4 ms·
A password manager solves this problem as well. Even if the user choses to use a low-entropy password for his locally stored safe, the actual passwords generat
by usrbinbash 5y ago
A password manager solves this problem as well.
Even if the user choses to use a low-entropy password for his locally stored safe, the actual passwords generated (which the user doesn't even need to know) for the services he accesses will be of high quality, and unique to every service.
The only point of vulnerability is then if the device gets stolen/hacked, but that's a proble that one entity has to deal with, instead of a problem that affects millions of users like a DB leak full of weak passwords.
- willis936 5y agoA password manager is higher energy than reusing the same low-entropy password directly. So no, it does not solve the password problem.
- usrbinbash 5y agoUsing a PKI, or a hardware token, or MFA or any other method is also "higher energy" than reusing the same low-entropy password directly.
- willis936 5y agoUnless, of course, passwords were no longer made an option. Pushing down the energy of alternatives that are secure enough is important work.
- usrbinbash 5y agoPasswords will be an option as long as comfort is a selling point.