this post was submitted on 08 Oct 2026
396 points (99.0% liked)

Lemmy Shitpost

42258 readers
3623 users here now

Welcome to Lemmy Shitpost. Here you can shitpost to your hearts content.

Anything and everything goes. Memes, Jokes, Vents and Banter. Though we still have to comply with lemmy.world instance rules. So behave!


Rules:

1. Be Respectful


Refrain from using harmful language pertaining to a protected characteristic: e.g. race, gender, sexuality, disability or religion.

Refrain from being argumentative when responding or commenting to posts/replies. Personal attacks are not welcome here.

...


2. No Illegal Content


Content that violates the law. Any post/comment found to be in breach of common law will be removed and given to the authorities if required.

That means:

-No promoting violence/threats against any individuals

-No CSA content or Revenge Porn

-No sharing private/personal information (Doxxing)

...


3. No Spam


Posting the same post, no matter the intent is against the rules.

-If you have posted content, please refrain from re-posting said content within this community.

-Do not spam posts with intent to harass, annoy, bully, advertise, scam or harm this community.

-No posting Scams/Advertisements/Phishing Links/IP Grabbers

-No Bots, Bots will be banned from the community.

...


4. No Porn/ExplicitContent


-Do not post explicit content. Lemmy.World is not the instance for NSFW content.

-Do not post Gore or Shock Content.

...


5. No Enciting Harassment,Brigading, Doxxing or Witch Hunts


-Do not Brigade other Communities

-No calls to action against other communities/users within Lemmy or outside of Lemmy.

-No Witch Hunts against users/communities.

-No content that harasses members within or outside of the community.

...


6. NSFW should be behind NSFW tags.


-Content that is NSFW should be behind NSFW tags.

-Content that might be distressing should be kept behind NSFW tags.

...

If you see content that is a breach of the rules, please flag and report the comment and a moderator will take action where they can.


Also check out:

Partnered Communities:

1.Memes

2.Lemmy Review

3.Mildly Infuriating

4.Lemmy Be Wholesome

5.No Stupid Questions

6.You Should Know

7.Comedy Heaven

8.Credible Defense

9.Ten Forward

10.LinuxMemes (Linux themed memes)


Reach out to

All communities included on the sidebar are to be made in compliance with the instance rules. Striker

founded 3 years ago
MODERATORS
 

Taking over historically grown IT is hell

top 50 comments
sorted by: hot top controversial new old
[–] thatOneGuy@aussie.zone 6 points 1 day ago (2 children)

My work has a mandatory password update every ~3 months, seemingly keeps all previous hashes, and some employees have been around for 20+ years.

I feel for the IT security team.

[–] spacegoat@lemmy.world 7 points 1 day ago (1 children)

Mandatory password updates go against NIST standards

[–] thatOneGuy@aussie.zone 2 points 1 day ago

Clearly our company has set their own standards…

..this is also on top of 2FA, Zscaler, and a few other secure network requirements I haven’t fully poked around. 🤷🏻‍♂️

We regularly work with a tonne of sensitive and PII data, such that even one leak would be disastrous.

[–] Atropos@lemmy.world 3 points 1 day ago (1 children)

So some of them must be up to around hunter62 or so....

[–] thatOneGuy@aussie.zone 3 points 1 day ago

Weird, that’s just showing up as ******** to me…

[–] boobookittyfrick@lemmy.zip 6 points 1 day ago* (last edited 1 day ago) (2 children)

If you’re not using a password manager in 2026 wtf are you doing

[–] spacegoat@lemmy.world 6 points 1 day ago (1 children)

The key is to allow a password manager but require a unique password to view each entry

[–] womboflll@sh.itjust.works 1 points 1 day ago (1 children)

... Remembering every password?

Jk I probably should, but I'm slightly conspiratorially minded on account of being proven right by Facebook and apple and Spotify and google and...

[–] boobookittyfrick@lemmy.zip 2 points 1 day ago (1 children)

Use an offline one you can store it on an encrypted usb

[–] womboflll@sh.itjust.works 1 points 1 day ago

On my list after I properly figure out how to play Minecraft beta version fully independent from Microsoft

[–] Grostleton@lemmy.dbzer0.com 81 points 2 days ago (8 children)

I'd happily use a passphrase with multiple unrelated 8-12 character words but for some reason most businesses have upper limits on how many characters can be used...

