3 ms·
> With a single random password most people will write down their password, so anyone who can read what was written down gains full access. With a random userna
by nathantotten 8y ago
> With a single random password most people will write down their password, so anyone who can read what was written down gains full access. With a random username and a user-chosen password most people will write down their username but not their password. Clearly this approach is more secure.
I don't believe this is grounded in evidence. You are basically saying that given two hard to remember strings, most people will write down one hard to remember string and not the other hard to remember string. Why?
> I don't see how relying on haveibeenpwnd can be considered secure. Many people use the same password for different sites. If your site's login credentials are just email+password you are relying on the security and honesty of all other sites that use the email+password combination.
I think you are missing the point of the haveibeenpwnd service. The point is to block people from using ANY password that is listed in the haveibeenpwnd database, thus denying attackers from using that dictionary of known passwords.
- MarkMc 8y agoA string is not that hard to remember when it is a password you thought up and have been using for 10 years. OK I cannot offer proof that most people would not write down their password, but surely some would not - and for those people having a separate User ID/password combination represents improved security. But anyway this is beside the point, which is that adding random characters to user credentials improves security - whether those credentials are 1 or 2 strings - and would have prevented this TurboTax attack. Yes, using the haveibeenpwnd service offers some level of protection. But it still allows an attacker to breach a random website like funnycatpictures.com and find the email/password combinations that are not on haveibeenpwnd. Boom, that attacker has access to all those users' tax information.