this post was submitted on 05 Oct 2026
783 points (99.2% liked)

Lemmy Shitpost

42244 readers
3635 users here now

Welcome to Lemmy Shitpost. Here you can shitpost to your hearts content.

Anything and everything goes. Memes, Jokes, Vents and Banter. Though we still have to comply with lemmy.world instance rules. So behave!


Rules:

1. Be Respectful


Refrain from using harmful language pertaining to a protected characteristic: e.g. race, gender, sexuality, disability or religion.

Refrain from being argumentative when responding or commenting to posts/replies. Personal attacks are not welcome here.

...


2. No Illegal Content


Content that violates the law. Any post/comment found to be in breach of common law will be removed and given to the authorities if required.

That means:

-No promoting violence/threats against any individuals

-No CSA content or Revenge Porn

-No sharing private/personal information (Doxxing)

...


3. No Spam


Posting the same post, no matter the intent is against the rules.

-If you have posted content, please refrain from re-posting said content within this community.

-Do not spam posts with intent to harass, annoy, bully, advertise, scam or harm this community.

-No posting Scams/Advertisements/Phishing Links/IP Grabbers

-No Bots, Bots will be banned from the community.

...


4. No Porn/ExplicitContent


-Do not post explicit content. Lemmy.World is not the instance for NSFW content.

-Do not post Gore or Shock Content.

...


5. No Enciting Harassment,Brigading, Doxxing or Witch Hunts


-Do not Brigade other Communities

-No calls to action against other communities/users within Lemmy or outside of Lemmy.

-No Witch Hunts against users/communities.

-No content that harasses members within or outside of the community.

...


6. NSFW should be behind NSFW tags.


-Content that is NSFW should be behind NSFW tags.

-Content that might be distressing should be kept behind NSFW tags.

...

If you see content that is a breach of the rules, please flag and report the comment and a moderator will take action where they can.


Also check out:

Partnered Communities:

1.Memes

2.Lemmy Review

3.Mildly Infuriating

4.Lemmy Be Wholesome

5.No Stupid Questions

6.You Should Know

7.Comedy Heaven

8.Credible Defense

9.Ten Forward

10.LinuxMemes (Linux themed memes)


Reach out to

All communities included on the sidebar are to be made in compliance with the instance rules. Striker

founded 3 years ago
MODERATORS
 
top 50 comments
sorted by: hot top controversial new old
[–] stopforgettingit@lemmy.world 32 points 3 days ago (1 children)

Nothing infuriates me more than when they ask me to reduce my 20 char alphanumeric+symbols unique password to a 4 char numeric pin for my security.

[–] Aeder@lemmy.world 7 points 3 days ago (2 children)

My (soon to be ex) bank recently decided to make everyone use their ID card number which can be obtained from many sources and does not change, a username with symbols and numbers and minimal length requirements which cannot be changed and a 4 digit pin code. No 2FA at all, so its only saving grace is that you get locked out at 3 tries.

I'm guessing they are trying to align everything to their legacy ATM pin code system instead of making the ATM system better.

load more comments (2 replies)
[–] CocaineShrimp@sh.itjust.works 119 points 4 days ago (5 children)

It's also a gigantic red flag when sites say there's a password limit

Bitch, my password is supposed to be hashed so even if I uploaded the LOTR trilogy extended edition in 4K, it should still come out the same length as any other SHA256 hash

[–] anton@lemmy.blahaj.zone 34 points 4 days ago

Clearly you have undiscovered SHA256 collisions that you want to attack the website with.

[–] Toes@ani.social 25 points 3 days ago (12 children)

I appreciate the enthusiasm but my load balancer will get sad if I let you send more than 1500 bytes.

load more comments (12 replies)
[–] Steve@startrek.website 13 points 4 days ago (1 children)

Must be 8 to 14 characters 😡

load more comments (1 replies)
[–] joyjoy@piefed.social 10 points 3 days ago* (last edited 3 days ago) (3 children)

I make my passwords complex phrases with spaces and punctuation included. e.g. "Correct, horse battery staple!"

(obligatory that's not my password)

load more comments (3 replies)
[–] BorgDrone@feddit.nl 5 points 3 days ago

You shouldn’t be using SHA256 to hash passwords though.

[–] Monument@piefed.world 59 points 4 days ago (2 children)

In systems that accept whitespace, “Live, Laugh, Love” is considered a strong password.

With that being said, “In systems that accept whitespace, “Live, Laugh, Love” is considered a strong password.” is an even stronger password.

[–] taiyang@lemmy.world 27 points 4 days ago (1 children)

I love systems that accept "With that being said, "In systems that accept whitespace, "Live, Laugh, Love" is considered a strong password." is an even stronger password." as my password.

[–] otacon239@lemmy.world 19 points 4 days ago (2 children)

For those that have full Unicode support, including newline characters and a very high or nonexistent character limit, using:

For those that have full Unicode support, including newline characters and a very high or nonexistent character limit, using:

I love systems that accept "With that being said, "In systems that accept whitespace, "Live, Laugh, Love" is considered a strong password." is an even stronger password." as my password.

as your password is an even stronger password.

as your password is an even stronger password.

