3 ms·
This article is weird and contradicts itself. Having a strong password reduces the likelihood that your password can be brute forced if the hash is purchased o
by SCdF 7y ago
This article is weird and contradicts itself.
Having a strong password reduces the likelihood that your password can be brute forced if the hash is purchased online. This helps with "Credential Stuffing", "Password spray" and "Brute force" on their list.
Not re-using passwords means that if one account is successfully compromised it doesn't then mean that others are too. This helps with basically the entire list.
(Maybe it's addressed further down, but the first item in the first table contradicts the premise so I didn't spend any time reading any further.)
- cr0sh 7y agoThere was also weirdness like this: "So, as far as password spray is concerned – your password doesn’t matter – as long as it isn’t in the “most common passwords” top 50 list!" Shouldn't that actually read: "So, as far as password spray is concerned – your password doesn’t matter – if it is in the “most common passwords” top 50 list!" That is - don't use a common password (and don't reuse passwords), and your chances of a compromise go down greatly? But this wording (and it's repeated similarly elsewhere in the article) seems backwards, unless I'm misinterpreting it?