On 07/10/17 00:30, Philip Paeps wrote: > I don't consider a long random password the user can't change > particularly insecure.
It's not too bad really, if the password is per application and saved. Lots of corporates have single sign on. Same password everywhere in business. In theory, this should mean people people login once, and kerberos, OAUTH, ... does it's trick and people are logged in. In practice, people add their company IMAP account to their phone, and click `save password`. They login (on their desktop) to a corporate web application that uses an LDAP backend rather than tokens to login. They save their password. So their `keys to everything` corporate password gets saved and entered all over the place. This is poor Google have obviously done a good job of risk managing new logins. Tim _______________________________________________ mailop mailing list [email protected] https://chilli.nosignal.org/cgi-bin/mailman/listinfo/mailop
