California Bans Weak Login Credentials

Yea, I'm surprised this isn't pushed more by password rules. Fuck special character and numbers. Just enforce a minimum of 20 letters.

Personally? There's no reason that every site in existence needs to manage it's own user/password credentials. Ideally this would be handled by the OS (with a way to import across multiple devices of course) so you only need to verify, rather then store passwords across hundreds of different sites. With what we have now, your only as secure as the weakest site's security.

password_reuse.png




(Seriously, there's an xkcd for everything)
 
Personally? There's no reason that every site in existence needs to manage it's own user/password credentials. Ideally this would be handled by the OS (with a way to import across multiple devices of course) so you only need to verify, rather then store passwords across hundreds of different sites. With what we have now, your only as secure as the weakest site's security.

View attachment 110976



(Seriously, there's an xkcd for everything)
I actually prefer SSO. Have one with 2FA and use it for everything. Way more secure.
 
Back
Top