top | item 11769676

(no title)

dspeyer | 9 years ago

Because passwords are terrible.

Lots of users pick guessable ones unless you have extensive password rules to stop them, and those rules are a huge pain to your users.

Lots of users have terrible password hygiene, leaving them all sorts of places they shouldn't.

Enough users are going to forget their passwords that you need a recovery mechanism. Which means an attacker needs to break either the password or the recovery. The most common recovery method is email, but Google often is the email provider.

discuss

order

nxzero|9 years ago

My understanding is that this was deployed internally first, so the calm that "people" don't get passwords seems like a stretch.

(Meaning I assume that the average person working at Google is smart enough to know how to use passwords.)

jsolson|9 years ago

Knowing how and putting it into practice are two different things.

I know I should eat better and exercise more, and yet here I am eating a scone and not having been on my bike in nearly a month.