in reply to Re^8: Password strength calculation
in thread Password strength calculation
but as they don't take notice it's actually irrealis :)
This attitude is the real problem. I don't mean you specifically, but generally across the web and beyond.
Users are too stupid to remember more than one long word, so we'll have to force them into using mixed case and puntuation to achieve security!
Ignoring the fact that most of those same users probably remember 2 or 3 or 4 pin numbers for credit cards. And what is a 4-digit pin if you spell it out in English (or Spanish or Japanese)?
Yet every password guide or ruleset I've every read on a website goes with some variation on the 6-8 characters with at least 1 digit and 1 punctuation and "Don't share passwords between sites". We've programmed people into the very habits that lead to all the problems we are now having.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^10: Password strength calculation
by mbethke (Hermit) on Jan 21, 2012 at 18:48 UTC | |
by BrowserUk (Patriarch) on Jan 21, 2012 at 21:04 UTC | |
by mbethke (Hermit) on Jan 21, 2012 at 22:54 UTC | |
by BrowserUk (Patriarch) on Jan 21, 2012 at 23:54 UTC |