3 ms·
I was in charge of password policy for a healthcare app. We tried to use phrases, often cited as more secure than character/length requirements. The doctors ha
by lttg 4y ago
I was in charge of password policy for a healthcare app. We tried to use phrases, often cited as more secure than character/length requirements.
The doctors hated it. They didn't understand what a phrase was, it was too different from every other system they interacted with, and it was extra cog load in their already busy days.
- nicoburns 4y agoWhy not just have a length requirement and recommend a phrase? “Passphrase” isn’t that common a word, so it merits an explanation. But “your password has to be long, but you don’t need to use special characters, and can use regular english word if you want” is surely easy enough to understand.
- puffoflogic 4y ago> it was too different from every other system they interacted with Translation: they couldn't use the same standard password they use for their banking, their email (also used for 2fa), Facebook, and this porn site they found by clicking on a pop-up ad.