-SYNC compatible) | Asus MG28UQ (4K, 60Hz, FreeSync compatible)
Case Cooler Master HAF 922
Audio Device(s) Creative Sound Blaster X-Fi Fatal1ty PCIe
Power Supply Corsair AX1600i
Mouse Microsoft Intellimouse Pro - Black Shadow
Keyboard Yes
Software Windows 10 Pro 64-bit
But that said no one is sitting in there basement brute forcing my TPU account with 4 titans.
Agreed, the TPU account isn't worth doing, along with most other forums, which is why I didn't list it in the examples. Only logins that would cause one real trouble if they were compromised.
 

silentbogo

Moderator
Staff member
Joined
Nov 20, 2013
Messages
5,473 (1.44/day)
Location
Kyiv, Ukraine
System Name WS#1337
Processor Ryzen 7 3800X
Motherboard ASUS X570-PLUS TUF Gaming
Cooling Xigmatek Scylla 240mm AIO
Memory 4x8GB Samsung DDR4 ECC UDIMM
Video Card(s) Inno3D RTX 3070 Ti iChill
Storage ADATA Legend 2TB + ADATA SX8200 Pro 1TB
Display(s) Samsung U24E590D (4K/UHD)
Case ghetto CM Cosmos RC-1000
Audio Device(s) ALC1220
Power Supply SeaSonic SSR-550FX (80+ GOLD)
Mouse Logitech G603
Keyboard Modecom Volcano Blade (Kailh choc LP)
VR HMD Google dreamview headset(aka fancy cardboard)
Software Windows 11, Ubuntu 20.04 LTS
MD5 is a bad example.
Many moons ago I could do collision cracking with my 74GB rainbow table collection on an old Dell laptop (even had it on DVDs :laugh:) .
That was sufficient enough for mixed-case alphanumeric passwords up to 13 symbols long.
 
Joined
May 8, 2016
Messages
244 (0.08/day)
System Name Box
Processor Ryzen 9 5900X
Motherboard MSI Meg Ace Max 570S
Cooling Corsair h150i Elite Capellix 360 white
Memory 16 GB Teamforce DDR 4 4500 (2x8) CL18
Video Card(s) Aorus 1080ti
Storage NVMe: Samsung 980 Pro 2TB, WD_BLACK SN770 2TB, Crucial P5 Plus 2TB, spinners: 3TB, 4TB
Display(s) Samsung 1080p
Case Lian Li 011 Dynamic white - fans: 2x140mm, 7x120mm
Audio Device(s) stock
Power Supply EVGA G2 850
Mouse Razor DeathAdder 3.5G
Keyboard Corsair K68 RGB
VR HMD Valve Index
Software Win10 pro
Benchmark Scores later
If possible, I prefer to use a half dozen or so dictionary words as a password.
 
Joined
Nov 18, 2010
Messages
7,124 (1.45/day)
Location
Rīga, Latvia
System Name HELLSTAR
Processor AMD RYZEN 9 5950X
Motherboard ASUS Strix X570-E
Cooling 2x 360 + 280 rads. 3x Gentle Typhoons, 3x Phanteks T30, 2x TT T140 . EK-Quantum Momentum Monoblock.
Memory 4x8GB G.SKILL Trident Z RGB F4-4133C19D-16GTZR 14-16-12-30-44
Video Card(s) Sapphire Pulse RX 7900XTX + under waterblock.
Storage Optane 900P[W11] + WD BLACK SN850X 4TB + 750 EVO 500GB + 1TB 980PRO[FEDORA]
Display(s) Philips PHL BDM3270 + Acer XV242Y
Case Lian Li O11 Dynamic EVO
Audio Device(s) Sound Blaster ZxR
Power Supply Fractal Design Newton R3 1000W
Mouse Razer Basilisk
Keyboard Razer BlackWidow V3 - Yellow Switch
Software FEDORA 39 / Windows 11 insider
Many moons ago I could do collision cracking with my 74GB rainbow table collection on an old Dell laptop

Aaaannndd.... what did you crack? :D :pimp:
 
Joined
Oct 29, 2012
Messages
842 (0.20/day)
Location
Germany
System Name Perf/price king /w focus on low noise and TDP
Processor Intel Xeon E3-1230 v2
Motherboard Gigabyte GA-B75M-D3H
Cooling Thermalright HR-02 Macho Rev.A (BW)
Memory 16GB Corsair Vengeance LP Black
Video Card(s) Gigabyte GTX 670 OC
Storage 525GB Crucial MX300 & 256GB Samsung 830 Series
Display(s) Home: LG 29UB65-P & Work: LG 34UB88-B
Case Fractal Design Arc Mini
Audio Device(s) Asus Xonar Essence STX /w Sennheiser HD 598
Power Supply be quiet! Straight Power CM E9 80+ Gold 480W
Mouse Roccat Kone XTD optical
Keyboard SteelSeries Apex M500
Software Win10
I use keepass and its password creator. Would take 'em quite a while to brute force such passwords...
 
