You will soon come to the conclusion that it is still easier to teach people to use a password manager for this because these schemes are nice but only get you this far before you have to revert to remember that single password again.
You will soon come to the conclusion that it is still easier to teach people to use a password manager for this because these schemes are nice but only get you this far before you have to revert to remember that single password again.
For example; your "password" could be a combination of words, numbers, and characters while the "thing you know" is something like capitalizing the even or odd first character corresponding with the even or odd number corresponding to the first letter of the site or company, and combine that with the even or odd sequenced number and character in their sequential location in the password or at the end or beginning of the entered password.
I'm sure I could describe that more clearly if I tried.
The second main reason passwords suck (after the fact users trend to choose weak passwords) is that developers implement all sort of contradicting password rules.
Can't wait till we check min entropy and otherwise don't care.
At Schwab I'm using 31 characters randomly generated by LastPass for a login name but they limit things to 8 characters for a password.
Absolutely crazy. Even if they are not having problems, why should customers like us have to worry about it?
http://www.schwab.com/public/schwab/client_home/password_for...
Between now allowing very long passwords, the free 2 factor token (hardware symantec vip, not SMS based), and being able to lock your accounts with a voice password/passphrase that you must give the rep to discuss your account on the phone (so then just SSN/mothers maiden name/birthdate isn't enough), I think they've pulled quite far ahead lately. It's better than any of the other banks I've used.
[Note: voice password is not their voice fingerprint sillyness their reps will think you are asking about at first]
Oh, but they have a 4-digit pin, too! That makes it oh so much more secure.
They had two factor authentication though, with a phone call or SMS. What happened if you forgot your password? Well you had to reset it, using only phone call/SMS, of course!
It's the most bizzare password requirement I have ever seen and I am pretty sure it's not secure. Have I mentioned it only works in IE and uses ActiveX controls?
Inclusive, I hope.
american express use to enforce insane limits on passwords back in 2010[0]. 6-8 characters for passwords, no special character and had to have 1 letter, 1 number and it wasn't case sensitive. unfortunately _I_ had an amex card.
that page i linked to also has a reply from amex support who shows little knowledge about the difference between passwords and website encryption.
they eventually started expanding that limit from 6-8 characters to 8-20 characters around 2012? 2013?
[0] http://securitywatch.pcmag.com/e-commerce/284119-amex-passwo...