|
You are here |
jasonwryan.com | ||
| | | | |
kevincox.ca
|
|
| | | | | ||
| | | | |
ariya.io
|
|
| | | | | We are notoriously bad at password hygiene. Yet, it is crucial for our digital lives. How many of us managed to convince our friends and family members to use a strong and unique password for every service which they use? How about the grumpy response when you suggest them to always use a password manager for everything? | |
| | | | |
www.mikekasberg.com
|
|
| | | | | Jeff Atwood wrote a post on Coding Horror today calling out bullshit password rules. And he's dead on. Password rules, as most sites implement them... | |
| | | | |
myers.io
|
|
| | | Every so often I see posts on Stack Exchange, or Hacker News where someone has figured out that their passwords are being sent to the server and the server can see them! The logic that we see is that if the password is hashed client side, then only the hash needs to be sent to the server, so the server never knows the password. Unfortunately, I sometimes even see this go one step further when people suggest that with this arrangement, HTTPS isnt required. Wrong. | ||