The 25 worst passwords of 2013: 'password' gets dethroned
pcworld.com
pcworld.com
The users are actually quite smart in deciding how much effort is adequate for the realistically expected risk to them. Unless their perception is manipulated.
Article is garbage: sample is clearly biased.
1. Something you know: password, secret question, mother's maiden name. These can be forgotten. If the information is generated by the user, it has the potential to be something easily guessed.
2. Something you have: SSH key, GPG key, RSA token, Yubikey, Google Authenticator. These can be quite secure, but hard to use. Losing a physical auth token deprives the user of access. SSH/GPG key pairs depend on the security of the system(s) they're stored on.
3. Something you are: fingerprint, retina scan, face recognition, voiceprint. These are irrevocable and anathema to privacy. Worst of all, they're not very reliable or secure. Fingerprint scanners are stymied if one has recently been lifting weights or rock climbing. Face recognition is affected by lighting, makeup, glasses, hair, sunburn/tan, age, etc. Voice auth is a joke. It can fail due to emotional stress, sickness, or background noise.
Combinations can be used for more secure authentication, but so far nothing has been as simple or as convenient as a password.
> 23. azerty
Thank you france.