GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    prettygood (prettygood@socially.drinkingatmy.computer)'s status on Monday, 09-Jun-2025 10:08:39 JST prettygood prettygood
    If a site/service/software limits what characters you can use in a password, I will personally guarantee that they are mishandling your security in some way or another, probably multiple ways.
    In conversation about 8 days ago from socially.drinkingatmy.computer permalink

    Attachments


    1. https://drinkingatmy.computer/pleroma/3e/67/b2/3e67b259b1d5d5ca9b5f81c0d4637ad12e33bc0a6cd2c838cc38ec04d43bc544.png?name=image.png
    • Embed this notice
      crow (crow@irlqt.me)'s status on Monday, 09-Jun-2025 10:13:12 JST crow crow
      in reply to

      @prettygood@socially.drinkingatmy.computer real - i always assume it's in plain text somewhere

      probably a VARCHAR64 column in an ancient MySQL db

      In conversation about 8 days ago permalink
      prettygood likes this.
    • Embed this notice
      prettygood (prettygood@socially.drinkingatmy.computer)'s status on Monday, 09-Jun-2025 10:18:55 JST prettygood prettygood
      in reply to
      • gray
      @gray
      In conversation about 8 days ago permalink

      Attachments


      1. https://drinkingatmy.computer/pleroma/20/8d/ce/208dce0bd0a6a8897bcc862539d66d2e029eefb2b96f95d0260db68f7d6351b8.png?name=uzakiwhat.png
    • Embed this notice
      gray (gray@clubcyberia.co)'s status on Monday, 09-Jun-2025 10:18:56 JST gray gray
      in reply to
      @prettygood I had a work website say I wasn’t supposed to use a password manager to save my password so I just saved it into an Outlook sticky note
      In conversation about 8 days ago permalink
    • Embed this notice
      Nudhul (nudhul@shitposter.world)'s status on Monday, 09-Jun-2025 10:19:06 JST Nudhul Nudhul
      in reply to
      @prettygood same with an unreasonable minimum length
      In conversation about 8 days ago permalink
      prettygood likes this.
    • Embed this notice
      prettygood (prettygood@socially.drinkingatmy.computer)'s status on Monday, 09-Jun-2025 10:20:06 JST prettygood prettygood
      in reply to
      • Paradox
      @Paradox my go-to is 64 characters, full ASCII set, randomized. It works more often than not, but the notable exceptions always seem to be the important places, like financial institutions and core service providers.
      In conversation about 8 days ago permalink
    • Embed this notice
      Paradox (paradox@raru.re)'s status on Monday, 09-Jun-2025 10:20:08 JST Paradox Paradox
      in reply to

      @prettygood I haven't found a single one that lets you use anything and everything.

      In conversation about 8 days ago permalink
    • Embed this notice
      gray (gray@clubcyberia.co)'s status on Monday, 09-Jun-2025 10:20:58 JST gray gray
      in reply to
      @prettygood it is also one of the bullshit sites that forces you to change your password every 90 days or something
      In conversation about 8 days ago permalink
      prettygood likes this.
    • Embed this notice
      prettygood (prettygood@socially.drinkingatmy.computer)'s status on Monday, 09-Jun-2025 10:21:19 JST prettygood prettygood
      in reply to
      • gray
      @gray this doesn't bother me, I have a lot of entropy to expend on generating random strings
      In conversation about 8 days ago permalink
    • Embed this notice
      Epsi (epsi@akko.wtf)'s status on Monday, 09-Jun-2025 10:21:41 JST Epsi Epsi
      in reply to
      @prettygood no single quote or <> allowed hmmm...
      In conversation about 8 days ago permalink
      prettygood likes this.
    • Embed this notice
      prettygood (prettygood@socially.drinkingatmy.computer)'s status on Monday, 09-Jun-2025 10:21:58 JST prettygood prettygood
      in reply to
      • Epsi
      @epsi little bobby XML parser (bullshitting)
      In conversation about 8 days ago permalink
    • Embed this notice
      Paradox (paradox@raru.re)'s status on Monday, 09-Jun-2025 10:22:45 JST Paradox Paradox
      in reply to

      @prettygood I have never thought about using carriage returns in my passwords. I don't even know if I could copypaste one. That's interesting.

      In conversation about 8 days ago permalink
      prettygood likes this.
    • Embed this notice
      Epsi (epsi@akko.wtf)'s status on Monday, 09-Jun-2025 10:24:02 JST Epsi Epsi
      in reply to
      @prettygood yeah I'm just musing haha
      In conversation about 8 days ago permalink
      prettygood likes this.
    • Embed this notice
      Vo (vo@noauthority.social)'s status on Monday, 09-Jun-2025 10:29:09 JST Vo Vo
      in reply to
      • gray

      @prettygood @gray My credit union got bought out or are outsourcing their online services (idk which I can't keep up, changes like this happen yearly) and the new service's mobile app won't let you paste your password from your password manager. Browser works fine though.

