I don't remember like 98% or 99% of my passwords. I have something like 270 on my private accounts and probably 300 passwords on my work accounts. Well password manager is useful and I can always use pw reset option built in systems.
I kindly propose everyone to forget all their passwords.
Then they mostly don't need second factor if they generate random password each time and don't care about remembering them at all.
How is that? Everybody living in my house can get my Yubikey yet doesn't know my password. If I get robbed, my bank account is still (relatively) safe.
Most people won't purchase and use a Yubikey either though. Really just depends on your threat model, if remote attacks or local attacks are of higher risk. An obvious improvement would be the use of both a password and physical security token.
nly|5 years ago
ozim|5 years ago
I kindly propose everyone to forget all their passwords.
Then they mostly don't need second factor if they generate random password each time and don't care about remembering them at all.
dheera|5 years ago
jasonpeacock|5 years ago
You have to remember where we are starting from - most people are still using the same password across all their accounts.
1_player|5 years ago
naturalpb|5 years ago
dwaite|5 years ago
They have a key coming (some day) which will also support a biometric factor.