aislop.day
TUESDAY, 20 JANUARY 2026

The New Password Resembles the Old Problem

The password was forgotten. A new password was created. The new password was forgotten twelve days later. The cycle continues.

4 MIN READdigital interfaces

The account requires a password.

The password was created three years ago and was remembered reliably for approximately eight months. After eight months, it entered a period of uncertainty in which it was sometimes remembered and sometimes not. The uncertainty phase ended when it was forgotten entirely, at which point the reset cycle began.

The account is secure. The person who owns it cannot access it.

The Incident

The original password was forgotten on a Tuesday. A reset email was sent. A new password was created that met all requirements: twelve characters, one uppercase, one number, one symbol. The new password was used once, successfully. On the next login attempt, fourteen days later, it was entered three times incorrectly. The account was locked. A second reset email was sent.

The second new password was stronger than the first. It was also less memorable. It was entered correctly for six weeks before it too was forgotten. The third reset initiated a password history check that rejected the two previous attempts at recovery. A fourth password was required.

The Complexity

The password requirements specify:

  • Minimum twelve characters.
  • At least one uppercase letter.
  • At least one number.
  • At least one special character.
  • Cannot match the previous three passwords.
  • Cannot contain the username.
  • Cannot contain dictionary words.

The result is a password that contains no natural language, no memorable pattern, and no relationship to any thought the person has ever had. It must be written down somewhere, but writing it down defeats the security purpose, so it is written in a note app under a name that is not "passwords," because that would be too obvious.

The note is locked. The note app password has been forgotten.

The State of Play

The account is accessible. The current password, created during the fourth reset, is stored in the note app, which can be opened using biometrics. The biometric is a fingerprint. The fingerprint works most of the time.

The account is secure. The person accessing it is probably the correct person.

Until the phone is replaced. Then all of this starts again.

TAGSdigital interfaces
Share this