Who need XSS when you can simply ask?
reddit.com
reddit.com
Some wise guy decided to have a little joke, and posted a comment instructing people to copy and paste a snippet of Javascript on their URL location bar. A lot of people (presumably "web programmers") did as instructed. That little snippet posts a comment on that same thread, instructing the next person to do the same. That entire reddit thread is overrun with those script generated comments.
Social lesson: we are fked as far as security is concerned, if that reddit thread is any indication: even programmers would sheep-like do as they are instructed. I suppose that was the "lesson" the wise guy had in mind.
Some good samaritan posted another Javascript snippet to clean up the reddit thread - automatically downvote the spam comments or hide them.
(And Ming can be merciless about such things)
For example, if I am in IT and I tell people to choose a 512 character password with alphanumeric characters that changes every day and doesn't repeat any sequence that appeared in a previous password or contain a dictionary word, I can expect people to write their passwords down on paper and get hacked, even if I tell them not to write it down.
But I can always blame them for writing them down, few people will blame me for being too lazy to find another way to secure the system.
1. Choose a memorable (read: simple, dictionary, insecure) password
2. Choose a good password and write it down
If Joe the Cubedweller writes his login password down on a sticky note, the only other people who are expected to have physical access to that note are him and the other cubedwellers, and they're going to have little to gain from seeing it. I would be much more concerned with Joe picking a bad password that could be guessed by an attacker on the outside.
This argument presents a false dichotomy, as the issue is not how strong to make passwords, but whether there are other security mechanisms that could be used in conjunction with passwords or instead of passwords.
My point is that a password places all the blame on Joe instead of on IT, so IT prefers passwords :-)
MySonPlaysLittleLeague is a password that someone can easily remember, but few people get pointed in the direction of good sentence passwords, and most password policies indirectly limit the use of sentence passwords with character limits or number and punctuation requirements.
Another method that I have used in the past is leet-speak (oh look at me, aren't I cool - cough, cough), so I just used my name and converted it: Haitsma became H41t5m4, very similar to a random string, yet very memorable (depending on your interpretation of leet-speak, of course)
The phrase: "How are you" is 你好吗? Romanized, that becomes ni3 hao3 ma3. So a password might be ni3hao3ma3 or n13h403M43.
I own both, I've read both, but the rhino book is the one sitting on my desk 24x7.
Way to prove my belief wrong!