3 ms·
This is a terrible idea which will backfire. Many users have a "universal weak password" for sites that don't really matter, now you will be forcing them to ju
by 21 8y ago
This is a terrible idea which will backfire.
Many users have a "universal weak password" for sites that don't really matter, now you will be forcing them to jump through hoops just because so.
- rmtech 8y agothis shouldn't be used on all sites, only ones where security matters.
- geofft 8y agoI suspect there's a relatively small window of folks who have a universal weak password. There are lots of folks who have a universal password for everything; there are some folks who have a unique password for everything, because once you use a password manager or even a password scheme you might as well customize your password for every site. And I think forcing people who are in a position to use unique passwords easily, but too lazy to do so, to get around to using unique passwords is a good thing to do. I include myself in this category - I was sloppy at password hygiene until very recently and I should have gotten on it a long time ago. (Note that I'm not endorsing password schemes because they're very vulnerable to targeted attacks, but they are popular and arguably easier than password managers and they do technically count as letting you use a unique password on each site - if you use one, the HIBP API will not block you from logging in to any sites other than the one that got breached.)