logoalt Hacker News

ulfbert_inc • today at 10:49 AM • 4 replies • view on HN

You are presenting a false dilemma (probably unintentionally). While security can be at odds with usability, basic measures like password generation and management are a solved problem. In fact using password manager is more convenient than typing password manually, even 123456 :)


Replies

looperhacks • today at 12:19 PM

Unless of course, you need to unlock your password manager, which is not integrated with your browser, because corporate IT doesn't allow browser extensions or desktop apps so you're bound to a web app ...

xandrius • today at 11:08 AM

Ha, I don't need to type 123456, it's stored in my navigator's password manager for convenience. Checkmate.

➕ show 1 reply
dudul • today at 2:56 PM

Until security forces the password manager session to expire after 1 hour, and forces the master password to be 16 char long with a combination of lower, upper, digit, punctuation, moon phase, astrological sign. And then they force you to change it every 2 months, and you can't reuse it until the next time Halley's comet is in the solar system.

You're missing the systemic problem the parent is talking about.

➕ show 1 reply
holowoodman • today at 12:05 PM

Next step in typical security team fashion: Prevent password managers from working, by obscuring the password field, using click-to-type passwords or similar shenanigans, because fuck you, that's why...

➕ show 1 reply