      I don't know what this is supposed to prevent. Are they worried about hackers brute-forcing via Android automation or something?? They wouldn't need the clipboard then...

      In conversation about 8 days ago permalink
      prettygood likes this.
    • Embed this notice
      prettygood (prettygood@socially.drinkingatmy.computer)'s status on Monday, 09-Jun-2025 10:29:45 JST prettygood prettygood
      in reply to
      • Vo
      • gray
      @Vo @gray some executive got fed some bullshit at some conference and dictated bad policy to the org and now we're all worse off for it. That's just how it goes, unfortunately.
      In conversation about 8 days ago permalink
    • Embed this notice
      prettygood (prettygood@socially.drinkingatmy.computer)'s status on Monday, 09-Jun-2025 10:31:08 JST prettygood prettygood
      in reply to
      • Paradox
      • Vo
      @Vo @Paradox would you believe I've seen this happen as well?
      In conversation about 8 days ago permalink
    • Embed this notice
      Vo (vo@noauthority.social)'s status on Monday, 09-Jun-2025 10:31:09 JST Vo Vo
      in reply to
      • Paradox

      @prettygood @Paradox I found a site once that said (and accepted) 8-64 length but actually truncated to 63 before salting/hashing/storing. That was fun to figure out.

      In conversation about 8 days ago permalink
      prettygood likes this.
    • Embed this notice
      Vo (vo@noauthority.social)'s status on Monday, 09-Jun-2025 10:35:58 JST Vo Vo
      in reply to
      • Paradox

      @prettygood @Paradox we're past "poweruser" and into the "edge case" fringe, apparently

      In conversation about 8 days ago permalink
      prettygood likes this.
    • Embed this notice
      Vo (vo@noauthority.social)'s status on Monday, 09-Jun-2025 10:38:48 JST Vo Vo
      in reply to
      • gray

      @prettygood @gray they made me choose a username (instead of just using the debit card number like the old site) so I took the opportunity to call their app some tasteful cusswords

      In conversation about 8 days ago permalink
      prettygood likes this.
    • Embed this notice
      Sparkler (sparkler@mastodon.is-a.horse)'s status on Monday, 09-Jun-2025 10:38:53 JST Sparkler Sparkler
      in reply to
      • Paradox
      • Vo

      @Vo @prettygood @Paradox Hotmail/outlook used to do this, except it was 16 characters

      In conversation about 8 days ago permalink
      prettygood likes this.
    • Embed this notice
      Vo (vo@noauthority.social)'s status on Monday, 09-Jun-2025 10:54:32 JST Vo Vo
      in reply to
      • Paradox
      • Sparkler

      @sparkler @prettygood @Paradox I guess it would work fine (but insecurely) if the login page did the same truncate, but alas

      In conversation about 8 days ago permalink
      prettygood likes this.
    • Embed this notice
      prettygood (prettygood@socially.drinkingatmy.computer)'s status on Monday, 09-Jun-2025 11:00:59 JST prettygood prettygood
      in reply to
      • Ulysses
      @professionalbigot69 sauce? Bold claim. I wouldn't be surprised
      In conversation about 8 days ago permalink
    • Embed this notice
      Ulysses (professionalbigot69@poa.st)'s status on Monday, 09-Jun-2025 11:01:00 JST Ulysses Ulysses
      in reply to
      @prettygood Cloudflare MITMs passwords entered through the front end btw
      In conversation about 8 days ago permalink
    • Embed this notice
      Ulysses (professionalbigot69@poa.st)'s status on Monday, 09-Jun-2025 11:22:23 JST Ulysses Ulysses
      in reply to
      @prettygood In their developers knowledgebase:

      https://developers.cloudflare.com/fundamentals/account/account-security/leaked-password-notifications/
      In conversation about 8 days ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: developers.cloudflare.com
        Leaked Password Notifications · Cloudflare Fundamentals docs
        Cloudflare automatically checks if your password has been compromised when you log in to the Cloudflare dashboard. Every time you log in to your account, we will securely verify through threat intelligence sources to confirm if your password has been leaked in a past data breach.
    • Embed this notice
      prettygood (prettygood@socially.drinkingatmy.computer)'s status on Monday, 09-Jun-2025 11:22:23 JST prettygood prettygood
      in reply to
      • Ulysses
      @professionalbigot69 oh so they're MITMing your CF password, not just any old thing entered into a CF hosted/proxied site. I misunderstood.
      In conversation about 8 days ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.