5 ms·
As computer people we should move away from teaching people that a strong password is one that is made up of random numbers, letters, symbols, and is hard to re
by JungleGymSam 12y ago
As computer people we should move away from teaching people that a strong password is one that is made up of random numbers, letters, symbols, and is hard to remember. Instead, let's teach them to create much longer passwords that are nonsensical sentences.
*You can't beat the carrot!
OR
Passwords? They're for Sundays.
- SideburnsOfDoom 12y ago> let's teach them to create much longer passwords that are nonsensical sentences. Doesn't matter; nobody is going to remember fifty different ones. I have more website logins that that. Password reuse is going to happen and it is bad. The only secure way is for each password to be made up of a unique long, generated string of "random numbers, letters, symbols" for maximum entropy and stored in a password manager. The user just has to remember the password manager's master password (and maybe a desktop PC login). Now these remaining memorised passwords can be long nonsensical sentences if need be.
- JungleGymSam 12y agoI did a really poor job of explaining myself. Really poor. I meant the master password. Mitro's password strength meter uses guidelines which are becoming (are?) old. So let's just move away from that altogether (for passwords that people should remember) and doing something that makes it easy to use lots of characters.
- buyx 12y agoFNB South Africa is a bank that has horribly complex rules for passwords - no repeated letters, no sequential letters, in addition to the normal password strength requirements. Given the complexity, many people I know just save their passwords in plain-text.