3 ms·
Isn't it time governments start to regulate passwords ? (They already regulate a lot of privacy issues like medical and financial history. Some governments even
by nroets 3y ago
Isn't it time governments start to regulate passwords ? (They already regulate a lot of privacy issues like medical and financial history. Some governments even regulate the use of finger print authentication of employees)
For example, any website that allows users to choose normal, easy to remember passwords should meet a long list of requirements: For example security audits, bug bounties, capital reserves to deal with class action suits.
Then small websites will start either implement Open ID or encourage their users to use password manages.
- stef25 3y ago> Isn't it time governments start to regulate passwords ? Nah we're good. They already regulate cookies and it's a dumpster fire.
- mclightning 3y agodumpster fire for who?
- concordDance 3y agoUsers constantly having to reclick on popups.
- stef25 3y agoand they don't understand what they're clicking, and they have no transparency.
- nroets 3y agoCookie consent is just a nuisance. Like the cancer warnings in California.
- deleted 3y ago[deleted]
- koheripbal 3y agoThat would not have protected 23andme from this issue. Password complexity does not stop password reuse.
- nroets 3y agoI'm only suggesting password complexity as a compromise so that websites wouldn't need to implement OAuth. (Do you have a better comprise ?) Password complexity encourages the use of password managers. They in turn remove the need to reuse passwords.
- BrandoElFollito 3y agoPlease have a look at the "recommendations" of your national security agency (except NIST). It is all outdated, written by people who thought they understood security in the 90's. The French ANSSI recommendations are ridiculous. The German as well. Having an incompetent gov org forcing you to apply their "best practices" is terrible. We have already for banks and look at what they have done: all possible "don't do it!" implementations neatly on one page (source: Boursobank, Fortuneo and other French banks who replay that the security is "reviewed by experts")