Legacy systems. Cost. Lack of knowledge. Laziness. Lack of business case or risk analysis to support the change. Standards. Even laws.
-
-
Replying to @thorsheim @TychoTithonus and
I've worked at one of the Big Internet Companies and no offense, but all of those are utter BS. If it made UX sense it would've been done.
1 reply 0 retweets 0 likes -
Replying to @marcan42 @thorsheim and
All that stuff applies to enterprise systems, banks, etc. Your average modern Web company has no problem w/min=12 *if* it doesn't lose users
2 replies 0 retweets 0 likes -
Replying to @marcan42 @thorsheim and
So why aren't Twitter, Google, Facebook, and every mildly popular web startup using min=12 when it's a trivial config change for them?
1 reply 0 retweets 0 likes -
Replying to @marcan42 @TychoTithonus and
Because they prefer good UX, does risk analysis and threat models, and have TONS of compensating controls instead. Good security UX.
2 replies 0 retweets 0 likes -
Replying to @thorsheim @TychoTithonus and
So you're saying min=12 isn't good UX? :-) They wouldn't deploy the 300M blacklist either. They can afford to develop great controls.
1 reply 0 retweets 0 likes -
Replying to @marcan42 @TychoTithonus and
I would do a risk analysis & threat models first.
1 reply 0 retweets 0 likes -
Replying to @thorsheim @TychoTithonus and
My point is they do that all the time and clearly haven't concluded min=12 is a good idea. We don't have any data for that vs. blacklist.
1 reply 0 retweets 0 likes -
-
Replying to @thorsheim @TychoTithonus and
So, in my case I'm confident that blacklist usage likely !problem and if it is I have enough monitoring to revert before business impact.
2 replies 0 retweets 0 likes
Hence, let's see how it turns out in practice. For good measure I'll also log bool(pwlen>=12) to estimate impact of that policy.
-
-
Replying to @marcan42 @thorsheim and
User count is ~450, not huge but should allow for some conclusions. Next year can test with n>5000 if it goes well.
0 replies 0 retweets 1 likeThanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.