<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[It&#x27;s the annual &quot;change my work password&quot; day.]]></title><description><![CDATA[<p>It's the annual "change my work password" day. (Yes, I know, don't tell me, tell the IT department.)</p><p>For credentials I'm going to type a lot, I still prefer a short password full of strange characters to a long passphrase made of words. It's more effort to memorise, but once that's done, it's faster to enter than a long passphrase – a benefit that lasts the rest of the year.</p><p>My current memorisation technique involves a recurring timer. Every N minutes, an alert goes off, and I stop whatever I'm doing, run 'su $USERNAME -c "echo ok"', type my password, and make sure it did echo "ok". I do the password change first thing in the morning, and over the course of the day, increase the period between memory checks, from 5 minutes down to 15 or 30, so that it moves from short-term to long-term memory. If I find I've forgotten it in one of these tests, I'm allowed to look it up, but in every test I must first try it from memory and _then_ find out what I got wrong. And then retype it right.</p><p>I like this technique because it's simultaneously practice at remembering the password, and practice at typing it quickly and accurately. Even the "do it right now, interrupting whatever else you were doing" aspect is deliberate: it trains the skill of remembering the password _even while distracted_, which is actually necessary, if e.g. you need to 'sudo' something in a sudden emergency that's taking up most of your brain.</p><p>Reinforcing the new password periodically over the course of the first day is generally enough that when I come to log in the next morning I can remember it even after a night's sleep. And then I'm over the hump.</p><p>But one problem I still haven't solved is remembering, the next day, *that* I changed my password. It's still common for me to type the old one three times running before I realise what the problem is!</p>]]></description><link>https://board.circlewithadot.net/topic/4bfbffe0-2e77-406f-aaff-bb33ab33f512/it-s-the-annual-change-my-work-password-day.</link><generator>RSS for Node</generator><lastBuildDate>Mon, 25 May 2026 08:58:31 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/4bfbffe0-2e77-406f-aaff-bb33ab33f512.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 20 May 2026 10:28:06 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to It&#x27;s the annual &quot;change my work password&quot; day. on Wed, 20 May 2026 14:46:01 GMT]]></title><description><![CDATA[<p><span><a href="/user/simontatham%40hachyderm.io">@<span>simontatham</span></a></span> <br />Only once a year? I never had such a long period at any job - it was always 90 days between changes, with the difference in similarity rules.</p>]]></description><link>https://board.circlewithadot.net/post/https://mammut.moe/users/gemelen/statuses/116607442044614827</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mammut.moe/users/gemelen/statuses/116607442044614827</guid><dc:creator><![CDATA[gemelen@mammut.moe]]></dc:creator><pubDate>Wed, 20 May 2026 14:46:01 GMT</pubDate></item><item><title><![CDATA[Reply to It&#x27;s the annual &quot;change my work password&quot; day. on Wed, 20 May 2026 13:24:06 GMT]]></title><description><![CDATA[<p><span><a href="/user/simontatham%40hachyderm.io">@<span>simontatham</span></a></span> we change the passwords way more often, 3mo I think, and we have 2 (long story). I dump them in a password manager they gave me, whose main password does not change, and do a little dance every time I need to enter them. Nothing I do requires snappiness.</p>]]></description><link>https://board.circlewithadot.net/post/https://en.osm.town/users/mdione/statuses/116607119941310528</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://en.osm.town/users/mdione/statuses/116607119941310528</guid><dc:creator><![CDATA[mdione@en.osm.town]]></dc:creator><pubDate>Wed, 20 May 2026 13:24:06 GMT</pubDate></item><item><title><![CDATA[Reply to It&#x27;s the annual &quot;change my work password&quot; day. on Wed, 20 May 2026 13:22:58 GMT]]></title><description><![CDATA[<p><span><a href="/user/nachtet%40norden.social">@<span>nachtet</span></a></span> yes, I've heard that from a few other people too. Seems fairly common. Happily I don't have that problem myself – the finger shapes are associated fairly strongly with the characters, for me, so even if I temporarily forget what the characters are, I can remember them again _by_ imagining my fingers going through the motions.