Linked by Howard Fosdick on Sat 10th Nov 2012 07:28 UTC
Thread beginning with comment 541822
To read all comments associated with this story, please click here.
To read all comments associated with this story, please click here.
Features
Linked by Thom Holwerda on 06/13/13 14:35 UTC
Linked by Thom Holwerda on 06/11/13 17:07 UTC
Linked by Thom Holwerda on 06/10/13 23:13 UTC
Linked by Thom Holwerda on 06/08/13 14:57 UTC
Linked by Thom Holwerda on 06/07/13 11:40 UTC
Linked by Thom Holwerda on 06/04/13 12:45 UTC
Linked by nfeske on 05/31/13 10:12 UTC
Linked by Thom Holwerda on 05/29/13 16:59 UTC
Linked by Thom Holwerda on 05/24/13 17:26 UTC
Linked by Thom Holwerda on 05/21/13 21:38 UTC
More Features »
Sponsored Links



Member since:
2007-09-22
First tip: it is already mentioned in the article, but needs repeating: don't reuse passwords.
Second tip: use a password that can't be guessed. Which is getting harder every day: Ars Technica: Why passwords have never been weaker - and crackers have never been stronger:
http://arstechnica.com/security/2012/08/passwords-under-assault/
Third tip: use a password-generator and -manager to handle your passwords.
Fourth tip: there are "single sign in" / "federated login" solutions:
- https://browserid.org/ (Mozilla project for "verified email address", only do email verification ones)
- http://openid.net/ and http://oauth.net/ Some examples: Google-, Yahoo-, Hotmail-account, Twitter- and yes even Facebook connect is based on oAuth. At least Google and probably others also have 2 factor authentication.
- http://en.wikipedia.org/wiki/SAML_2.0 (the solution certain enterprises use)
HTTP/2.0 might get builtin support for "federated login" as well.
There is a tradeoff in using one account of course, but many normal users just don't want to deal with password managers and prefer to use one password.
Edited 2012-11-10 13:43 UTC