Joined
Feb 14, 2012
Messages
2,323 (0.52/day)
System Name msdos
Processor 8086
Motherboard mainboard
Cooling passive
Memory 640KB + 384KB extended
Video Card(s) EGA
Storage 5.25"
Display(s) 80x25
Case plastic
Audio Device(s) modchip
Power Supply 45 watts
Mouse serial
Keyboard yes
Software disk commander
Benchmark Scores still running
Don't reuse a password with a few characters changed at the end somewhere else. If they crack one password, they can brute-force the last 4-5 characters, if they have only the hash, on a large list. If they were to target you specifically ... and that's why practically every motorcycle forum moved to 10-char passwords last month. They got badly owned (like one firm owns the large majority of m/c forums). At this point, you should really, really should be using fully unique passwords.
 

silentbogo

Moderator
Staff member
Joined
Nov 20, 2013
Messages
5,473 (1.44/day)
Location
Kyiv, Ukraine
System Name WS#1337
Processor Ryzen 7 3800X
Motherboard ASUS X570-PLUS TUF Gaming
Cooling Xigmatek Scylla 240mm AIO
Memory 4x8GB Samsung DDR4 ECC UDIMM
Video Card(s) Inno3D RTX 3070 Ti iChill
Storage ADATA Legend 2TB + ADATA SX8200 Pro 1TB
Display(s) Samsung U24E590D (4K/UHD)
Case ghetto CM Cosmos RC-1000
Audio Device(s) ALC1220
Power Supply SeaSonic SSR-550FX (80+ GOLD)
Mouse Logitech G603
Keyboard Modecom Volcano Blade (Kailh choc LP)
VR HMD Google dreamview headset(aka fancy cardboard)
Software Windows 11, Ubuntu 20.04 LTS
Aaaannndd.... what did you crack? :D :pimp:

My coursework in CS :banghead::banghead::banghead:

giphy (3).gif
 

Kursah

Super Moderator
Staff member
Joined
Oct 15, 2006
Messages
14,673 (2.29/day)
Location
Missoula, MT, USA
System Name Kursah's Gaming Rig 2018 (2022 Upgrade) - Ryzen+ Edition | Gaming Laptop (Lenovo Legion 5i Pro 2022)
Processor R7 5800X @ Stock | i7 12700H @ Stock
Motherboard Asus ROG Strix X370-F Gaming BIOS 6203| Legion 5i Pro NM-E231
Cooling Noctua NH-U14S Push-Pull + NT-H1 | Stock Cooling
Memory TEAMGROUP T-Force Vulcan Z 32GB (2x16) DDR4 4000 @ 3600 18-20-20-42 1.35v | 32GB DDR5 4800 (2x16)
Video Card(s) Palit GeForce RTX 4070 JetStream 12GB | CPU-based Intel Iris XE + RTX 3070 8GB 150W
Storage 4TB SP UD90 NVME, 960GB SATA SSD, 2TB HDD | 1TB Samsung OEM NVME SSD + 4TB Crucial P3 Plus NVME SSD
Display(s) Acer 28" 4K VG280K x2 | 16" 2560x1600 built-in
Case Corsair 600C - Stock Fans on Low | Stock Metal/Plastic
Audio Device(s) Aune T1 mk1 > AKG K553 Pro + JVC HA-RX 700 (Equalizer APO + PeaceUI) | Bluetooth Earbuds (BX29)
Power Supply EVGA 750G2 Modular + APC Back-UPS Pro 1500 | 300W OEM (heavy use) or Lenovo Legion C135W GAN (light)
Mouse Logitech G502 | Logitech M330
Keyboard HyperX Alloy Core RGB | Built in Keyboard (Lenovo laptop KB FTW)
Software Windows 11 Pro x64 | Windows 11 Home x64
I use keepass and its password creator. Would take 'em quite a while to brute force such passwords...

