Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Unique across all other services the user has accounts at? If you did that it would be both creepy and impressive. :)


Let's start a global registry where everyone registers the password you use at every site. So we can cross reference and check that you (or anyone else) hasn't used that password elsewhere. OF course we will store the password in plain text.


We try to make sure it is by enforcing password expiry, no password reuse and complex passwords. We also have a massive shitlist of passwords from various leaks.


Because of which, your users probably write their password down on a post-it note stuck to their monitor...


That's a lot safer than using a weak password. I don't have a citation handy but security researchers often support writing down passwords to encourage using stronger and more frequently changed passwords.


That depends, if it's on a system that's accessible internally only, then it's likely not safer.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: