The truth is the password is just another failed security concept- because those that work, cant be remembered by the users. So ones security researches terrible, is a neurologists reasonable. The actually embarrassing part is that after years of research- we still do not have a alternative.
How about a password manager? Or even better: Some kind of hardware token and a good standard that goes with it?
86% of CrashCrate subscribers used passwords already leaked in other breaches
101–110 of 145 posts
Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#102This riles me up so I will rant. I've given up remembering passwords for important accounts and just use the 'forgot me password' button to auth through email. If your site or service doesn't have more than 100 million users, please don't require a password for my email. Let me log in with another trusted account (Google, Twitter, etc). I miss the days of oauth2 and the flexibility of authenticating small services.
No thanks, it’s far better to handle your own user authentication and not depend on third parties.
Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#103When I feel like a security goon's arbitrary and capricious password policy is irrational and counterproductive, I make my passwords worse in the hopes that I have to someday read it to someone, or perhaps it gets spilt outin the open, and then everyone will see how forcing me to pick a password that adheres to certain characteristics solved nothing. Just wait. Someday you will see dumps of pwnt password that look li…
I completely agree. "Your password must be at least 10 character long, include 2 upper case, 2 lower case, 2 digits, 2 special characters, must be changed every 60 days and cannot be reused for the next 3 years" G0Fuc4Y@urse!f To me this is a sure way that people are gonna pick horrible and stupid passwords.
You forgot "and may not be longer than 16 characters".
Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#104At bare minimum websites should use 2FA - a simple TOTP on any smartphone will do wonders. But, the issue is that 86% of all websites offer so little value that 86% of people would just not bother using the site if they had to do the 2FA dance each time. That is the fundamental problem here - not people reusing passwords, or password policies that break when encountering my password manager. It's not surprising peopl…
Please not. I don't want to use a 2FA for every crappy website with a login, nor do I have my phone with me all the time. (optional is fine of course)
I am thinking of a mars bar right now - it's utterly fucking pointless for me - i'm fat enough as it is and it has no nutritional value. so anything that increases the height of the bar to me buying one is fine by my slow thinking rational self. Sugar taxes, backroom, top shelf mars bar vendors are my bag baby.
Just say no.
Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#105Earlier quoted context omitted.
I'm not sure what you are saying ... should I memorize dozens of passwords like WCLfx(edI%uHgjWM6RuEeC6Qh for the services I use or should I strap on getting those dozens of services to use a perfect SSO service that doesn't leak privacy and is perfectly secure and doesn't exist yet?
I'm saying all solutions are a compromise. (And you do need to memorize your password manager password - and your main email account password as well) Also a lot of leaked passwords were strong, they just got compromised because someone didn't know about 70's password security basics. Should we just never use any leaked password ever again? (Note I'm not saying: with the same login - or any of the "top 100") Should w…
Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#106When I feel like a security goon's arbitrary and capricious password policy is irrational and counterproductive, I make my passwords worse in the hopes that I have to someday read it to someone, or perhaps it gets spilt outin the open, and then everyone will see how forcing me to pick a password that adheres to certain characteristics solved nothing. Just wait. Someday you will see dumps of pwnt password that look li…
Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#107Earlier quoted context omitted.
I completely agree. "Your password must be at least 10 character long, include 2 upper case, 2 lower case, 2 digits, 2 special characters, must be changed every 60 days and cannot be reused for the next 3 years" G0Fuc4Y@urse!f To me this is a sure way that people are gonna pick horrible and stupid passwords.
> Your password must be at least 10 character long You forgot "and may not be longer than 16 characters".
Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#108Earlier quoted context omitted.
I completely agree. "Your password must be at least 10 character long, include 2 upper case, 2 lower case, 2 digits, 2 special characters, must be changed every 60 days and cannot be reused for the next 3 years" G0Fuc4Y@urse!f To me this is a sure way that people are gonna pick horrible and stupid passwords.
> Your password must be at least 10 character long You forgot "and may not be longer than 16 characters".
Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#109When I feel like a security goon's arbitrary and capricious password policy is irrational and counterproductive, I make my passwords worse in the hopes that I have to someday read it to someone, or perhaps it gets spilt outin the open, and then everyone will see how forcing me to pick a password that adheres to certain characteristics solved nothing. Just wait. Someday you will see dumps of pwnt password that look li…
Such a rebel. Remember that at the end of the road it’s your identity your password protects.
Those scenarios are almost always a bad employer policy, in which case it's their data the password is protecting.
Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#110Earlier quoted context omitted.
I completely agree. "Your password must be at least 10 character long, include 2 upper case, 2 lower case, 2 digits, 2 special characters, must be changed every 60 days and cannot be reused for the next 3 years" G0Fuc4Y@urse!f To me this is a sure way that people are gonna pick horrible and stupid passwords.
> Your password must be at least 10 character long You forgot "and may not be longer than 16 characters".
I've seriously considered closing my accounts over it.
Edit: Yep, still as bad
Password must be 6-10 characters and contain at least 2 numbers and 2 letters. Password may not contain the following special characters: space , + " % & ' ; = ^ or curly braces.