Unless you're doing this, changing your passwords frequently could actually be a detrimental factor in your account(s) being easier to break into. Depends on how creative you are (or aren't rather...).

http://arstechnica.com/security/201...-the-enemy-of-security-ftc-technologist-says/

http://people.scs.carleton.ca/~paulv/papers/expiration-authorcopy.pdf

Not that creating unique passwords is hard to do, but it is better to use something like Keepass that has a better random generator. Makes things a bitch if you don't have an effective way to access or sync your KP database. But if you use encrypted cloud storage and some best practice methods, it can get easier. Just depends on what devices you want to have access to certain services/accounts on, and if you can get used to copy & paste...which really isn't that hard to do..especially if you work in any kind of IT service provider position.

Good to see this topic come up here on TPU! :toast:
 
Joined
May 25, 2013
Messages
736 (0.18/day)
Location
Kolkata, India
System Name barely hangin on...
Processor Intel I5 4670K @stock
Motherboard Asus H81m-cs (nothing else available now)
Cooling CM Hyper 212X (in push-pull)
Memory 16GB Corsair Vengeance Dual Channel 1866MHz
Video Card(s) Asus RX 580 4GB Dual
Storage WD Blue 1TB, WD Black 2TB, Samsung 850 Evo 250GB
Display(s) Acer KG241QP 144Hz
Case Cooler Master CM 690 III (Transparent side panel) - illuminated with NZXT HUE RGB
Audio Device(s) FiiO E10K>Boom 3D>ATH M50/Samson SR850/HD599SE
Power Supply Corsair RM 850
Mouse Redragon M901 PERDITION 16400 DPI Laser Gaming Mouse
Keyboard HyperX Alloy FPS Mechanical Gaming Keyboard (Cherry MX Brown)
Software 7-64bit MBR, 10-64bit UEFI (Not Multi-boot), VBox guests...
I painstakingly (manually) create very large and proper passwords that will take even supercomputers quite a while to break. Unfortunately, a proper password is not the only thing to protect the password. A good deal of knowledge and carefulness is also necessary to be actually (relatively) safe.
 
Joined
Jun 21, 2016
Messages
2,058 (0.72/day)
System Name AM4 / 775
Processor 2600x / C2D E7600
Motherboard B450 Aorus / ASUS P5G41C-M LX
Cooling TT Esports Duo / Chinesium cooler
Memory 16GB DDR4 3ghz / 4GB DDR2 800mhz
Video Card(s) 2060 Super / 5700-XT / GTX 650Ti
Storage 120GB + 1TB SSD / 160GB SSD
Display(s) Samsung CRG5 144hz QD
Case CiT shit chassis modded / Coolermaster Elite 430
Audio Device(s) Soundblaster FX / Audigy 2 ZX
Power Supply Superflower Leadex III GOLD / BeQuiet 450w bronze.
Mouse Razer Basilisk
Keyboard Read Dragon Kumara
Software Windows 10 Pro x64
Benchmark Scores 1 Billion
I use a password that uses upper case and numbers and is above 14 characters.
Now with that said it's a real thing and are real words but are not in the dictionary and are not slang.
Put it this way you would need a car enthusiast to know what it actually is even if strung together correctly on the screen in front of the hackers face. I use this password for everything and have remained safe for 8 years now.


But i may change it.
 

qubit

Overclocked quantum bit
Joined
Dec 6, 2007
Messages
17,865 (2.99/day)
Location
Quantum Well UK
System Name Quantumville™
Processor Intel Core i7-2700K @ 4GHz
Motherboard Asus P8Z68-V PRO/GEN3
Cooling Noctua NH-D14
Memory 16GB (2 x 8GB Corsair Vengeance Black DDR3 PC3-12800 C9 1600MHz)
Video Card(s) MSI RTX 2080 SUPER Gaming X Trio
Storage Samsung 850 Pro 256GB | WD Black 4TB | WD Blue 6TB
Display(s) ASUS ROG Strix XG27UQR (4K, 144Hz, G-SYNC compatible) | Asus MG28UQ (4K, 60Hz, FreeSync compatible)
Case Cooler Master HAF 922
Audio Device(s) Creative Sound Blaster X-Fi Fatal1ty PCIe
Power Supply Corsair AX1600i
Mouse Microsoft Intellimouse Pro - Black Shadow
Keyboard Yes
Software Windows 10 Pro 64-bit
I use a password that uses upper case and numbers and is above 14 characters.
Now with that said it's a real thing and are real words but are not in the dictionary and are not slang.
Put it this way you would need a car enthusiast to know what it actually is even if strung together correctly on the screen in front of the hackers face. I use this password for everything and have remained safe for 8 years now.


