<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Password Meters Inconsistent &amp;amp; Misleading! in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/Password-Meters-Inconsistent-amp-Misleading/m-p/32127#M2173</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/136236425"&gt;@ericgeater&lt;/a&gt; No, in answer to your question.&amp;nbsp;&amp;nbsp; I did notice the latest Firefox has a password sync capability for convenience and some password managers also have the same capability to link between sites.&amp;nbsp;&amp;nbsp; Great convenience for the public, and the speed of reaction we all want in terms of interaction.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But this sacrifices both privacy and security for the sake of convenience.&amp;nbsp; However, these features are the very things that every user wants.&amp;nbsp;&amp;nbsp; And are probably very willing to sacrifice with exceptions in the case of Firefox and a Master password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;</description>
    <pubDate>Wed, 29 Jan 2020 18:10:19 GMT</pubDate>
    <dc:creator>Caute_cautim</dc:creator>
    <dc:date>2020-01-29T18:10:19Z</dc:date>
    <item>
      <title>Password Meters Inconsistent &amp; Misleading!</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Password-Meters-Inconsistent-amp-Misleading/m-p/32080#M2164</link>
      <description>&lt;P&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="A December 2019 study by University of Plymouth Professor Steve Furnell assessed the effectiveness of 16 password meters that people are likely to encounter online. While most meters effectively steer users towards more secure passwords, some will over-rate even the most commonly used ones that are found on top 10 &amp;quot;worst-passwords&amp;quot; lists.  One positive finding was that a browser-generated password was consistently rated strong. There was no mention of password managers and the strength of the passwords they generate. The paper is behind a pay-wall. An overview is given here: https://www.sciencedaily.com/releases/2019/12/191219090745.htm" style="width: 400px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/3779i6B0D77680179AAF1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="password_meter.jpg" alt="A December 2019 study by University of Plymouth Professor Steve Furnell assessed the effectiveness of 16 password meters that people are likely to encounter online. While most meters effectively steer users towards more secure passwords, some will over-rate even the most commonly used ones that are found on top 10 &amp;quot;worst-passwords&amp;quot; lists.  One positive finding was that a browser-generated password was consistently rated strong. There was no mention of password managers and the strength of the passwords they generate. The paper is behind a pay-wall. An overview is given here: https://www.sciencedaily.com/releases/2019/12/191219090745.htm" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;A December 2019 study by University of Plymouth Professor Steve Furnell assessed the effectiveness of 16 password meters that people are likely to encounter online. While most meters effectively steer users towards more secure passwords, some will over-rate even the most commonly used ones that are found on top 10 "worst-passwords" lists.  One positive finding was that a browser-generated password was consistently rated strong. There was no mention of password managers and the strength of the passwords they generate. The paper is behind a pay-wall. An overview is given here: https://www.sciencedaily.com/releases/2019/12/191219090745.htm&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:25:07 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Password-Meters-Inconsistent-amp-Misleading/m-p/32080#M2164</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2023-10-09T09:25:07Z</dc:date>
    </item>
    <item>
      <title>Re: Password Meters Inconsistent &amp; Misleading!</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Password-Meters-Inconsistent-amp-Misleading/m-p/32097#M2170</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/887781263"&gt;@AppDefects&lt;/a&gt; Another set of reasons for eliminating passwords and going FIDO instead.&amp;nbsp; Given that the shift to SD-WANs and Zero Trust Security is absolutely riddled with digital certificates.&amp;nbsp;&amp;nbsp;&amp;nbsp; Perhaps greater security awareness on the use of passwords, holding them in browsers is required throughout the whole of 2020?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2020 18:43:25 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Password-Meters-Inconsistent-amp-Misleading/m-p/32097#M2170</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2020-01-28T18:43:25Z</dc:date>
    </item>
    <item>
      <title>Re: Password Meters Inconsistent &amp; Misleading!</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Password-Meters-Inconsistent-amp-Misleading/m-p/32116#M2172</link>
      <description>&lt;P&gt;Is that a recommendation for browsers to retain / keep passwords?&amp;nbsp; I've always been skeptical of that.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 14:30:38 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Password-Meters-Inconsistent-amp-Misleading/m-p/32116#M2172</guid>
      <dc:creator>ericgeater</dc:creator>
      <dc:date>2020-01-29T14:30:38Z</dc:date>
    </item>
    <item>
      <title>Re: Password Meters Inconsistent &amp; Misleading!</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Password-Meters-Inconsistent-amp-Misleading/m-p/32127#M2173</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/136236425"&gt;@ericgeater&lt;/a&gt; No, in answer to your question.&amp;nbsp;&amp;nbsp; I did notice the latest Firefox has a password sync capability for convenience and some password managers also have the same capability to link between sites.&amp;nbsp;&amp;nbsp; Great convenience for the public, and the speed of reaction we all want in terms of interaction.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But this sacrifices both privacy and security for the sake of convenience.&amp;nbsp; However, these features are the very things that every user wants.&amp;nbsp;&amp;nbsp; And are probably very willing to sacrifice with exceptions in the case of Firefox and a Master password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 18:10:19 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Password-Meters-Inconsistent-amp-Misleading/m-p/32127#M2173</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2020-01-29T18:10:19Z</dc:date>
    </item>
  </channel>
</rss>

