LOL
28 karma · joined September 3, 2018
A dictionary approach is something I'd normally associate with offline attacks since online requires you go through the active system which should hopefully have some sort of rate-limits to prevent that. Offline attacks can be more brute-force and don't necessarily require pre-existing knowledge.
1) People suck at making their own passwords and this encourages bad passwords and password reuse. 2) The article admits that paper alone isn't good enough, but suggests that having "four password storage methods" is the optimal solution. That seems... unwieldy. Storing the most important (banking info, email) passwords in your head is a recipe for password reuse or getting locked out of your account.