Become a fan of Slashdot on Facebook

 



Forgot your password?
typodupeerror
×

Comment Re:We already know that. (Score 1) 242

But that's why I said the government doesn't need to mandate any specific policies. They just need to mandate that some organization is set up and produces some reference implementation that's kept up-to-date continuously, and that every site must either use/contribute-to that implementation, or at least follow the latest policies of that implementation.

Comment Re:We already know that. (Score 3, Insightful) 242

forcing pw changes every 60 days with a 15 pw history that cant repeat.

I said:

kept up-to-date with current best-practices

As I understand it, password changes is not current best-practice. Thank you for highlighting my point. Best practices are too hard to keep up with manually. It's better if you have reference implementations that removes these out-of-date practices as fast as possible, and have developers use these, instead of having to trust each developer to be properly and timely educated, on top of implementing the new rules correctly.

You should learn to read and carefully consider what has been said, before trying to nitpick with a point that is already accounted for.

As for 2FA, that's a shit solution. You shouldn't have to have a phone just to use websites. We need a better way that's not dependent on a phone that could get lost, or you'd have to change and then you'd have to remember to update every possible website with your phone details.

Comment Re: Ditch the password (Score 4, Insightful) 242

The "lifehack" I've heard some people use is to just use random answers to security questions. There is no reason to actually put your mother's maiden name for the security question of your mother's maiden name. They're not actually going to verify your mother's maiden name. All they'll verify is if they ask you the question and you provide the answer that was recorded.

So your mother's maiden name could be an arbitrarily long phrase that's easy to remember but has no actual content related in any way to your mother's maiden name.

Slashdot Top Deals

He has not acquired a fortune; the fortune has acquired him. -- Bion

Working...