You essentially have to make the choices: UsePassword (YES | NO) connect on LinkedIn, By There are other strategies, making the client perform some mildly expensive action (factor a 64-bit co-prime?)

And then, after the attack was discovered and Twitter temporarily shut down all verified accounts, the public lost a vital source of information.

Or at the very least do it for admin/moderator level users.”. For a marginal cost of damn close to zero they could have required two-factor. (If I were a national-intelligence agency, I might even use a bitcoin scam to mask my real intelligence-gathering purpose.)

@Simon Willison You have to prevent/ignore submission of a new password-attempt for a certain time and not delay your processing of a single request.

Only way back in is to call the help desk.

There is no regulation.

Why even lock the account for an hour? I've been writing about security issues on my blog since 2004, and in my monthly newsletter since 1998. Somehow your web app has to recognize multiple login attempts (which itself isn’t easy in a 1000’s of servers farm) and then pass the connection off to a low-level waiter. January 13, 2009 6:20 AM. If they don’t or can’t enforce complexity requirements, they should do this, save for the fact that management often balks at it. They get to decide what level of security you have on your accounts, and you have no say in the matter.

A 10 character password with 5 bits of entropy per character is not feasibly guessable even at a high rate. Bruce Schneier is an internationally renowned security technologist, called a "security guru" by The Economist.

NO!!! account simply because someone is The users might not be IT savvy, but the IT group really should know better, 20+ years after the dangers of enforced password timeouts were documented. He is, to his surprise, presented with twitter support tools. Feel free to delete my comment after you’ve read it…. Many people rely on Twitter’s authentication systems to know that someone who purports to be a certain celebrity, politician, or journalist is really that person. Couple that with a shell script, and you could add those entries to Netfilter to block not only SSH, but everything on your server. You gotta have limits. January 15, 2009 3:03 PM.

January 12, 2009 11:39 AM, @MikeA: “I’m guessing that the “month name as password” stupidity only occurs at companies that are still doing the “make users change passwords frequently” stupidity.”. You’ve reduced the brute-force time by 90%, but 25 years is still too long to wait to get someone’s Twitter account.

of accounts!

January 12, 2009 11:12 AM. Balance(Usabilty, Complexity of password, change frequency, and lockout behavior) Simon Willison • Paeniteo •

Twitter will send you a link to a pass update page, that automatically logs into your acct after the pw is changed. Bruce Schneier on Seems to me that Twitter, in particular, is prepared for two-factor authentication.