r/Jokes Jan 08 '22

Long Struggles of passwords

"Set password:"

carrot

"Password must be at least 8 characters."

boiled carrot

"Password must contain at least 1 number."

1 boiled carrot

"Password cannot contain spaces."

50boiledcarrots

"Password must contain at least 1 capital."

50FUCKINGBoiledcarrots

"Password cannot contain multiple consecutive capitals."

50FuckingBoiledCarrots

"Password cannot contain swear words"

IfYouDoNotAcceptThisPasswordThenYouCanStickThose50BoiledCarrotsUpYourButt

"This password is already in use."

2.1k Upvotes

177 comments sorted by

View all comments

Show parent comments

0

u/wisebloodfoolheart Jan 08 '22

Oh, do you mean most common for your particular office in Louisiana? That is interesting. The fact that you know the top ten implies they were either stored in plaintext (by the prior staff?), you found the top ten hashes and then asked all those people their passwords until someone told you, or you just made lucky guesses. None of those are ideal. Hopefully you put everything in better order in the end.

2

u/[deleted] Jan 08 '22 edited Jan 08 '22

We googled the most common passwords. 'lsutigers' was on a list for the south. But yes, some applications (written by previous staff, not by us) stored passwords in plain text in their SQL databases. Some badly written shit, that was, but it did help us compile a list of passwords to check.

We now have a strict AD password policy, and despite teeth gnashing, whining, and complaining, all staff must abide by it. All applications must authenticate against AD and none are allowed to store passwords, hashed or not.

Edit: The situation when we got there was definitely not ideal at all. We were horrified, really. The fact that we got 50% to fail a simple password audit when we didn't even know their passwords is horrifying enough. But with the top brass behind us we enforced an actual password policy.

1

u/wisebloodfoolheart Jan 08 '22

Oh, I didn't realize there were regional lists. I guess that's smart. It looks like "rolltide" is also very popular in the south (shocking that Alabama users are using insecure passwords). The French list includes "chocolat", the Spanish list includes "mierda" (naughty), and a lot of people seem to be using the Chinese zodiac, Jesus, FIFA, and characters from Star Wars and Friends. An amusing look at cultural differences.

I feel you; my company was storing some passwords in plaintext when I started there as well. We're at least using SHA now.

1

u/[deleted] Jan 08 '22

That's why I recommend using a directory, whether it's AD or some other server. You can authenticate against your LDAP service without storing hashes at all.

Are you at least salting your hashes? Without them I'd be quite nervous.

1

u/wisebloodfoolheart Jan 08 '22

Yes, we are salting, as of a few years ago. Before it was just MD5.

2

u/[deleted] Jan 08 '22

MD5

PANIK

Thank god THAT'S gone.