For sites where I don't really care about security (present company included :), I use a passphrase, usually in the form of a mnemonic. As an example, the password I may choose for this site would be "Hack_G1bson_RedPill_KungFooey" Much easier to remember and it only makes sense to me. Also, for apps like Dropbox, you better be using multi-factor authentication.
I can't do this for every site because of their tyrannical password requirements. I wish they used overall password complexity as an entropy threshold instead of 1 lower, 1 upper, etc.
If Im feeling "community minded" that day, I might email their contact address and tell them why I didn't complete the signup process - if I'm in a stabby mood I'll more likely just lampoon them as morons on Twitter. doubt either action on my part makes any difference.
You could argue that if someone doesn't care for their digital security that's their problem, but we live in a time when one single careless employee can screw over 60 million people, as it was the case with Dropbox.
However, I think being able to use the same stupid password on all sites I do not care about is a feature rather than a bug.
I had a "stupid" multiply re-used password exposed in a breach of PerlMonks (which I didn't really care about in 2007 or so) which I also used when signing up to check out yet another new social media site in 2008. A couple of years later my Twitter account was sending Acai berry spam to my friends...
(And even if new-site-de-jour doesn't turn out to be something you stick with, it's now got your name (or regular handle) with the risk of damaging your reputation when it gets exploited without you even knowing...)
Yeah, I mean, my friends talked me into signing up for some stupid site back in 2005, "Face"-something? Seemed pretty trivial to me.
(IIRC in all seriousness Facebook's password requirements were hilariously trivial back when they first started.)
Thinking about it, my account was added by a company using Azure, perhaps they are able to set the password restrictions for their sub-accounts...
If you have deals with many strangers do you not expect to get your hands dirty in some way?
This was something I changed when I realized that a tax related government agency's machine I was using about 10 years ago man in the middled SSL connections to my online banking. Who knows what was logged and what the retention on that was? I don't have time or the inclination to ensure every relative's / customer's devices are secure, so I use my own or go without.
In practice, it would mean replacing most of the world's user-facing computer infrastructure.
The card reader doesn't have to be any more tamper-resistant than the rest of the computer. On a public terminal, it should probably be built like an ATM's card slot (and the rest of the machine should be similarly armored), but on a personal computer it doesn't need to be any more robust than the keyboard a user would otherwise type passwords in with. The card-computer communication is all encrypted anyway, so even if it's built like any old USB peripheral it's still better than typing into a keyboard.
The first makes your public key useless for security. The second locks you out of everything.
So you've still got to have patterns-of-fraudulent-use detection, and some sort of token-reset mechanism.
Persistent data encryption is another option, but that compounds the key-loss problem in that you cannot access earlier data.
I have an encrypted file with website|username|password on my laptop to allow for unique passwords across sites. But it's a pain, and definitely not something everyone will do.
It's shameful that it's so much easier to find tutorials on how to store passwords "securely" (including several tutorials that tell you crazy insecure things, like storing with unsalted commodity hashes) than it is to find tutorials on how to integrate your brand new battling-fairies website game with OAuth for authentication.
I think it's going to have to be legislated:
1. Mandate that all publicly disclosed passwords are collected in a compiled set.
2. Require that any Internet service vendor check against this set on password change revisions, and against different portions of the file, as maintainable, on each authentication.
Known passwords are rejected when set, and mandate changes when detected on login.
Asking a 76 year old mostly-computer-illiterate pereson to come up with a never-been-used-before password simply doesn't work.
This also means mandating password safes on all consumer-grade OSes. Apple already does, Microsoft and Android. For Linux, you might be semi- on your own, though most distros offer several options.
I'd also like to see 2FA via a keyfob generator rather than contact token (e.g., phone, email).
Do all login through OAuth or the related proprietary "login with" mechanisms Facebook and Twitter have. Offer your users a choice of mechanism, in the signup flow, and don't require that they first set up a password that they then replace with login-with-(whatever).
If you can't imagine what this looks like, open an incognito browser and go through the signup-for-an-account flow at stackoverflow.com. That should be what you're aiming for.
None that will not dissuade potential paying customers, though.
Then, you reinforce that by using some sort of SSO setup/service (you can outsource this to someone like okta.com if necessary), so that all internal systems never have a place to set a password. (e.g., don't make people set up separate accounts with passwords on the corporate jira or bitbucket server)
Basically, not training people to reuse passwords internally can help them to not reuse their one internal password externally.
Another possibility is to simply buy a password manager subscription for every employee and have it as a perk. That's a per-employee overhead of $20-30/year.
At scale, there's no way you'll get everyone to use good passwords. Random generation is a bad idea, users just write them down if you do that.