Remove heres-why-insert-thing-here-is-not-a-password-killer
article thumbnail

Here's Why [Insert Thing Here] Is Not a Password Killer

Troy Hunt

These days, I get a lot of messages from people on security related things. Often it's related to data breaches or sloppy behaviour on behalf of some online service playing fast and loose with HTTPS or passwords or some other easily observable security posture. It's totally going to kill passwords! I know, massive shock right?

Passwords 227
article thumbnail

Generated Passwords, UX and Security Absolutism

Troy Hunt

So why doesn't every site take away the ability for people to choose their own passwords? Why not just generate the password for them thus completely eradicating password reuse? It doesn't matter who generated the password. passwords ?? So the root cause is credential reuse. Absolute genius!

Passwords 162