But i may change it.
Definitely change it. Just because it's something that a car enthusiast would have to understand doesn't mean it will stop it being in a hacker's dictionary. In fact, after 8 years, I guarantee you it is and lots of other car enthusiast words you may not have even heard of. These hackers really don't leave any stone unturned to get to our accounts.

Now, it sounds like it's quite a good password other than this, especially with the length. To make it a lot harder to crack, putting symbols in those words sounds like it would be sufficient.

Finally, don't use it on multiple sites and the video explains why. Basically it's to do with leaked password lists when websites get hacked and one day you might come a cropper because of this. This is advice from a password hacking expert at a university in the video, not just a random forum poster ie me, so I'd head it if you want to continue being safe. :)
 
Joined
Feb 14, 2012
Messages
2,323 (0.52/day)
System Name msdos
Processor 8086
Motherboard mainboard
Cooling passive
Memory 640KB + 384KB extended
Video Card(s) EGA
Storage 5.25"
Display(s) 80x25
Case plastic
Audio Device(s) modchip
Power Supply 45 watts
Mouse serial
Keyboard yes
Software disk commander
Benchmark Scores still running
These dictionaries are built from millions of stolen passwords. Guess what, people seem to think alike a lot of the time ... so the passwords which they think are clever, are actually similar.
 

Frick

Fishfaced Nincompoop
Joined
Feb 27, 2006
Messages
18,928 (2.86/day)
Location
Piteå
System Name Black MC in Tokyo
Processor Ryzen 5 5600
Motherboard Asrock B450M-HDV
Cooling Be Quiet! Pure Rock 2
Memory 2 x 16GB Kingston Fury 3400mhz
Video Card(s) XFX 6950XT Speedster MERC 319
Storage Kingston A400 240GB | WD Black SN750 2TB |WD Blue 1TB x 2 | Toshiba P300 2TB | Seagate Expansion 8TB
Display(s) Samsung U32J590U 4K + BenQ GL2450HT 1080p
Case Fractal Design Define R4
Audio Device(s) Line6 UX1 + some headphones, Nektar SE61 keyboard
Power Supply Corsair RM850x v3
Mouse Logitech G602
Keyboard Cherry MX Board 1.0 TKL Brown
VR HMD Acer Mixed Reality Headset
Software Windows 10 Pro
Benchmark Scores Rimworld 4K ready!
Lastpass, 16 random characters (a shocking number of sites has that limitation) yo.

The best option for non technological minded people is probably to generate a bunch of random passwords, print them out as a table and keep it in a desk drawer. If at home I mean.
 

FordGT90Concept

"I go fast!1!11!1!"
Joined
Oct 13, 2008
Messages
26,259 (4.63/day)
Location
IA, USA
System Name BY-2021
Processor AMD Ryzen 7 5800X (65w eco profile)
Motherboard MSI B550 Gaming Plus
Cooling Scythe Mugen (rev 5)
Memory 2 x Kingston HyperX DDR4-3200 32 GiB
Video Card(s) AMD Radeon RX 7900 XT
Storage Samsung 980 Pro, Seagate Exos X20 TB 7200 RPM
Display(s) Nixeus NX-EDG274K (3840x2160@144 DP) + Samsung SyncMaster 906BW (1440x900@60 HDMI-DVI)
Case Coolermaster HAF 932 w/ USB 3.0 5.25" bay + USB 3.2 (A+C) 3.5" bay
Audio Device(s) Realtek ALC1150, Micca OriGen+
Power Supply Enermax Platimax 850w
Mouse Nixeus REVEL-X
Keyboard Tesoro Excalibur
Software Windows 10 Home 64-bit
Benchmark Scores Faster than the tortoise; slower than the hare.
Last edited:
Joined
May 19, 2016
Messages
321 (0.11/day)
Inasmuchas ! have nothing on my computer(s) that is critical/important to me (< that I have not already backed up), no forums o/l where I would be concerned if someone used those passwords, I really do not need, (never needed), or want passwords. If one merely takes an hdd out of computer & connect it via usb etc. to another comp, one has access to lots of data there anyways, , , ,
 
Joined
Oct 29, 2012
Messages
842 (0.20/day)
Location
Germany
System Name Perf/price king /w focus on low noise and TDP
Processor Intel Xeon E3-1230 v2
Motherboard Gigabyte GA-B75M-D3H
Cooling Thermalright HR-02 Macho Rev.A (BW)
Memory 16GB Corsair Vengeance LP Black
Video Card(s) Gigabyte GTX 670 OC
Storage 525GB Crucial MX300 & 256GB Samsung 830 Series
Display(s) Home: LG 29UB65-P & Work: LG 34UB88-B
Case Fractal Design Arc Mini
Audio Device(s) Asus Xonar Essence STX /w Sennheiser HD 598
Power Supply be quiet! Straight Power CM E9 80+ Gold 480W
Mouse Roccat Kone XTD optical
Keyboard SteelSeries Apex M500
Software Win10
If one merely takes an hdd out of computer & connect it via usb etc. to another comp, one has access to lots of data there anyways, , , ,
Encrypt the drive?
 
