3 ms·
^ This. We should teach users to put their passwords into very few, limited, and trusted places. The cool new social app is NOT trusted. That random app on you
by caseysoftware 3y ago
^ This.
We should teach users to put their passwords into very few, limited, and trusted places. The cool new social app is NOT trusted. That random app on your phone is NOT trusted.
There's even an xkcd on this one: https://xkcd.com/792/ https://xkcd.com/792/
- pmontra 3y agoThat xkcd is about the downside of using the dame password on many services. No service is really trusted so what we should teach people to do is, as usual, to use a password manager to randomly generate a new password for every service. Maybe that's what you were advocating but it was not clear to me. We should also teach to ourselves to throw away all those weird rules about passwords, like 6 to 15 characters max, letters and digits and a random set of punctuation characters liked by the site owner. Why those limits when they are storing a hash anyway?