Choosing a name that meets modern password complexity requirements
Description
A four-panel comic strip from 'CommitStrip' depicting a conversation between a doctor and a man. In the first two panels, the man, with a wild expression, dictates a nonsensical string of characters, including mixed cases, numbers, and symbols, to the skeptical doctor. In the third panel, the doctor confirms the full name, 'yJ%X6PL@'z,' and the man agrees enthusiastically. The final panel reveals the man is naming his young nephew (who is happily holding a puppy), and when the doctor questions if the child will remember it, the man confidently replies, 'He'll thank me when he's older.' This comic satirizes the increasingly absurd complexity requirements for modern passwords, analogizing them to naming a child. The joke resonates with senior developers who have experienced the friction between stringent security policies and user experience, where 'secure' often becomes synonymous with 'unusable' and 'unmemorable'
Comments
20Comment deleted
I tried to name my son using our corporate password policy. He's now 'Hunter2!', but every three months I have to call him 'Hunter2@' and he's not allowed to be named any of his previous 12 names
Bold move naming the kid “yJ%X6PL@’z”; he’ll ace every entropy meter - right up until the hospital’s legacy EMR truncates at 8 bytes and collides him with “hunter2”
After 20 years of sanitizing user inputs and escaping special characters, you realize the real vulnerability was letting developers name their children - somewhere a DBA is crying over a WHERE clause that needs to handle little Bobby'); DROP TABLE students;--
This is what happens when you let a developer who's spent too many years fighting with regex validators, SQL injection prevention, and Unicode normalization name a human being. The kid's going to need a prepared statement just to introduce himself at school, and good luck getting that past any government database that still thinks VARCHAR(50) without special characters is perfectly adequate for the 21st century
Naming the kid yJ%X6PL@'z is a full-stack integration test: IAM rejects the %, the legacy DB escapes the ', SSO parses the @ as an email, and the ETL quietly nulls the record
Threat modeling level: name the dog yJ%X6PL@'z so every ‘first pet’s name’ KBA is OSINT-proof - assuming the vet’s regex lets the apostrophe through
This identifier's so cryptic, even the family monorepo needs a dedicated grep alias to reference it
Me rn Comment deleted
X Æ A-12 Comment deleted
Explain Comment deleted
A few years later, when puppy leaves this world, it would be easier to forget ...just as your regular password Comment deleted
Then the dad failed, cause some websites don't allow using apostrophe Comment deleted
Not in "secret question" section ¯\_(ツ)_/¯ Comment deleted
😲 Comment deleted
Lol, when he grows up, that password will be too weak Comment deleted
"What was your first pet name?" Comment deleted
Ohhhhhhhhhhhh, that makes sense! Comment deleted
Genius Comment deleted
ol' Pl@zie Comment deleted
/wajihzesplaz/ Comment deleted