Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Hell yeah it is less secure. password, letmein, 123456, j@nuary1

All bad passwords. All will be chosen by your users at some point. The last satisfies any complexity requirements I have ever run against in the wild.

There is nothing insecure about sending a plain-text password that compares to a badly chosen password -- email isn't that easy to intercept and properly nobody is hacking your users physical (or wireless) network. At least not compared to the number of people who will be attempting to crack their online password.



"email isn't that easy to intercept and properly nobody is hacking your users physical (or wireless) network".

If you actually believe this, then we will never be in agreement.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: