Possibly, it is meant as a reminder of something that we should all not forget?
Would the submitter please take the time to clarify the reasoning for necroing this article?
Possibly, it is meant as a reminder of something that we should all not forget?
Would the submitter please take the time to clarify the reasoning for necroing this article?
I mean, many people may have many reasons that got this article to the front page, does it really matter what they are (or what the single reason of the submitter was)?
I was attempting to ask for information that I intended/hoped to stimulate conversation.
I also intended to highlight that the article was 2009; as I spent the time to read it and began a response before I observed the date.
I don't know how prevelant some of the password management tools and two factor authentication was in 2009, but it's common to use them now. Browsers are more sophisticated and the landscape has changed a lot.
That all said the sentiment of the article still stands true. Users (like my family) hate worrying about security.
So as a whole I think now it's an issue of education. Yes I know LastPass is controversial, but it is still better then password1 or 1234.
* Updates still suck, users still can't tell the difference between fake and real ones
* Passwords are still annoying
* 2FA exists, is better than 5 years ago, but most people don't use it because, and this is the articles point, it's still annoying
* Recognizing phishing URLs can still be hard to do, even for tech savvy people
* Cert errors are still false positives (in that there is no danger, not that there is a technical issue) more often than not
Browsers now automatically update. There is the issue with adobe updates, but automatic updates make this different. Yes they still suck on many applications, but doesn't that affect the article?
>* Passwords are still annoying
LastPass, keePass and other tools give uses a much more simplified way to access our accounts. Also being able to link Google/Facebook to an account does the same thing.
This article isn't 100% outdated, but it needs an update to address some of the changes that are there.
What about HTTP vs HTTPS and signing in over starbucks? Does your average user know about that.?
This is an issue of education and how to get the most bang for your buck, 2 factor authentication (easy), Password Management Software (easy), letting google/facebook/etc authenticate your account (easy).
There are ways to make peoples lives easier AND more secure, I don't know if these tools existed back then but I've been using LastPass for 2 years and back then it was clunky to use. Now I personally find it easy as heck. I'm more secure (then I was) and my life is easier. To that end this article needs an update.
I was talking about the referenced article Microsoft research paper when I said it was not relevant.
One of his examples in 7.3 User Effort is not Free he mentions the users time in input of a 6 digit pin vs an 8 digit password. But he doesn't include the use of a password management system. If you use a password managment system you can actually save time on password input.
Then look at his section on passwords. The same thing applies. And the article is not security advice but it contains security advice from 2009 which is different today.
>That all said the sentiment of the article still stands true. Users (like my family) hate worrying about security.
When I said "article" I was talking about the full document which gets directly into security best practice.
http://research.microsoft.com/en-us/um/people/cormac/papers/...
Also HN Comment guidlines indicate you shouldn't ask Did you read the article?
> Please don't insinuate that someone hasn't read an article. "Did you even read the article? It mentions that" can be shortened to "The article mentions that." https://news.ycombinator.com/newsguidelines.html