  Daniel Premium,MVM join:2000-06-26 Pleasanton, CA clubs: 
| reply to nwrickert Re: Big Sites That Don't Allow Complex Passwords !?!
said by nwrickert :Your argument is invalid simply because over 95% of users still do manage their own passwords. If they actually are trying to remember 55 passwords, then they are probably using very weak passwords and re-using the same password for many sites. And if they are doing that, they have a more serious problem than the one you suggested in your OP. Well, that is the reality we're facing. The question is, how do we mitigate some of this risk? It's a lot harder to get users to change their habits than it is to get a single site that handles millions of accounts to change theirs.
I agree it's not a real solution, but nothing in security ever is. It's about reducing risk, and if we can add ANY significant amount of complexity to the incredibly weak passwords that most people use, we'll have accomplished something. Hence my OP. -- dmiessler.com -- grep understanding knowledge |