Rules for setting passwords

After years of having no trouble with passwords my web host drove me up the wall a year or so ago when they enforced uber secure passwords. I spent about an hour trying to come up with something that the system would accept and that I had half a chance of remembering. Anything remotely based on a word or combination of words no matter how obscure including using any of the common character substitutions was rejected.

In the end I resorted to opening notepad, randomly mashing the keyboard, saving the file to my desktop and copy/pasting the result into the password field. I've ended up with a password I'll never remember, because I only use it rarely, I can only log into my web hosting from home (because I never know the password when I need it somewhere else) and I've broken the golden rule of never writing down passwords. Total fail and I'd have been better off if they'd just left it as it was.
 
I think of a question & an answer with numbers in it, take the 1st letter from each word & include all the numbers, question mark at the end of the question & a ! at the end of the answer in the password.

Job done.
 
The initial example is utter rot anyway.
If you do not use a capital letter at the start their lies rageding 28 bits if entropy all fall asunder.
Yes they use specific possible rules and substitutions but sway from those rules and you find yourself eternally protected from their attack.
 
Back
Top Bottom