Time to Forget Passwords?
July 7, 2005 by PingOne of the things Bill Cheswick mentioned during his talk was that the battle for unguessable passwords is lost. According to him, it is time to stop complaining that people pick passwords that are vulnerable to dictionary attacks. It will never get better. Instead, he suggests not letting users pick passwords.
What do you think? Is it really time to stop letting users pick passwords? If we assume that passwords can’t be made unguessable, does it follow that passwords are no use at all?
July 7th, 2005 at 07:14
I am a big fan of password stores such as pwsafe which will gernerate unique good passwords for all the places they are needed, and an easy interface to be able to recall them and use them.
July 7th, 2005 at 07:18
Good point.
The Mac OS X keychain is a really nice feature, and it makes passwords easier for me to use, though it doesn’t change the way i choose passwords.