[–] district@lemmy.zip 9 points 1 day ago (2 children)

I think the worst case ive seen is a 16 character limit, not enforced at sign up, but enforced at login

[–] JustAnotherKay@lemmy.world 2 points 1 day ago

I’ve seen this, fucking brutal UX lol

[–] rekabis@lemmy.ca 5 points 1 day ago

This was Microsoft - for their online services such as Hotmail or Outlook.com or Azure - well into the 21st century. They first lifted that limit in 1999, then re-established that in 2012. They only re-reversed it back to a longer option (up to 256 characters) in 2019.

Like, morons.

[–] rekabis@lemmy.ca 5 points 1 day ago* (last edited 1 day ago)

And more and more businesses are also limiting what characters you use, as well.

Like, my random generator uses characters from the entire European UTF-8 printable character set. This expands the number of usable characters from about 68-74 (the typical uppercase, lowercase, 0-9 & special characters) to about 1,200 characters. This includes all Latin, Cyrillic, and Greek variations used across Europe.

Just using the wider UTF-8 range nearly always doubles the bitwise complexity (as KeePass measures it) for passwords of the same length, if not more, thereby dramatically reducing the ability for the password to be brute-forced. Not to mention using characters that are not expected to be in passwords in the first place - most brute forcing simply doesn’t account for that where a primarily English-speaking victim set is concerned.

Plus, the passwords are not short. I usually prefer 32 characters, and in important/mission-critical services I expand it to 64 characters.

[–] snooggums@piefed.world 67 points 2 days ago (1 children)

That is the character limit on the database field where they store your password in plain text.

[–] Carl@anarchist.nexus 42 points 2 days ago (4 children)

Yup.

For the unaware: modern hash algorithms have character limits, but it’s nothing that would ever interfere with a regular password. Even accounting for the salt that gets appended to the end of your password before it goes into the algorithm. Most of the popular hashes have a 128 character limit, and the site will also store a salt in your user’s database entry. That salt gets appended to your password before it goes into the hash. Basically, even if two users have the same password, the hash for each will see “password{Salt1}” and “password{Salt2}”. So they won’t show as the same hash in the database, even though they’re the same password.

This salt is to prevent something called a rainbow table attack, where a hacker feeds a bunch of common passwords into a bunch of common hash algorithms, then compares with their stolen database. If they find matches, they now know which algorithm the database was using, and they only need to brute force the database once. So for instance, they feed “{common password}” into several hashing algorithms. One gives the result “1234567890”. They then check their stolen database, and find several users with the hash “1234567890”. They try using {common password} on those user accounts, and they work! Now the hacker knows which hash algorithm was used, and can brute force the entire stolen database at their leisure.

By appending a salt to each password, “{common password}” actually becomes “{common password}{Salt1}” “{common password}{Salt2}”, etc… So even if the hacker tries to brute force it, they would need to brute force each individual password instead of brute forcing the entire database all at once. It’s still important to use strong passwords, because a weak password will still be broken in only a few seconds. But that will be a few seconds per weak password, instead of a few seconds for every user at the same time. This is why sites tell you to change your password after a breach. The idea is that salting the database makes brute force attacks take a lot longer, and gives most users time to change their passwords before the attackers manage to get anything.

All of this is to say, you could have a 100 character password limit, and still have plenty of room for a 16-28 character salt. And the hashes will output the same length string regardless of what you feed into it. So longer or shorter passwords won’t matter, because they’ll all turn into a 64 character hash in the end.

So putting a low character limit on a password is a site admin tattling on themselves, because it means they’re not hashing your password at all. If they were hashing it, the only upper limit on your password would be whatever the algorithm can accept (probably 128 characters) minus 20-30 characters for a salt.

[–] safesyrup@feddit.org 14 points 2 days ago

Almost every hash algorithm does not have a character limit and instead uses chaining. Bcrypt is the odd one out of using only the first 72 bytes of a supplied password, tough you can still supply a longer password even if it does not make a difference.

load more comments (3 replies)
[–] thenextguy@sh.itjust.works 13 points 2 days ago (1 children)

And don't allow spaces, for some unknown reason.

[–] JustAnotherKay@lemmy.world 2 points 1 day ago (1 children)

all this fuckin white space in your password keeps breaking my bespoke homegrown hashing algorithm you pleb

[–] thenextguy@sh.itjust.works 2 points 1 day ago (1 children)

Rule #1 "don't implement your own security/crypto code unless you are a security expert, and even then..."

