This is sophware's Typepad Profile.
Join Typepad and start following sophware's activity
Join Now!
Already a member? Sign In
sophware
Recent Activity
This article seems like good knowledge, in-depth analysis, and bad advice. There's no easy solution, but this implementation would be disaster. Gawker and J. Random aren't necessarily the real problems (especially with the options of cascade of passwords, LastPass, KeePass, Password Safe, SuperGenPass, home-made transform using hash algorithm, etc.). Examples of real problems: Using the same password everywhere, passwords that can be reset via email or challenge questions, and sites that don't allow strong passwords. The idea in this article would be a real big problem. 7 ways, just off the top of my head, to pwn someone with this "centralized risk:" http://sophware.posterous.com/even-coding-horror-may-not-have-a-good-answer
Toggle Commented Dec 16, 2010 on The Dirty Truth About Web Passwords at Coding Horror
sophware is now following The Typepad Team
Dec 16, 2010