On 07/10/17 00:30, Philip Paeps wrote:
> I don't consider a long random password the user can't change
> particularly insecure. 

It's not too bad really, if the password is per application and saved.

Lots of corporates have single sign on.  Same password everywhere in
business.     

In theory, this should mean people people login once, and kerberos,
OAUTH, ... does it's trick and people are logged in.

In practice, people add their company IMAP account to their phone, and
click `save password`.  They login (on their desktop) to a corporate web
application that uses an LDAP backend rather than tokens to login. They
save their password.  So their `keys to everything` corporate password
gets saved and entered all over the place.  This is poor


Google have obviously done a good job of risk managing new logins.


Tim

_______________________________________________
mailop mailing list
[email protected]
https://chilli.nosignal.org/cgi-bin/mailman/listinfo/mailop

Reply via email to