4 ms·
The reason for this type of password security theatre is that it maintains the fantasy world of purely human password management: 1. Every password only ever e
by pjdorrell 10y ago
The reason for this type of password security theatre is that it maintains the fantasy world of purely human password management:
1. Every password only ever exists inside the brain of the user, or inside the password entry field in the UI of the application at the time of login.
Unfortunately there are additional requirements, which make it impossible for anyone who is not superhuman to satisfy the first requirement:
2. All passwords should be unique across applications (or websites)
3. All passwords are long and random enough that they cannot be guessed by password-cracking software in a reasonable amount of time.
4. There is an ever-growing list of applications and websites that require passwords.