Hornbein
Gold Member
- 3,507
- 2,886
Yes, I have for years thought those big passwords are silly. You have to record them somewhere, and that record is then a security risk.Algr said:The brute force "try every password" attack was completely solved decades ago. (Just disallow more than one attempt per second.). All these giant untypeable unmemorizable O0Il| sensitive passwords are just bad security experts passive aggressively punishing users, and finding ways to blame users for bad product design.
Realize though that the true goal isn't to make the the user safe. The goals are to make the user feel safe and make sure someone else gets the blame if something goes wrong. There is also a big pressure for conformity. If everyone else goes to big passwords and you don't then in court you can be accused of laxity. An effective defense is to show you did what everyone else was doing.