Passwords are not going away - Per Thorsheim - NDC Security 2022

Поділитися
Вставка
  • Опубліковано 20 жов 2024

КОМЕНТАРІ • 10

  • @dtkedtyjrtyj
    @dtkedtyjrtyj 2 роки тому +6

    YES! Never force password change.
    I've cancelled paid services because they require me to change password.

    • @tactileslut
      @tactileslut 2 роки тому

      When forced to change it frequently I will carry it with me, character accurate, as I'll lose muscle memory and won't get it from stored hints within the usual tolerance for guesses.

  • @pedro_8240
    @pedro_8240 2 роки тому +3

    27:05 not that you should be using SMS for that, anyway, considering how unsafe that is.

  • @manmohanmundhraa3087
    @manmohanmundhraa3087 2 роки тому

    In many sites there is policy to change password on certain interval. This is prominent in finance, banking and investment related website. How to remember or get such changing password scenario?

  • @colbyboucher6391
    @colbyboucher6391 5 місяців тому

    TLDR use password generators and store them somewhere secure because the big danger is the ease of getting cracked

  • @Rx7man
    @Rx7man 2 роки тому +1

    does forcing punctuation/caps/numbers actually help much? Logically speaking, you're reducing the possible combinations

    • @ntl7775
      @ntl7775 2 роки тому

      Yes, but if you don't force it people would probably use words that can be found in a dictionary and thus guessed more easily. Like their favorite animal or something

    • @jurgen9568
      @jurgen9568 2 роки тому

      Code is written that way because it is easy to implement. The proper way to write the code is to check the password complexity. And then fail if it is too easy. So if you use only lower case characters but it is 40 chars long that should be fine. Programmers are lazy and a bit dim.

  • @longdench
    @longdench 2 роки тому

    comment