</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/simontatham/statuses/116607115476686895</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/simontatham/statuses/116607115476686895</guid><dc:creator><![CDATA[simontatham@hachyderm.io]]></dc:creator><pubDate>Wed, 20 May 2026 13:22:58 GMT</pubDate></item><item><title><![CDATA[Reply to It&#x27;s the annual &quot;change my work password&quot; day. on Wed, 20 May 2026 13:21:46 GMT]]></title><description><![CDATA[<p><span><a href="/user/simontatham%40hachyderm.io">@<span>simontatham</span></a></span> My new password problem is that my brain stores it in the tactile memory section after I used it a couple of times and then if I have to type it in on keys instead if touch pad or vice versa I suddenly lose all concept of it.</p>]]></description><link>https://board.circlewithadot.net/post/https://norden.social/users/nachtet/statuses/116607110753177516</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://norden.social/users/nachtet/statuses/116607110753177516</guid><dc:creator><![CDATA[nachtet@norden.social]]></dc:creator><pubDate>Wed, 20 May 2026 13:21:46 GMT</pubDate></item><item><title><![CDATA[Reply to It&#x27;s the annual &quot;change my work password&quot; day. on Wed, 20 May 2026 12:10:43 GMT]]></title><description><![CDATA[<p><span><a href="/user/simontatham%40hachyderm.io">@<span>simontatham</span></a></span> when you're finished the day before, imagine doing something drastic/noticable/unpleasant to your keyboard for a minute or so.The more convoluted and visceral the better. (You poured coffee all over the keyboard, then lit it on fire so that it smells of charred roast and is blackened to ash. Also somehow still sticky to the touch.) That memory should pop to mind when you arrive in the morning, which you can use to remember the change.</p>]]></description><link>https://board.circlewithadot.net/post/https://mathstodon.xyz/users/drScott/statuses/116606831372835691</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mathstodon.xyz/users/drScott/statuses/116606831372835691</guid><dc:creator><![CDATA[drscott@mathstodon.xyz]]></dc:creator><pubDate>Wed, 20 May 2026 12:10:43 GMT</pubDate></item><item><title><![CDATA[Reply to It&#x27;s the annual &quot;change my work password&quot; day. on Wed, 20 May 2026 11:56:48 GMT]]></title><description><![CDATA[<p><span><a href="/user/simontatham%40hachyderm.io">@<span>simontatham</span></a></span><br />I just take forced password changes as a "your password must be Spring2026" policy.</p><p>If they want me to use a better password, they can change the policy.</p><p>(Though where I worked, it was always the Microsoft default of three months).</p>]]></description><link>https://board.circlewithadot.net/post/https://c.im/ap/users/116216635389955538/statuses/116606776667415736</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://c.im/ap/users/116216635389955538/statuses/116606776667415736</guid><dc:creator><![CDATA[leeloo@c.im]]></dc:creator><pubDate>Wed, 20 May 2026 11:56:48 GMT</pubDate></item><item><title><![CDATA[Reply to It&#x27;s the annual &quot;change my work password&quot; day. on Wed, 20 May 2026 11:36:21 GMT]]></title><description><![CDATA[<p><span><a href="/user/simontatham%40hachyderm.io">@<span>simontatham</span></a></span> I had a habit of using single words or short phrases in non-English languages (Icelandic, Latin, Klingon (yes!), Dutch, to name a few) with the appropriate non-alpha bits thrown in to satisfy the stupid parser... _and then I'd stuff them in my password manager_, whose master passphrase is under MY control, and accessible from my phone as well as the desktop... as an SRE I'd use sudo often enough to get it in my head by EOD if I changed it in the morning, and, given advanced warning, I made sure to never change it on a Friday... that way the muscle memory has time to sink in before the weekend.  </p><p>The real problem was coming up with a good one in the first place - easy enough to type, complex enough to satisfy the idiots who wrote the standards... the thing that really gets me is that while _allowing_ numbers and specials is one thing, _requiring_ one of each class really cuts your pattern space... taking you from a choice of 92 different values for each character to 30, 26, and TEN choices respectively for three of'em. (Assuming Little Bobby Tables rules aren't in play, which further reduces your specials count...) (OTOH, if you say, "must contain _at least three_ of upper, lower, number, symbol" that makes it easier for you and harder for the black hats... <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f608.