As far as password cracking is concerned, it has a HUGE bottleneck as discussed here, http://security.stackexchange.com/a/25392
The only threat to safety will be the human element as btilly suggested.
The only threat to safety will be the human element as btilly suggested.
I know at least two websites that ask for a username, a password, and they also give a capcha. I have some websites that won't let Chrome save my password.
Really, I want a hardware thing with a long secure passphrase, that has all my other usernames and passwords (12 character alpha numeric with upper and lower case) in it, that confirms my identity to all these different websites. (Can I do this with Yubikey? or anything else?)
Similar project without the hardware is mozilla's persona, which is an open standard if im not wrong and it is better than signin using fb or gmail, as it wont be sharing any user data with website.