4 ms·
I'm sure they are, but I think predictability is slightly less bad than being distributed across every single service they've ever used. There's only so much I
by discreditable 7y ago
I'm sure they are, but I think predictability is slightly less bad than being distributed across every single service they've ever used. There's only so much I can do about people not giving a crap.
- rtempaccount1 7y agoTOTP or other forms of 2FA are the best way of avoiding the very real problem of user password re-use.
- pstch 7y agoI don't see how TOTP/2FA can avoid the problem of user password re-use. The password has still been reused, whether an extra layer of authentication is used or not. Maybe you can say that it mitigates it, but I don't think it avoids it at all.
- infogulch 7y agoThere are two slightly overlapping ways to actually solve this problem: 1. Use a password manager. 2. Have the tools, knowledge, capability, and willingness to use secure passphrases.
- tomglynch 7y agoOne other way. Websites could hash and salt the users password client side, then proceed as usual (SSL and hash it server side). Means the users password is effectively a long, secure passphrase and is unique. What do you think?
- raesene9 7y agoI'd say it avoids it, mitigates would work fine. The sum of the authentication credentials passed to the application is different for each site. with 2FA you submit password + token. so an attacker who is replaying compromised credentials can't gain unauthorised access with them alone.
- dredmorbius 7y agoTesting against known password lists is a huge win.
- ScottBurson 7y agoYes, this is the right answer. See https://haveibeenpwned.com/Passwords https://haveibeenpwned.com/Passwords