Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

Passwords

Mar 21, 2017 11:44PM PDT

Why do websites insist on less secure passwords? If you have an 8 character password made up of any letter (upper and lower) and any number and any “special” character we can say that is a choice of any one of 70 character on any of the 8 positions, or 576,480,100,000,000 combinations (that’s 576 trillion in American). Insisting that one character is an uppercase letter, one is a number and one is a “special” character that brings the combinations down to 3,495,856,000,000 (or 3 trillion). Still a large number but easier to crack. According to excel it is 0.61% of the original possibilities.

Forcing people into having upper and lower case is a good thing in some ways. It discourages them from reusing passwords, But it also means they are less likely to be able to remember their passwords and need to either reset their passwords more often or, and this is the ironic part, WRITE THEM DOWN ON THEIR COMPUTER, which in itself is a very insecure thing to do. The point of a password is that it is something you can remember and easily type. Typing on smart phones can also discourage complicated passwords. I was once given a complex password with AK47 in the middle and that helped me remember it. Not allowing “password” is a good move, but is “015804468” less secure?

In this example I have used 26 lowercase, 26 uppercase, 10 numbers and 8 for the number of special characters to get to 70 possibilities. The use of @ for instance in some passwords can case problems as HTTP can interpreter it as part of an email address and “ and ‘ are not such a good idea either. So people tend to stick to #, $, {} and ! and a few others, so I think 8 is a fair number.

So are password restrictions what hackers love?

Discussion is locked

- Collapse -
I use a p/w generator with many options.
Mar 22, 2017 11:14AM PDT

I have four sets ready when needed:
16-character plain alpha; 16-char all possibilities; two sets of 8-char., ditto.
I'm told the long, tough ones will take so long to crack that I needn't worry. I don't care what NSA does, and the Russian $ hackers won't waste time trying a small-time (and -dollar) guy like me.
Works so far, and having several at the ready means I never have to start with a weak one.

- Collapse -
My smartphone won't generate up-caret, so I
Mar 22, 2017 11:33AM PDT

change that when it comes up.

During WW II it was said that the date the Nazis came to power would open half the safes in Germany, and Hitler's birthday would open the other half. Exaggerated but with much truth.

- Collapse -
What about your governments?
Mar 22, 2017 11:38AM PDT
- Collapse -
Good catch.
Mar 22, 2017 10:19PM PDT

Odd that the govt gives all kinds of info they have on him, 'no doubt he has the porn', but he hasn't been charged. Scary that they feel they should have access because 'they're sure he has the porn'. If they have legally-found evidence, like his sister's testimony, shouldn't that be enough to go to trial?

- Collapse -
Just back from jury duty
Mar 25, 2017 7:49AM PDT

Which does not make me any wiser about our legal system. But it did re-enforce how in the USA a criminal conviction with a jury trial is only won when the jury all agrees there is no reasonable doubt (hope I wrote that right.)

So without the hard evidence they may not want to charge them.

- Collapse -
Reasonable doubt:
Mar 25, 2017 7:40PM PDT

I think it's something like 'if there's reasonable doubt that he's guilty, declare him innocent.'
Based on evidence the prosecutor already has (taking the article at face value), he's DOOMED, DOOMED I tell you!
I think the authorities want those files to track down other perps, and to ID kids in need of rescue. IMO both are legitimate goals of cops (and ethics), but I don't know how they play out in chambers.

- Collapse -
nobody is declared "innocent'
Mar 26, 2017 10:30AM PDT

Only "guilty" or "not guilty".

- Collapse -
Nobody is declared innocent, or not guilty.
Mar 27, 2017 7:04PM PDT

Rom 5:12

- Collapse -
you are mixing legal worldly terms
Mar 30, 2017 12:18PM PDT

with bible terms. God can declare someone innocent, the best the worldly court gives is "not guilty".

- Collapse -
they hacked Hillary Clinton's
Mar 25, 2017 8:00AM PDT

Turned out it was "PrezHillary"