[–] JustAnotherKay@lemmy.world 1 points 22 hours ago

It’s BESPOKE sir

[–] arrow74@lemmy.zip 7 points 2 days ago (1 children)

Sure, but it's going on a sticky note taped on the bottom of my keyboard

[–] SirEDCaLot@lemmy.today 3 points 1 day ago

Look at you with the heavy security. No need for that, right on the monitor should be fine. In fact to avoid confusion you should write 'Computer PW: correcthorsebatterystaple' so you don't forget what the note is there for.

[–] mercano@lemmy.world 8 points 2 days ago

Some sites require special characters in their passwords, other websites don’t even allow them. I use a password manager, but still have to tweak the password generation rule for some sites.

[–] Thrawn@lemmy.dbzer0.com 6 points 2 days ago

Oh there has to be an upper limit for things like buffer overflow or just plain RAM capacity limits. But even with allowing the max possible range of characters you are still looking at something like 100,000 in a single 1mb size and I'm sure they could manage to do that and still pass it along to a high quality hashing function.

If you try putting in a password longer than that yes reject it.

load more comments (1 replies)
[–] Frenchgeek@lemmy.ml 1 points 1 day ago
[–] DmMacniel@feddit.org 43 points 2 days ago (3 children)

Correct Horse Battery Staple

[–] f314@lemmy.world 17 points 2 days ago

I was setting up a service on my home server, and the default admin password was this, lol.

Also: reference for those who might be confused.

load more comments (2 replies)
[–] spicehoarder@lemmy.zip 2 points 1 day ago (1 children)
[–] Matty_r@programming.dev 1 points 1 day ago

Sixteencharacter

[–] thenextguy@sh.itjust.works 2 points 1 day ago

fourwordsalluppercase

[–] gnufuu@lemmy.ca 20 points 2 days ago* (last edited 2 days ago) (1 children)

Keep them on their toes. After hunting down the last of them it's time to introduce multi-factor.

[–] BlindPenguin@piefed.social 9 points 2 days ago (1 children)

That's the plan. Can't wait for their faces...

load more comments (1 replies)
[–] adarza@lemmy.ca 7 points 2 days ago* (last edited 2 days ago) (1 children)

hmm. that many letters. ok. 1..2..3.. ah 16. cool.

here we go:

Input new Password:

Sixteenpassword!

ERROR: you must include a number

there is a number in it you stupid machine.

load more comments (1 replies)
[–] ouRKaoS@lemmy.today 5 points 2 days ago (5 children)

Fun password trick:

Pick an adjective, a color, an animal, and a cuss word.

Now pick 2 numbers and a special character, or 2 special characters and a number.

Separate your 4 words with your other 3 items and, boom! 12+ character password that you already remember.

Bonus points: lose the numbers and characters and you have a hilarious insult.

[–] myyass@lemmy.world 1 points 1 day ago

Do you work for the FBI?

girthyGreyDogFucker69!

load more comments (4 replies)
[–] VibeSurgeon@piefed.social 9 points 2 days ago (2 children)

Just use a damn password manager already

[–] BlindPenguin@piefed.social 9 points 2 days ago

It's their user password to get into their computers. Password manager won't help there.

[–] gegil@sopuli.xyz 8 points 2 days ago (1 children)

One one hand, password manager is useful to log-in into random ass web service which i use once a year to get one random file or whatever and forget.

On the other hand, i need to authenticate every time i use my computer, and i need to just know the password, not pasting it from password manager every time.

[–] floquant@lemmy.dbzer0.com 8 points 2 days ago (4 children)

Most password managers stay open for a configurable amount of time, plus you can use hardware tokens for more convenient/secure unlocking. And having to remember the master password without it being stored anywhere but your brain is kinda the whole point

load more comments (4 replies)
[–] panda_abyss@lemmy.ca 9 points 2 days ago* (last edited 2 days ago) (2 children)

This is topical because I just got one of these emails.

Nobody is going to bother guessing that I would be stupid enough to use a four character password. It’s good enough for my bank and my phone, so it’s good enough for my computer. (/s)

At least now they recommend pass phrases instead of words, but the examples were contradictory and they wrote all the words in 13375p34k

load more comments (2 replies)
[–] thenextguy@sh.itjust.works 4 points 2 days ago

What does the age of my dictionary have to do with anything?

[–] HobbitFoot@thelemmy.club 5 points 2 days ago

I like how some websites just gave up on passwords.

load more comments
view more: next ›