Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> doesn't the new one the bank sends you usually have the same number?

Never happened to me using several European banks. Either way the date and CVV change so that's part of the new password.

> Yes it does. The more often you have to pick passwords, the more likely you are to pick weaker ones.

I don’t think so. People will just change the number at the end, it's not like they will stop using aDgTGdE and start using 11111112 simply because of rotation. It's more likely that they will append a ! or change helloworld to helloworld2. It's not a downgrade by any mean.

Plus such rotation even "guarantees" that the password isn't shared across services, unless they're all rotating with the same frequency and they all start with helloworld2



> It's not a downgrade by any mean.

If the minimum password length is 8 and the last two characters are the current month or year, the actual password length is roughly 6.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: