If you're responsible for running a website, how are you going to be resilient against attackers who come to your site with legitimate usernames and passwords of your members? One way is to email the user when they log in from a new device or computer. They then have to enter a 6 digit one time password from the email. Someone who grabs the users email and password from a breach would also need access to their email.
86% of CrashCrate subscribers used passwords already leaked in other breaches
31–40 of 145 posts
Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#3286% of my passwords are for low consequence sites. How much should I care if someone hacks my handle and posts ads on a chat site? Or reads registration-required articles under my registration? Or etc etc.
1. With a password manager, you don't have to think anymore if a site is high-consequence or low-consequence. 2. What kinds of websites that require a sign-in are actually low-consequence? I can't think of any from the top of my head, but that's probably because I'm pretty reluctant to sign up to new sites.
Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#33Earlier quoted context omitted.
No, please don't. This is arduous for those of us who like a bit of privacy and regularly clear their cookies etc.
Why not whitelist the cookies of sites where you're going to log right back in?
Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#34Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#3586% of my passwords are for low consequence sites. How much should I care if someone hacks my handle and posts ads on a chat site? Or reads registration-required articles under my registration? Or etc etc.
1. With a password manager, you don't have to think anymore if a site is high-consequence or low-consequence. 2. What kinds of websites that require a sign-in are actually low-consequence? I can't think of any from the top of my head, but that's probably because I'm pretty reluctant to sign up to new sites.
Forum logins risk reputational damage, but otherwise are reasonably limited. Some people use specialist forums to ask one-off questions, for example.
Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#36At bare minimum websites should use 2FA - a simple TOTP on any smartphone will do wonders. But, the issue is that 86% of all websites offer so little value that 86% of people would just not bother using the site if they had to do the 2FA dance each time. That is the fundamental problem here - not people reusing passwords, or password policies that break when encountering my password manager. It's not surprising peopl…
If all online shops were required to let me buy something without creating an account, my "password footprint" would be about 1/2 of what it is.
Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#37Just wait. Someday you will see dumps of pwnt password that look like:
Password-1234
Password_1234
Password!1234
Password&1234
Password?1234
Password$1234
And that is rated as a "VERY STRONG" password.Have fun with your character diversity, and your 90 day password expiration rotation schemes. Go ahead and try to force me into a corner. I'm still picking terrible passwords and I'm picking especially terrible ones because someone out there is trying to pull my strings.
Pull my strings. Make me more predictable within your little security policy world. See how that plays out.
Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#3886% of my passwords are for low consequence sites. How much should I care if someone hacks my handle and posts ads on a chat site? Or reads registration-required articles under my registration? Or etc etc.
Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#39Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#4086% of my passwords are for low consequence sites. How much should I care if someone hacks my handle and posts ads on a chat site? Or reads registration-required articles under my registration? Or etc etc.
1. With a password manager, you don't have to think anymore if a site is high-consequence or low-consequence. 2. What kinds of websites that require a sign-in are actually low-consequence? I can't think of any from the top of my head, but that's probably because I'm pretty reluctant to sign up to new sites.
It's usually not a function of the site, but a function of the site and the user. pg would probably care more about his HN account than user051783254. That said, some sites where I expect the majority of users (mostly the non-paying ones, but perhaps even the paying ones depending on the payment mechanism) would probably not care about their accounts being hijacked might include: HN, StackOverflow, CodeProject, AllTrails, Disqus, Last.fm, SlickDeals, etc.