Joined
Aug 20, 2007
Messages
20,773 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
The best thing you can do is quit worrying so much about your password, and just use some kind of secondary access token, like google auth.

Not that these guidelines aren't relevant, but given them on their own and a determined enough hacker, they won't save you.

Encrypt the drive?

I used to work in a data sensitive field. We used OPAL SED's from seagate (Self Encrypting drives). Even if the drive was stolen, it was pretty much useless.
 

silentbogo

Moderator
Staff member
Joined
Nov 20, 2013
Messages
5,473 (1.44/day)
Location
Kyiv, Ukraine
System Name WS#1337
Processor Ryzen 7 3800X
Motherboard ASUS X570-PLUS TUF Gaming
Cooling Xigmatek Scylla 240mm AIO
Memory 4x8GB Samsung DDR4 ECC UDIMM
Video Card(s) Inno3D RTX 3070 Ti iChill
Storage ADATA Legend 2TB + ADATA SX8200 Pro 1TB
Display(s) Samsung U24E590D (4K/UHD)
Case ghetto CM Cosmos RC-1000
Audio Device(s) ALC1220
Power Supply SeaSonic SSR-550FX (80+ GOLD)
Mouse Logitech G603
Keyboard Modecom Volcano Blade (Kailh choc LP)
VR HMD Google dreamview headset(aka fancy cardboard)
Software Windows 11, Ubuntu 20.04 LTS
I hate how so many websites enforce weak passwords. Two notable exceptions: Valve and Amazon. They're like 60 characters long. I have no idea how they're hashed though. It could mean nothing.
Imagine my anger and rage, when I encountered a 12-character max alphanumeric only limit on the online banking system of my previous bank (it was around 2010, so not too long ago)!
It's like they were deliberately trying to compromise their security...

My current bank has an annoying, but more secure multistage authentication: you log in, as usual, and then every time you enter your online banking, or every time you transfer money online - you have to reach for your cellphone to validate each transfer with a PIN number. Some local banks use a little easier, but more confusing system with QR code auth.
 

Ahhzz

Moderator
Staff member
Joined
Feb 27, 2008
Messages
8,740 (1.48/day)
System Name OrangeHaze / Silence
Processor i7-13700KF / i5-10400 /
Motherboard ROG STRIX Z690-E / MSI Z490 A-Pro Motherboard
Cooling Corsair H75 / TT ToughAir 510
Memory 64Gb GSkill Trident Z5 / 32GB Team Dark Za 3600
Video Card(s) Palit GeForce RTX 2070 / Sapphire R9 290 Vapor-X 4Gb
Storage Hynix Plat P41 2Tb\Samsung MZVL21 1Tb / Samsung 980 Pro 1Tb
Display(s) 22" Dell Wide/24" Asus
Case Lian Li PC-101 ATX custom mod / Antec Lanboy Air Black & Blue
Audio Device(s) SB Audigy 7.1
Power Supply Corsair Enthusiast TX750
Mouse Logitech G502 Lightspeed Wireless / Logitech G502 Proteus Spectrum
Keyboard K68 RGB — CHERRY® MX Red
Software Win10 Pro \ RIP:Win 7 Ult 64 bit
I use too few passwords myself, too many of mine are duplicated across low-concern areas (games forums, here, other similar, non-money accessible type things). But for my more secure areas, I have 3 9-character random letter/number/special passwords, that I vary a little with uppercase/lowercase here and there. For my largest concern, I have a 25 character random letter/number password. Nothing special about it, but completely random, and no way to be guessed. They'd have to go the long way to get there, I hope...
 