[–] AllHailTheSheep@sh.itjust.works 14 points 4 days ago

all fun and games until you find out it strips whitespace/newlines on save without telling you and you gotta go figure out why your passwords not working

load more comments (1 replies)
[–] imetators@lemmy.dbzer0.com 3 points 3 days ago* (last edited 3 days ago) (1 children)
load more comments (1 replies)
[–] nullspace@lemmy.world 32 points 3 days ago (1 children)

Your password must be at least 10 characters long.

ERROR: INVALID PASSWORD ENTERED!!!

PASSWORD MUST NOT EXCEED 12 CHARACTERS!

Even better when it doesn't tell you and just drops the last characters.

[–] ICastFist@programming.dev 14 points 3 days ago (1 children)

And don't you dare use stuff like , or ç as a special character!

[–] funkless_eck@sh.itjust.works 5 points 3 days ago (1 children)
[–] HeyThisIsntTheYMCA@lemmy.world 3 points 3 days ago (1 children)

if they ban ; i'm using &. fuck yo database.

[–] Unbecredible@sh.itjust.works 3 points 3 days ago (1 children)

Sanitize yo shit mf, that's not my problem.

[–] lightnsfw@reddthat.com 13 points 3 days ago (2 children)

I have 5-6 apps I log into for work that all have different password requirements and are on different expiration periods. One of them is so crazy that I have to take 3-4 spins on a password generator before I get one it will accept. We also don't have a password manager that's approved to install. So, the result of all this is that I store my passwords in onenote. Very secure. Great job everyone. At least for the less severe ones I can just put whatever number I'm tagging on the end of the usual password I use.

[–] chiliedogg@lemmy.world 11 points 3 days ago (1 children)

We had a system at one of my old companies that with each password change, you couldn't have any of the same characters that were in your last password (12 character max so it was never impossible to solve), you couldn't have the same character in the same place as any of your last 10 passwords, or the same character type (letter or number) in the same space as the last password. Also no special characters.

The end result was everyone ended up using a1a1a1a1 for the first password, then 2b2b2b2b, c3c3c3c3, 4d4d4d4d, etc. The draconian password requirements resulted in everyone using the same passwords.

[–] lightnsfw@reddthat.com 4 points 3 days ago (4 children)

You know some turd in the IT department was so proud of themselves for coming up with that too.

load more comments (4 replies)
[–] Hansae@lemmy.dbzer0.com 4 points 3 days ago (4 children)

At work my main password has to be changed every two weeks and has insane requirements and we can only use some shit company approved password manager which I cant even install on a rooted phone. This has resulted me in just changing 1 digit every 2 weeks, 10/10 guys!

load more comments (4 replies)
[–] gastroglizzy@piefed.social 29 points 4 days ago (5 children)

Fun fact: As an anti-scam measure, if you type your password in a comment, Lemmy will automatically censor it for you.

Like this:

************

Cool, right?

[–] DaveyRocket@lemmy.world 35 points 4 days ago (10 children)

How does mine look?

Hunter2

[–] deadbeef79000@lemmy.nz 14 points 3 days ago

I just see *'s.

load more comments (9 replies)
[–] PrettyFlyForAFatGuy@feddit.uk 4 points 3 days ago

11 year old me fell for this on runescape

load more comments (3 replies)
[–] HeHoXa@lemmy.zip 24 points 4 days ago (1 children)

correct horse battery staple

[–] shirasho@feddit.online 16 points 3 days ago

Requiring specific characters reduces the number of permutations. The only thing that makes a password more secure is increasing the minimum length. As the OP suggests, enforcing special characters makes most people just put a special character at the end. What you have effectively done is make the last character so easy to guess that it might as well not exist.

[–] QualifiedKitten@discuss.online 14 points 3 days ago

My new job has us doing various security trainings every month and they also send out fake phishing emails. I initially ignored the emails prompting me to do the training because they require you to click a personalized link in the email to access the training. Eventually, my manager reached out and asked why I hadn't done the training, so I explained, but finally clicked through to do it. That month's training was about how a long passphrase is more secure than a list of character type requirements. Guess whose password requirements are a list of character type requirements?

[–] nullify3112@lemmy.world 2 points 2 days ago

Let me introduce you to MyP4s$worcl*websitename**@

[–] shrugs@piefed.social 13 points 4 days ago (1 children)

for real, why is it so hard to count entropy?

load more comments (1 replies)
[–] OddMinus1@sh.itjust.works 3 points 3 days ago (2 children)

Do you want your password to be sent raw into a service to analyze your password entropy and detect common patterns, OR do you want a simple rule which can be checked client side?

[–] ikidd@lemmy.dbzer0.com 5 points 3 days ago

You don't send full raw hashes, k-anonymity is a thing. HaveIBeenPwned just takes the first 5 of a hash and sends you back a list that you compare clientside so it never leaves as a usable password.

[–] undefined@lemmy.hogru.ch 7 points 3 days ago* (last edited 1 day ago)

The FBI training I’m forced to take at work suggests replacing characters in that manner. “Just use a $ instead of S!”

But back in like 2006 I brute forced a dump of 20 Windows passwords in that style on my old Dell single core machine in less than two seconds. Every passing year I’m still shocked people continue thinking this would work.

load more comments
view more: next ›