This is worthy of a paper, Twitter not sufficient. I imagine blocking 306 million pwds would cause massive customer loss & complaints.
-
-
Maybe a soft-block of non-top10k would be okay then? You know the "somebody else is using your password" jokes might be useful eventually:-)
1 reply 0 retweets 0 likes -
Does Google, Twitter, Facebook or your bank use any blacklists? Why/not?
1 reply 0 retweets 0 likes -
They use lists for lowering pw score, not technically a block list, though. My bank uses SMS OTP with PIN, my other bank allowed login=pw.
1 reply 0 retweets 0 likes -
Replying to @spazef0rze @thorsheim and
Michal Špaček Retweeted Michal Špaček
Czech post uses a minimal block list, with veeeery interesting choices... :-)https://twitter.com/spazef0rze/status/676700855681224704 …
Michal Špaček added,
1 reply 0 retweets 1 like -
Replying to @spazef0rze @thorsheim and
Google et al. have 2FA, list of devices, locations. Like you said, other serverside features, which I like a lot, more than a block list.
1 reply 0 retweets 0 likes -
Replying to @spazef0rze @thorsheim and
It's very rare you would choose a secure AND leaked-from-someone-else pwd. Most blocklist hits will be either nonsecure or personal reuse.
1 reply 0 retweets 2 likes -
Replying to @marcelsulek @thorsheim and
The question is: is a block list the right way how to teach users about secure passwords/accounts? Maybe but you block 3 pws & they go away.
2 replies 0 retweets 0 likes -
Replying to @spazef0rze @marcelsulek and
Michal Špaček Retweeted Per Thorsheim
Would be cool to do a research, how many pws are blocked for 1 user (probably 1+) when they give up. Basically thishttps://twitter.com/thorsheim/status/893797466889441281 …
Michal Špaček added,
1 reply 0 retweets 0 likes -
Replying to @spazef0rze @marcelsulek and
And as I said, know your userbase. We're not Twitter; I guarantee lost business if we just enable the block list would be much lower.
1 reply 0 retweets 0 likes
I mean, we're talking about Spain's largest LAN party, and we're at capacity. Block list or no, next year we'll fill up.
-
-
Replying to @marcan42 @spazef0rze and
Nobody intent on going and grabbing a ticket before they're gone will give up due to poor password choices.
1 reply 0 retweets 0 likes -
Replying to @marcan42 @marcelsulek and
Yep, sorry, somewhere on the way we've probably switched from talking about just one site to general block list usage :-)
0 replies 0 retweets 0 likes
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.