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--smiling_imp" style="height:23px;width:auto;vertical-align:middle" title="😈" alt="😈" /> )</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/stonebear2/statuses/116606696235707422</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/stonebear2/statuses/116606696235707422</guid><dc:creator><![CDATA[stonebear2@hachyderm.io]]></dc:creator><pubDate>Wed, 20 May 2026 11:36:21 GMT</pubDate></item><item><title><![CDATA[Reply to It&#x27;s the annual &quot;change my work password&quot; day. on Wed, 20 May 2026 11:10:19 GMT]]></title><description><![CDATA[<p><span><a href="/user/simontatham%40hachyderm.io" rel="nofollow noopener">@<span>simontatham</span></a></span> If they read the academic documentation, they know. After reading the NIST recommendations that says forcing password change is useless, they compromized and changed mandatory change from 3 months to 6 months <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f937.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--shrug" style="height:23px;width:auto;vertical-align:middle" title="🤷" alt="🤷" />. Everyone is just reusing the same password and adding numbers because that's the only password memorization scheme that works on the median person who has dozens of passwords to remember.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/aris/statuses/116606593888198239</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/aris/statuses/116606593888198239</guid><dc:creator><![CDATA[aris@infosec.exchange]]></dc:creator><pubDate>Wed, 20 May 2026 11:10:19 GMT</pubDate></item><item><title><![CDATA[Reply to It&#x27;s the annual &quot;change my work password&quot; day. on Wed, 20 May 2026 11:00:00 GMT]]></title><description><![CDATA[<p><span><a href="/user/aris%40infosec.exchange">@<span>aris</span></a></span> don't tell me, tell the IT department!</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/simontatham/statuses/116606553348236493</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/simontatham/statuses/116606553348236493</guid><dc:creator><![CDATA[simontatham@hachyderm.io]]></dc:creator><pubDate>Wed, 20 May 2026 11:00:00 GMT</pubDate></item><item><title><![CDATA[Reply to It&#x27;s the annual &quot;change my work password&quot; day. on Wed, 20 May 2026 10:59:30 GMT]]></title><description><![CDATA[<p><span><a href="/user/simontatham%40hachyderm.io" rel="nofollow noopener">@<span>simontatham</span></a></span> my memory is really bad and forcing me to remember a new password is deemed to fail. That's why most people's password is asdf123 and I don't blame that technology mistake on them.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/aris/statuses/116606551347475553</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/aris/statuses/116606551347475553</guid><dc:creator><![CDATA[aris@infosec.exchange]]></dc:creator><pubDate>Wed, 20 May 2026 10:59:30 GMT</pubDate></item><item><title><![CDATA[Reply to It&#x27;s the annual &quot;change my work password&quot; day. on Wed, 20 May 2026 10:54:56 GMT]]></title><description><![CDATA[<p><span><a href="/user/simontatham%40hachyderm.io">@<span>simontatham</span></a></span> I did tell my IT department. They sighed, and said they agreed with me, and that our auditors were idiots.</p>]]></description><link>https://board.circlewithadot.net/post/https://fosstodon.org/users/DrHyde/statuses/116606533415575499</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://fosstodon.org/users/DrHyde/statuses/116606533415575499</guid><dc:creator><![CDATA[drhyde@fosstodon.org]]></dc:creator><pubDate>Wed, 20 May 2026 10:54:56 GMT</pubDate></item><item><title><![CDATA[Reply to It&#x27;s the annual &quot;change my work password&quot; day. on Wed, 20 May 2026 10:37:44 GMT]]></title><description><![CDATA[<p><span><a href="/user/simontatham%40hachyderm.io">@<span>simontatham</span></a></span> I feel like the answer there is probably a post-it note <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f60a.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--blush" style="height:23px;width:auto;vertical-align:middle" title="😊" alt="😊" /></p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.ie/users/xanna/statuses/116606465797782781</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.ie/users/xanna/statuses/116606465797782781</guid><dc:creator><![CDATA[xanna@mastodon.ie]]></dc:creator><pubDate>Wed, 20 May 2026 10:37:44 GMT</pubDate></item></channel></rss>