4 ms·
Can't you say the same about the regular username + password implementation? Or are there smaller chances of that happening if you separate the login data into
by Ygor 16y ago
Can't you say the same about the regular username + password implementation?
Or are there smaller chances of that happening if you separate the login data into two different parts, like username and password?
Is it just a psychological difference, or is there something more there?
- wwortiz 16y agoBasic statistics says yes the chances are much much smaller if you have both username + password. The larger the password and the more obscure the password means that chances grow smaller of someone else choosing it but that doesn't mean everyone uses large and obscure passwords.
- JangoSteve 16y agoThe logistics of it are different. With username + password, 2 people can have the same password. So you only need to warn someone if the username has already been taken. But in order to warn someone that a secret phrase has already been taken, you've just given them all the info they need to login as that other person. That being said, if you were to enforce that the first half (or some undisclosed portion) of the secret phrase couldn't be taken, then you'd be closer to comparing apples to apples.