<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www2.sqlblog.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Opinion: Passwords as a concept are completely broken</title><link>http://www2.sqlblog.com/blogs/greg_low/archive/2012/08/22/opinion-passwords-as-a-concept-are-completely-broken.aspx</link><description>One thing you get to do as you get older, or have been around the industry for a long time, is to pontificate. My pet topic today is passwords. I think that they are, as a concept, now completely broken and have been for a long time. We tell users: 1.</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP2 (Build: 61129.1)</generator><item><title>re: Opinion: Passwords as a concept are completely broken</title><link>http://www2.sqlblog.com/blogs/greg_low/archive/2012/08/22/opinion-passwords-as-a-concept-are-completely-broken.aspx#44819</link><pubDate>Wed, 22 Aug 2012 08:14:54 GMT</pubDate><guid isPermaLink="false">21093a07-8b3d-42db-8cbf-3350fcbf5496:44819</guid><dc:creator>jamiet</dc:creator><description>&lt;p&gt;Greg,&lt;/p&gt;
&lt;p&gt;Agreed. As a halfway house I use Lastpass; its not ideal (not least because it has a glaring single point of failure) but, for me, its the best option right now.&lt;/p&gt;
&lt;p&gt;JT&lt;/p&gt;</description></item><item><title>re: Opinion: Passwords as a concept are completely broken</title><link>http://www2.sqlblog.com/blogs/greg_low/archive/2012/08/22/opinion-passwords-as-a-concept-are-completely-broken.aspx#44820</link><pubDate>Wed, 22 Aug 2012 08:32:46 GMT</pubDate><guid isPermaLink="false">21093a07-8b3d-42db-8cbf-3350fcbf5496:44820</guid><dc:creator>Chris Donges</dc:creator><description>&lt;p&gt;OpenID was an attempt to fix the problem.&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://en.wikipedia.org/wiki/OpenID"&gt;http://en.wikipedia.org/wiki/OpenID&lt;/a&gt;&lt;/p&gt;</description></item><item><title>re: Opinion: Passwords as a concept are completely broken</title><link>http://www2.sqlblog.com/blogs/greg_low/archive/2012/08/22/opinion-passwords-as-a-concept-are-completely-broken.aspx#44821</link><pubDate>Wed, 22 Aug 2012 09:51:14 GMT</pubDate><guid isPermaLink="false">21093a07-8b3d-42db-8cbf-3350fcbf5496:44821</guid><dc:creator>RichB</dc:creator><description>&lt;p&gt;Aye, and it's only getting worse, with many sites now demanding about 3 different passwords, letters from ordinal positions within them, and magnifying the problem with dates of birth and mothers maiden names (which of course I am just going to plug into some poxy webforum).&lt;/p&gt;
&lt;p&gt;Key fobs to generate randomish numbers, one of which you need a pin to input first... HSBC needs: 1xmembership number (about 11 digits), 1xmemorable code (over 8 iirc) AND 1xPin to generate an rsa type # to tap in. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;Almost always there to protect what... a forum login??&lt;/p&gt;</description></item><item><title>re: Opinion: Passwords as a concept are completely broken</title><link>http://www2.sqlblog.com/blogs/greg_low/archive/2012/08/22/opinion-passwords-as-a-concept-are-completely-broken.aspx#44823</link><pubDate>Wed, 22 Aug 2012 11:17:57 GMT</pubDate><guid isPermaLink="false">21093a07-8b3d-42db-8cbf-3350fcbf5496:44823</guid><dc:creator>Ben Thul</dc:creator><description>&lt;p&gt;I couldn't tell you what most of my passwords are. I, like Jamie, use something to remember and generate them for me. I like the combination of KeePass and Dropbox.&lt;/p&gt;</description></item><item><title>re: Opinion: Passwords as a concept are completely broken</title><link>http://www2.sqlblog.com/blogs/greg_low/archive/2012/08/22/opinion-passwords-as-a-concept-are-completely-broken.aspx#44825</link><pubDate>Wed, 22 Aug 2012 12:56:03 GMT</pubDate><guid isPermaLink="false">21093a07-8b3d-42db-8cbf-3350fcbf5496:44825</guid><dc:creator>Stephen Mandeville</dc:creator><description>&lt;p&gt;I use Keepass 2 professionally and personaly&lt;/p&gt;
&lt;p&gt;Free and it works great&lt;/p&gt;
&lt;p&gt;Whole DBA team uses a shared version.&lt;/p&gt;</description></item><item><title>re: Opinion: Passwords as a concept are completely broken</title><link>http://www2.sqlblog.com/blogs/greg_low/archive/2012/08/22/opinion-passwords-as-a-concept-are-completely-broken.aspx#44826</link><pubDate>Wed, 22 Aug 2012 13:10:25 GMT</pubDate><guid isPermaLink="false">21093a07-8b3d-42db-8cbf-3350fcbf5496:44826</guid><dc:creator>snewfie</dc:creator><description>&lt;p&gt;And I forgot to mention That I also use Dropbox to have acces to my passwords from anywhere.&lt;/p&gt;</description></item><item><title>re: Opinion: Passwords as a concept are completely broken</title><link>http://www2.sqlblog.com/blogs/greg_low/archive/2012/08/22/opinion-passwords-as-a-concept-are-completely-broken.aspx#44855</link><pubDate>Fri, 24 Aug 2012 13:53:35 GMT</pubDate><guid isPermaLink="false">21093a07-8b3d-42db-8cbf-3350fcbf5496:44855</guid><dc:creator>@Hennie7863</dc:creator><description>&lt;p&gt;Yep really true and we need another solution for this. I'm getting crazy with all of the different passwords for sites. &lt;/p&gt;
&lt;p&gt;Yet another problem are the devices. Some sites reset the passwords (in case you forgot) and the result of this is, that i have to re-enter the password on every device.&lt;/p&gt;</description></item><item><title>re: Opinion: Passwords as a concept are completely broken</title><link>http://www2.sqlblog.com/blogs/greg_low/archive/2012/08/22/opinion-passwords-as-a-concept-are-completely-broken.aspx#44987</link><pubDate>Tue, 04 Sep 2012 01:01:40 GMT</pubDate><guid isPermaLink="false">21093a07-8b3d-42db-8cbf-3350fcbf5496:44987</guid><dc:creator>Andrew Oliver</dc:creator><description>&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://xkcd.com/936/"&gt;http://xkcd.com/936/&lt;/a&gt;&lt;/p&gt;</description></item></channel></rss>