3 ms·
It's cool! I've been wondering too, since it's been an eye opener without equals finding out just how wrong I was. I think there were multiple lines of reasonin
by Gruselbauer 10y ago
It's cool! I've been wondering too, since it's been an eye opener without equals finding out just how wrong I was. I think there were multiple lines of reasoning going on:
- "I don't even use that many logins."
I do. I just abused 'reset password via email'.
- "I distrust the cloud provider's opsec."
Seriously? I'm a self taught amateur. Get a grip guy.
- "What if they give my passwords to the NSA?"
... at this point I want to slap myself.
- "How can it be secure if it's easy to use?"
I blame PGP for this one...
So I guess many things. In the end it was the usual mix of uninformed bias, weariness against third parties in security, being very wrong and the assumption that security needs terrible UX.
As I said, I never looked back. I've even sat down with friends and family, explained the concept and turned their '$catsname$birthyear' passwords they used for absolutely everything into security they wouldn't ever hope to achieve otherwise. And they're all so freaking happy, too.
For their master passwords I used the 'correct horse battery staple' approach and nobody has a problem remembering one of those, especially if it's in their native language.
So, yup, you're right in every way. I didn't know better.