The solution is for a standard to emerge that incorporates rotation and (optionally random) password generation used across sites. No more fucking "Login with Google".
The solution is for a standard to emerge that incorporates rotation and (optionally random) password generation used across sites. No more fucking "Login with Google".
A: It's a good idea! B: In theory, yes. In practice, no. A: I'm only talking theory.
Great. The rest of us are talking about practice.
Most people don't use password managers, and some companies block their usage. Now add a requirement of a "secure" password.
This issue for master passwords is a bit harder, yes.
Which will result in two things:
1. LOTS of calls to IT from forgotten passwords
2. People writing their passwords down on sticky notes.
Of course, by remember, I mean put in a .txt file somewhere.
Both of your suggests disregards the user's experience and security is only ever as good as your user's willingness to use it.