4 ms·
Pass phrases are more memorable and at least appear more resistant to password cracking attempts, but as Mat Honan's experience and this recent post here on HN
by giantrobothead 13y ago
Pass phrases are more memorable and at least appear more resistant to password cracking attempts, but as Mat Honan's experience and this recent post here on HN (https://news.ycombinator.com/item?id=7142916 https://news.ycombinator.com/item?id=7142916) both show, your account security can come down to a successful social engineering hack on a minimum-wage customer service employee who has the power to reset your account password.
- batoure 13y agoThis is true however a close read of the article you site would show that part of the reason that that hack is possible is because in our current paradigm the idea that someone would have completely forgotten their password. If pass phrases became more common then perhaps customer service reps would be able to be more skeptical of the social engineering ploy that was put to use in this scenario
- giantrobothead 13y agoPerhaps. Unfortunately, that's probably a pretty big "if".
- batoure 13y agoTrue but it would be interesting to see some data on how many over the phone password resets big service providers do on a day to day basis. That kind of data would at least be a litmus to invalidate the current paradigm.
- giantrobothead 13y agoI would like to see some numbers on that. Is it as pervasive as it seems, or are the ones that get through just dramatic enough to set people on edge?
- ben0x539 13y agoMaybe what we really need to do to prevent identity theft is increase the minimum-wage. :)
- giantrobothead 13y agoIt couldn't hurt. At least the general populace's purchasing power would increase.