> But using weak and/or compromised passwords is a bad idea in exactly the same way that it's a bad idea to leave your front door unlocked.
I'd argue it's not quite the same... using weak passwords is more like using a lock that can be 'raked'; your security is just lax.
Re-using passwords is like using the same key for your front door, back door, garage, car... If someone finds it and makes a copy of it, they have full access.
Compromised passwords, it's when you know a key is lost or stolen and you don't re-key.
> From a policy perspective, I think the most appropriate thing would be a middle ground. It is good for everyone's peace of mind to be sure that your entire bank balance won't vanish without recourse, but if you leave your banking "front door" unlocked, the bank covers 90% of the actual unrecoverable loss, but you're on the hook for the other 10%. That eliminates perverse incentives to use weak passwords without being cruel to victims.
Both of my main financial institutions have 'pretty dang good' security measures on one level or another. One, has forced password changes at 6 month intervals (not as good as 90 days, but better than many!) The other does not have forced password changes but I know their internal security is... pretty crazy. Losing your badge 3 times is enough to get you fired, and any contractors who do work must be under a very specific specification of video surveillance while working with their clients.