Close Menu
Ztoog
    What's Hot
    Gadgets

    The best 3D printers under $500 for 2023

    AI

    Google DeepMind and the University of Tokyo Researchers Introduce WebAgent: An LLM-Driven Agent that can Complete the Tasks on Real Websites Following Natural Language Instructions

    Mobile

    Samsung Galaxy S24 Ultra is the new best smartphone camera: PhoneArena Camera Score

    Important Pages:
    • About Us
    • Contact us
    • Privacy Policy
    • Terms & Conditions
    Facebook X (Twitter) Instagram Pinterest
    Facebook X (Twitter) Instagram Pinterest
    Ztoog
    • Home
    • The Future

      What is Project Management? 5 Best Tools that You Can Try

      Operational excellence strategy and continuous improvement

      Hannah Fry: AI isn’t as powerful as we think

      FanDuel goes all in on responsible gaming push with new Play with a Plan campaign

      Gettyimages.com Is the Best Website on the Internet Right Now

    • Technology

      Iran war: How could it end?

      Democratic senators question CFTC staffing cuts in Chicago enforcement office

      Google’s Cloud AI lead on the three frontiers of model capability

      AMD agrees to backstop a $300M loan from Goldman Sachs for Crusoe to buy AMD AI chips, the first known case of AMD chips used as debt collateral (The Information)

      Productivity apps failed me when I needed them most

    • Gadgets

      macOS Tahoe 26.3.1 update will “upgrade” your M5’s CPU to new “super” cores

      Lenovo Shows Off a ThinkBook Modular AI PC Concept With Swappable Ports and Detachable Displays at MWC 2026

      POCO M8 Review: The Ultimate Budget Smartphone With Some Cons

      The Mission: Impossible of SSDs has arrived with a fingerprint lock

      6 Best Phones With Headphone Jacks (2026), Tested and Reviewed

    • Mobile

      Android’s March update is all about finding people, apps, and your missing bags

      Watch Xiaomi’s global launch event live here

      Our poll shows what buyers actually care about in new smartphones (Hint: it’s not AI)

      Is Strava down for you? You’re not alone

      The Motorola Razr FIFA World Cup 2026 Edition was literally just unveiled, and Verizon is already giving them away

    • Science

      Big Tech Signs White House Data Center Pledge With Good Optics and Little Substance

      Inside the best dark matter detector ever built

      NASA’s Artemis moon exploration programme is getting a major makeover

      Scientists crack the case of “screeching” Scotch tape

      Blue-faced, puffy-lipped monkey scores a rare conservation win

    • AI

      Online harassment is entering its AI era

      Meet NullClaw: The 678 KB Zig AI Agent Framework Running on 1 MB RAM and Booting in Two Milliseconds

      New method could increase LLM training efficiency | Ztoog

      The human work behind humanoid robots is being hidden

      NVIDIA Releases DreamDojo: An Open-Source Robot World Model Trained on 44,711 Hours of Real-World Human Video Data

    • Crypto

      Google paid startup Form Energy $1B for its massive 100-hour battery

      Ethereum Breakout Alert: Corrective Channel Flip Sparks Impulsive Wave

      Show Your ID Or No Deal

      Jane Street sued for alleged front-running trades that accelerated Terraform Labs meltdown

      Bitcoin Trades Below ETF Cost-Basis As MVRV Signals Mounting Pressure

    Ztoog
    Home » Passwords and their Discontents – O’Reilly
    Technology

    Passwords and their Discontents – O’Reilly

    Facebook Twitter Pinterest WhatsApp
    Passwords and their Discontents – O’Reilly
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp

    This article initially appeared in Business Age.

    In commentary equipped to Business Age, I shot my mouth off saying that passwords are a poor resolution for authenticating customers–however not one of the options are superb, both. The selections obtainable to us are at greatest poor.  So now I’m the sufferer of a follow-up query 🙂 What do I take advantage of?



    Learn quicker. Dig deeper. See farther.

    Unfortunately, “what do I use” isn’t actually a selection I get to make–as a rule, you’re caught with the alternatives of the individuals who constructed the websites you utilize. So the perfect you are able to do is be sure you have a great password. An excellent password is a protracted string of random letters, numbers, and punctuation marks. There are a number of methods of producing these. The easiest one is to let Google Chrome generate a password for you. (Firefox may generate safe passwords.)  While Google is broadly mistrusted, I believe that distrust is misplaced.  Google hasn’t been the sufferer of serious safety breaches (not like some well-known password managers), and they actually have little interest in promoting my passwords to different events. Yes, zero-day exploits and frequent safety updates to Chrome signifies that there are vulnerabilities–however it additionally signifies that vulnerabilities are detected and patched. We ought to all be way more involved about software program that isn’t up to date often. 

    Creating your personal good password is barely barely tougher than letting your browser do it for you–and, frankly, simpler than creating a nasty password (although not simpler to recollect). I open a textual content window and kind randomly on my keyboard for a number of seconds, yielding one thing like this: oe8h;org’pr/sajidj. (That’s 18 characters, generated in a few seconds.) I copy it and paste it into an utility that wants a password. If it asks for punctuation, a digit, or a capital letter, I’m going again to the textual content window, add one thing that appears random, then copy and paste once more. The copy/paste course of permits you to fill within the “retype new password” discipline with out error. (If pasting isn’t allowed, I query whether or not I wish to use that service.) Again, I let my browser save the password. It will synchronize throughout all my gadgets, which signifies that I don’t want to take care of a listing of passwords.

