Largest Study of its Kind Shows Outdated Password Practices are Widespread::undefined

  • 9point6@lemmy.world
    link
    fedilink
    English
    arrow-up
    54
    ·
    1 year ago

    Length is the most important thing, everything else is somewhat secondary. We should be shifting thinking of this to passphrases rather than passwords.

    I’m sure most of us have seen the “correct horse battery staple” XKCD, but that’s what people really need to think of as passwords now, not my-favourite-celebrity-but-with-the-“e”-changed-to-“3”-and-an-exclamation-mark-at-the-end.

    • wavebeam@lemmy.world
      link
      fedilink
      English
      arrow-up
      14
      ·
      1 year ago

      Nah fuck that. Sites need to adopt this passkeys instead. It’s an impossible task for people to have unique credentials for every site, even if they are “memorable”. This is a design issue not a personal responsibility one. When designing for large volumes of people, you have to assume that the majority will do something easy and stupid over difficult and smart.

      • GissaMittJobb@lemmy.ml
        link
        fedilink
        English
        arrow-up
        15
        ·
        1 year ago

        Until they do, password managers get you most of the way there, by letting you have a single password on your side, mapping to one password for each login. Bitwarden is great, and free.

      • themoonisacheese@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        10
        ·
        1 year ago

        Sites need to stop needing an account for everything. My haveibeenpwnd is full of sites that I can’t believe had my email in the first place. Obviously I gave it to them but like cmon