The 25 worst passwords of 2013: 'password' gets dethroned
1–10 of 13 posts
Re: The 25 worst passwords of 2013: 'password' gets dethroned
#2Re: The 25 worst passwords of 2013: 'password' gets dethroned
#3Re: The 25 worst passwords of 2013: 'password' gets dethroned
#4Passwords are bullshit and it is our failure as an industry: we should be moving away from passwords.
Re: The 25 worst passwords of 2013: 'password' gets dethroned
#5That's flawed logic. Most of the analysis comes from the Adobe leakage, and arguably a large share of users there didn't care about this service and used an easy and weak password. It would be much more interesting to have stats from active gmail accounts or bank accounts, for instance.
Re: The 25 worst passwords of 2013: 'password' gets dethroned
#6Re: The 25 worst passwords of 2013: 'password' gets dethroned
#7That's flawed logic. Most of the analysis comes from the Adobe leakage, and arguably a large share of users there didn't care about this service and used an easy and weak password. It would be much more interesting to have stats from active gmail accounts or bank accounts, for instance.
The users are actually quite smart in deciding how much effort is adequate for the realistically expected risk to them. Unless their perception is manipulated.
Re: The 25 worst passwords of 2013: 'password' gets dethroned
#8Passwords are bullshit and it is our failure as an industry: we should be moving away from passwords.
1. Something you know: password, secret question, mother's maiden name. These can be forgotten. If the information is generated by the user, it has the potential to be something easily guessed.
2. Something you have: SSH key, GPG key, RSA token, Yubikey, Google Authenticator. These can be quite secure, but hard to use. Losing a physical auth token deprives the user of access. SSH/GPG key pairs depend on the security of the system(s) they're stored on.
3. Something you are: fingerprint, retina scan, face recognition, voiceprint. These are irrevocable and anathema to privacy. Worst of all, they're not very reliable or secure. Fingerprint scanners are stymied if one has recently been lifting weights or rock climbing. Face recognition is affected by lighting, makeup, glasses, hair, sunburn/tan, age, etc. Voice auth is a joke. It can fail due to emotional stress, sickness, or background noise.
Combinations can be used for more secure authentication, but so far nothing has been as simple or as convenient as a password.
Re: The 25 worst passwords of 2013: 'password' gets dethroned
#9Passwords are bullshit and it is our failure as an industry: we should be moving away from passwords.
and use what authenticators?
Re: The 25 worst passwords of 2013: 'password' gets dethroned
#10Passwords are bullshit and it is our failure as an industry: we should be moving away from passwords.
A simple example:
Suppose you're already a registered user of XYZ.com. You've just downloaded the XYZ.com mobile app and wanted to login. You then login to XYZ.com and go to the page My Account > My Login Code. I use the built in QR code scanner in XYZ.com mobile to scan the one use QR code on the page. Viola! Mobile app is now logged in and no need to type my 30 characters mix-of-alphabets-digits-symbols password on the phone's tiny little on screen keyboard.