Conclusion Requiring that passwords conform to rules of length, complexity, and unpredictability increases the likelihood of someone gaining unauthorized access to a user's account. βββββ ββββ ββββ ββββββββ βββ βββββββββββββ ββββββ βββββ β βββββββ ββββββ ββ βββββββββ ββββββββ ββββββββ ββ ββ βββββββ ββββββββββ ββ ββββ ββββββ ββ ββββββββ β βββββββββ ββββββββ βββββββ βββββββ βββββββββ βββ ββ ββββ ββ βββββββββ βββββ βββββ βββββ ββββ βββββ
The author concludes that making people use long, complex, unpredictable passwords actually increases the chances their accounts are hacked. Why? Because itβs hard to access an account by guessing a password anyway, and complex passwords are more difficult to remember, meaning people usually write them down.
The author assumes the risk of a written password being stolen is greater than the risk of a non-complex password being guessed. This means assuming people are more likely to write down a complex password, and that writing down a password increases the chances a personβs account is accessed without authorization.
The overall conclusion of the ββββββββ ββ ββββββββ βββββββββ ββ βββββ βββ ββ βββ βββββββββ ββ ββββββββ
People who use ββββββββ βββββββ ββ ββββ ββββββββ βββββ βββββββββ βββ ββββ ββ ββββββ ββββββββ βββββββββ ββββ βββ βββββ ββββββββ βββ ββββββββββββββ
User accounts that βββ βββββββββββββ ββββββ βββββ β βββββββ ββββββ ββ βββββββββ ββββββββ βββββββ βββ βββββββ ββββββββ βββββ β ββββββββββ βββββ
When a password ββ βββββββ βββββ ββ βββββββββ βββ βββββββ ββββ βββββββ ββββ ββ ββββ ββ βββ ββββ ββββββββ ββ ββββ ββββββββββββ ββββββ ββ βββ ββββββ ββββββββ
When users who ββββββ βββββ βββββββββ βββ ββββββ βββ ββ βββββ βββ βββββββββ ββββ ββββ βββββ ββ βββββββ β βββββββββββ βββββββ ββ βββββ ββ ββββ βββββ ββββββββ βββββββββ
Passwords that conform ββ βββββ ββ βββββββ βββββββββββ βββ ββββββββββββββββ βββ ββ ββββββ ββ βββββ ββββ βββββββββ ββββ ββ βββ βββββββ ββ ββββ ββββββ