86% of CrashCrate subscribers used passwords already leaked in other breaches
1–10 of 145 posts
Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#2One way is to email the user when they log in from a new device or computer.
They then have to enter a 6 digit one time password from the email.
Someone who grabs the users email and password from a breach would also need access to their email.
Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#3So ones security researches terrible, is a neurologists reasonable. The actually embarrassing part is that after years of research- we still do not have a alternative.
Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#4If you're responsible for running a website, how are you going to be resilient against attackers who come to your site with legitimate usernames and passwords of your members? One way is to email the user when they log in from a new device or computer. They then have to enter a 6 digit one time password from the email. Someone who grabs the users email and password from a breach would also need access to their email.
Just like SQL injection and query prepare statements, issues are very much known but it's the want and need to act on them. GDPR should start to help this, but management tier individuals who push development time scales are also needing to be 'sold' the importance of this.
Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#5The truth is the password is just another failed security concept- because those that work, cant be remembered by the users. So ones security researches terrible, is a neurologists reasonable. The actually embarrassing part is that after years of research- we still do not have a alternative.
Remind me what's wrong with "correct horse battery staple" again?
Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#6Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#7The truth is the password is just another failed security concept- because those that work, cant be remembered by the users. So ones security researches terrible, is a neurologists reasonable. The actually embarrassing part is that after years of research- we still do not have a alternative.
> because those that work, cant be remembered by the users Remind me what's wrong with "correct horse battery staple" again?
Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#8The truth is the password is just another failed security concept- because those that work, cant be remembered by the users. So ones security researches terrible, is a neurologists reasonable. The actually embarrassing part is that after years of research- we still do not have a alternative.
> because those that work, cant be remembered by the users Remind me what's wrong with "correct horse battery staple" again?
Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#9If you're responsible for running a website, how are you going to be resilient against attackers who come to your site with legitimate usernames and passwords of your members? One way is to email the user when they log in from a new device or computer. They then have to enter a 6 digit one time password from the email. Someone who grabs the users email and password from a breach would also need access to their email.
Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#10I'm still not sure why most services don't default to just mailing you a one time, short lived login link.