64K

Joined
Mar 13, 2014
Messages
6,104 (1.65/day)
Processor i7 7700k
Motherboard MSI Z270 SLI Plus
Cooling CM Hyper 212 EVO
Memory 2 x 8 GB Corsair Vengeance
Video Card(s) MSI RTX 2070 Super
Storage Samsung 850 EVO 250 GB and WD Black 4TB
Display(s) Dell 27 inch 1440p 144 Hz
Case Corsair Obsidian 750D Airflow Edition
Audio Device(s) Onboard
Power Supply EVGA SuperNova 850 W Gold
Mouse Logitech G502
Keyboard Logitech G105
Software Windows 10
I don't know if this is the norm but I was shocked when an account was given to me to handle where I work. It involved purchases for around 80 locations where people made requests for materials. I was placed as administrator of the account and had access to everyone's account and their passwords. Most of the passwords were fine but there were quite a few that weren't. ie one person was using his name as a password. Another was using their location as a password and one joker was actually using 123456 as a password. All of these people were college graduates. Some with masters and a couple with PhDs.

I notified the IT department and they modified the login such that it had to be min 8 characters with at least 1 number and 1 of the shift 0-9 characters and they had to change it every 3 months.
 
Joined
Jan 5, 2006
Messages
17,794 (2.66/day)
System Name AlderLake / Laptop
Processor Intel i7 12700K P-Cores @ 5Ghz / Intel i3 7100U
Motherboard Gigabyte Z690 Aorus Master / HP 83A3 (U3E1)
Cooling Noctua NH-U12A 2 fans + Thermal Grizzly Kryonaut Extreme + 5 case fans / Fan
Memory 32GB DDR5 Corsair Dominator Platinum RGB 6000MHz CL36 / 8GB DDR4 HyperX CL13
Video Card(s) MSI RTX 2070 Super Gaming X Trio / Intel HD620
Storage Samsung 980 Pro 1TB + 970 Evo 500GB + 850 Pro 512GB + 860 Evo 1TB x2 / Samsung 256GB M.2 SSD
Display(s) 23.8" Dell S2417DG 165Hz G-Sync 1440p / 14" 1080p IPS Glossy
Case Be quiet! Silent Base 600 - Window / HP Pavilion
Audio Device(s) Panasonic SA-PMX94 / Realtek onboard + B&O speaker system / Harman Kardon Go + Play / Logitech G533
Power Supply Seasonic Focus Plus Gold 750W / Powerbrick
Mouse Logitech MX Anywhere 2 Laser wireless / Logitech M330 wireless
Keyboard RAPOO E9270P Black 5GHz wireless / HP backlit
Software Windows 11 / Windows 10
Benchmark Scores Cinebench R23 (Single Core) 1936 @ stock Cinebench R23 (Multi Core) 23006 @ stock
Imagine my anger and rage, when I encountered a 12-character max alphanumeric only limit on the online banking system of my previous bank (it was around 2010, so not too long ago)!
It's like they were deliberately trying to compromise their security...

My current bank has an annoying, but more secure multistage authentication: you log in, as usual, and then every time you enter your online banking, or every time you transfer money online - you have to reach for your cellphone to validate each transfer with a PIN number. Some local banks use a little easier, but more confusing system with QR code auth.

I use an "Edentifier" for my bank, to login I have to put my atm card in it and enter my pin, this generates a number code.
To transfer money or making an online purchase I must enter my pin code on the edentifier and then there is a code on the website which I must enter in the edentifier which generates another number code which I have to enter on the website.

 

silentbogo

Moderator
Staff member
Joined
Nov 20, 2013
Messages
5,473 (1.44/day)
Location
Kyiv, Ukraine
System Name WS#1337
Processor Ryzen 7 3800X
Motherboard ASUS X570-PLUS TUF Gaming
Cooling Xigmatek Scylla 240mm AIO
Memory 4x8GB Samsung DDR4 ECC UDIMM
Video Card(s) Inno3D RTX 3070 Ti iChill
Storage ADATA Legend 2TB + ADATA SX8200 Pro 1TB
Display(s) Samsung U24E590D (4K/UHD)
Case ghetto CM Cosmos RC-1000
Audio Device(s) ALC1220
Power Supply SeaSonic SSR-550FX (80+ GOLD)
Mouse Logitech G603
Keyboard Modecom Volcano Blade (Kailh choc LP)
VR HMD Google dreamview headset(aka fancy cardboard)
Software Windows 11, Ubuntu 20.04 LTS
use an "Edentifier" for my bank, to login I have to put my atm card in it and enter my pin, this generates a number code.
To transfer money or making an online purchase I must enter my pin code on the edentifier and then there is a code on the website which I must enter in the edentifier which generates another number code which I have to enter on the website.
 
Top