5 ms·
> None of this is helped by ... the continued low uptake of password managers to both store and generate passwords This article contains reasonable advice, but
by dfdz 5y ago
> None of this is helped by ... the continued low uptake of password managers to both store and generate passwords
This article contains reasonable advice, but I am not sure that is advice that anyone is interested in. Let me explain.
Most of my tech savvy friends/family use password managers (either digital or paper), two factor authentication, and sometimes hardware authentication devices for important accounts.
In contrast, most of my non-tech savvy friends/family do not care about password entropy or really anything to do with security. If the complexity requirements cause them to forget a memorized password, then they reset using their email.
Edit: Actually people forgetting their passwords because of complexity requirements might be useful, since it forces people not using a password manager to login by clicking a link from their email (which is better than a weak password) In this light, maybe companies should start to enforce even more crazy requirements at least 4 numbers, 4 symbols, 8 characters