Password Creation in the Presence of Blacklists, USEC '17, http://www.passwordresearch.com/papers/paper650.html … Didn't measure such a large blacklist though.
So why aren't Twitter, Google, Facebook, and every mildly popular web startup using min=12 when it's a trivial config change for them?
-
-
Because they prefer good UX, does risk analysis and threat models, and have TONS of compensating controls instead. Good security UX.
-
Btw: you can learn about how Facebook secures your pwd from this talk by Alec Muffett at my PasswordsCon in 2014:https://video.adm.ntnu.no/pres/54b660049af94 …
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.