Earlier quoted context omitted.
> The biggest problem with passwords is that users select them, and users are stupid. I really hope you don't work with users or are doing anything that affects them. Users are not stupid, they maybe lack understand or are lazy and things are inconvenient. But the world is easier if you can just pass of your responsibility to the ominous "dumb user", isn't it?
I meant no disrespect to users as a group. Nonetheless its clear that we can't get >99.5% of ùsers to implement this security control properly, and that makes it a bad security control. And to be clear, its my belief that if someone implements a security control that constantly fails due to misuse, the party at fault is the implementor, not the user. Whether that's because users don't understand or just that their in…
I agree. We can improve it so that others don't have to think about it and it actually solves their problem. Right now we pretty much just move the responsibility to the user.