11 votes

Four insecure standards we can't easily abandon

7 comments

  1. balooga
    Link
    I'm annoyed that Steve Gibson's SQRL zero-password login spec never took off, and honestly I blame him for creating the thing and basically abandoning it on day one. Tons of potential there, but...

    I'm annoyed that Steve Gibson's SQRL zero-password login spec never took off, and honestly I blame him for creating the thing and basically abandoning it on day one. Tons of potential there, but it's like he got bored and went back to tinkering with SpinRite. I say that as a huge fan of his Security Now podcast for many years.

    In the right hands, SQRL could've been a game-changer. Honestly it still could, if proper advocates took notice of it.

    7 votes
  2. [5]
    UntouchedWagons
    Link
    I don't mind passwords so long as sites don't have stupid restrictions on them like requiring special symbols or numbers.

    I don't mind passwords so long as sites don't have stupid restrictions on them like requiring special symbols or numbers.

    1 vote
    1. [4]
      MimicSquid
      Link Parent
      I don't mind passwords so long as sites don't have silly restrictions on them like forbidding symbols.

      I don't mind passwords so long as sites don't have silly restrictions on them like forbidding symbols.

      6 votes
      1. [2]
        mat
        Link Parent
        Have you encountered anywhere that allows emoji in passwords? I've always thought that would be a good way to add entropy.

        Have you encountered anywhere that allows emoji in passwords?

        I've always thought that would be a good way to add entropy.

        6 votes
        1. Tardigrade
          Link Parent
          What's stopping it from working generally beyond sites testing and rejecting it? Also turns out Tildes does support it.

          What's stopping it from working generally beyond sites testing and rejecting it?

          Also turns out Tildes does support it.

          1 vote
      2. arghdos
        Link Parent
        My favorite is when different interfaces to the same service accept different password lengths / restrictions. For instance: I cannot log into my Southwest account on my phone even when...

        My favorite is when different interfaces to the same service accept different password lengths / restrictions.

        For instance: I cannot log into my Southwest account on my phone even when copy-pasting the password from KeePass… the same password that works just fine on desktop.

        3 votes