4 ms·
A lot of talk of passwording concentrates on threats at the technology end, and they ignore threats at the user end. Emailed Passwords are a failure from a tec
by HarrietJones 12y ago
A lot of talk of passwording concentrates on threats at the technology end, and they ignore threats at the user end.
Emailed Passwords are a failure from a tech point of view, but they allow users to create more complex passwords without punishing them when they forget that password.
As it is, I have situations now when the complexity requirements of a password combined with the fact that I need to sign in to a separate mobile App and I'm given no way of seeing what the password was when I created it that I just throw my metaphorical hands in the air, and reset it to generic password "Green!12Letmein." on yet another account.
This is wrong of me. I know it's wrong, I'm aware of password remembering services and I'm technical but I still do it.
If I'm doing this, and you're doing this, then most of the world is doing it. By discounting passwords sent through email, then we may be making overall security worse instead of better.
- aianus 12y ago1Password has mobile apps so you can copy and paste passwords on mobile (pretty rare, since most services will remember you). Once you start using it you get really used to it and you won't go back. You just have to force yourself those first few days.
- x1798DE 12y agoThere's no point in using a secure password if it's stored in plaintext. Brute-force attacks on passwords usually need to be done offline in order to be effective (unless the site happens to not throttle authentication queries), so essentially as long as your password isn't one of the attackers' first 100-1000 guesses (being extremely charitable here), then it doesn't matter if your password is 15 characters or 150 characters, because the primary attack vector (database compromise) will reveal it instantly. Additionally, allowing passwords to be e-mailed is even worse than this, because there's a good chance the password is not encrypted in transit, which means that it can be intercepted on the way to your mailbox. In that case, the attacker doesn't even need to compromise the database to get your password, no matter how complex it is. Storing passwords in plaintext removes security even if it makes people use less complicated passwords.