    And what about two-factor authentication (2FA)?  Yes, positively–use it wherever potential.  A textual content to my cellphone isn’t superb, however it’s sufficient, and preferable to sending a code to e mail.  There are methods to assault an SMS to your telephone, however it’s not straightforward. But watch out–I as soon as had an app that may let me textual content from my laptop computer. If anybody texted me, it could show the textual content in a popup window on the laptop computer, which defeats the aim of 2FA. In common, you wish to obtain the safety code on a special system from the one you’re utilizing to login. That’s an issue when you’re utilizing a telephone; I don’t have a great resolution.

    Password rotation? I resist that, though an authentication supplier that I’ve to make use of requires it. The safety neighborhood has lengthy recognized that forcing customers to alter passwords regularly is a nasty observe. It encourages customers to decide on simply remembered passwords, and that’s the alternative of what we wish. Think about it: if a random password hasn’t been brute-forced previously 3 months, why do we predict it’s extra more likely to be brute-forced within the subsequent 3 months?  I get it–corporations must take care of insurers, and maybe forcing customers who’re by no means going to provide you with good passwords to alter passwords frequently is a win. I don’t wish to take into consideration these statistics. But one good password is infinitely higher than a nasty password that’s modified frequently.

    So–that’s what I do. It’s not elegant, and please don’t declare that it represents any “best practices.”  But that’s not likely the purpose. What I select to do is irrelevant, as a result of I’m on the mercy of the individuals who create the websites I take advantage of. And their practices could be shockingly dangerous. Here’s an actual instance. I pay an aged relative’s medical payments. Let that sink in:  we’re speaking one of the crucial privacy-conscious and closely regulated industries on the planet. Recently, I received a authentic request to pay a invoice, with a hyperlink to a website the place I can view it and pay. The e mail tells me that the account quantity, person title, and password are ALL THE SAME. And the account quantity is contained within the e mail. (And simply guessable.) That’s past horrendous. 

    It’s unlucky that there aren’t extra good options on the market, and that options like bodily safety keys aren’t extra broadly used. There was hope that passkeys would make passwords go away, however that hope is fading. Biometrics? If my Pixel telephone would do a greater job of figuring out my fingerprint or recognizing my face after I take my glasses off, we may speak about that various. However, wishing that we had a greater resolution received’t clear up the issue. Random passwords (no matter the way you generate them) and two-factor authentication are the perfect options now we have now.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp

    Related Posts

    Technology

    Iran war: How could it end?

    Technology

    Democratic senators question CFTC staffing cuts in Chicago enforcement office

    Technology

    Google’s Cloud AI lead on the three frontiers of model capability

    Technology

    AMD agrees to backstop a $300M loan from Goldman Sachs for Crusoe to buy AMD AI chips, the first known case of AMD chips used as debt collateral (The Information)

    Technology

    Productivity apps failed me when I needed them most

    Technology

    Makers are turning discarded vapes into tiny musical instruments

    Technology

    Best 85-Inch TV for 2026

    Technology

    Breaking Boundaries in Wireless Communication: Simulating Animated, On-Body RF Propagation

    Leave A Reply Cancel Reply

    Follow Us
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    Top Posts
    Gadgets

    Save $20 on a two-pack of MFi-certified rainbow lightning cables

    We might earn income from the merchandise obtainable on this web page and take part…

    Technology

    Veteran life sciences firm RA Capital spins up ‘planetary health’ team to ride climate tech wave

    Something that usually will get misplaced in discussions about climate change is the large well…

    Gadgets

    Qualcomm Expands Digital Chassis For Motorcycles And New Vehicles

    Qualcomm Technologies, Inc. has expanded its Snapdragon Digital Chassis portfolio to cater to the rising…

    Mobile

    Weekly poll: how old is your phone?

    Fairphone is promising 8 years (probably as much as 10) of help for its new…

    Technology

    Breaking Boundaries in Wireless Communication: Simulating Animated, On-Body RF Propagation

    More Information In the design and growth of wi-fi gadgets for body-worn purposes, a number…

    Our Picks
    Mobile

    Pixels may soon stop cutting off app names in the launcher and search

    AI

    Meet Sailor: A Suite of Open Language Models for Bridging Linguistic Barriers in Southeast Asia

    Gadgets

    Samsung Galaxy S24 Series Set To Launch In January 2024

    Categories
    • AI (1,560)
    • Crypto (1,826)
    • Gadgets (1,870)
    • Mobile (1,910)
    • Science (1,939)
    • Technology (1,862)
    • The Future (1,716)
    Most Popular
    Gadgets

    The best smokeless fire pits for 2023

    Mobile

    Samsung Galaxy Tab S9 review: Should you buy it?

    Crypto

    Top Crypto Movers of the Week

    Ztoog
    Facebook X (Twitter) Instagram Pinterest
    • Home
    • About Us
    • Contact us
    • Privacy Policy
    • Terms & Conditions
    © 2026 Ztoog.

    Type above and press Enter to search. Press Esc to cancel.