> Check submitted passwords against a dictionary of common passwords (123456, monkey, etc) and ban that traffic extra hard.
> Give guidance to users about creating strong passwords
Yeah, if I just want to talk about a propane with some folks I would eagerly wait to be lectured about IT security, scolded at my passwords of choice, go out of my way to appease site administrator's password policy...
Or with any modern password manager - including the one built into Apple devices - you could just click on “choose strong password” and have one generated for you and stored.
That works fine till you have the access to your password manager.
If you ever find yourself without it... imagine your Apple device got broken/stolen. You would be fine wihtout an ability to talk on some forum, but what about critical banking, e-gov sites?
You lost your cards with the phones/wallet. Or perhaps you didn't even had one, because Apple Pay. Well, at least you have one at home, so now you just must make it back... without money. Oh, somehow you have given enough cash to buy a new iDevice, great. Do you still remember the password, after years of FaceID?
You just never been in the situation where you lost your "IT life", along with "bank life" and "any government accepted ID life". Try it for a day or two, report back.
I have lost my ID once. There are ways to get your government ID when it’s lost. They have your picture and your information. There are procedures to verify it.
I also had to go to the bank first to get money without my ID to get my ID. There are ways to verify that too.
I'm glad what that worked for you, but here you would be told to get back with a proper ID. Nobody at the bank would risk their job even for $150.
> There are ways to get your government ID when it’s lost
Yes, sure, just like hundreds of years before? The question here is what without an ID you can't get the same phone number => you can't request password recovery for bazillions of services which treats SMS as 2FA for the password recovery. Banking apps are one of those.
I would repeat again, but try to 'lose' your wallet and the phone, preferably in some place 500+km from your home. Your opinion on some account/password policies would change.
> The question here is what without an ID you can't get the same phone number.
I’ve never shown my ID to get a phone for T-mobile or walked into the store. I even switched my service with the same number from AT&T to Verizon back in 2011 without going into the store. I entered some verification information and Verizon sent me an iPhone 4S. I logged into my iPhone 4S with my Apple ID and everything downloaded from iCloud - data, apps, and the screen layout. My Verizon phone became active and my AT&T phone deactivated with the same number.
> you can't request password recovery for bazillions of services which treats SMS as 2FA for the password recovery. Banking apps are one of those.
I can log into any Apple device with my Apple ID and receive SMS messages - not just iMessages. Currently, if I get an SMS message, it goes to my phone, my cellular Apple Watch, my iPad and my Mac.
My wife and I would have to lose six cellular equipped devices between us and both of our wallets not to have any access to anything.
> I would repeat again, but try to 'lose' your wallet and the phone, preferably in some place 500+km from your home. Your opinion on some account/password policies would change.
Well, seeing that my “home” right now is whatever city I happen to be in with my wife this week (doing the whole digital nomad thing across the US), I’ve thought a lot about that.
If I lost my phone. Hopefully I wasn’t mugged and I still have my Watch where I can make calls (at least in the US) from the same number and receive texts. My iPad also has a cellular connection that receives SMS messages from the same number. While it doesn’t have a dialer for regular calls, you can call a number from your contacts.
Stealing your account talking about propane sounds like a great way for me to inject spam/propaganda right in the middle of a group of trusted individuals. And this is exactly what we see countless times. Accounts with bad passwords get compromised, spam, then banned.
You're using a shared resource, you need to use it responsibly.
Except it is always a magnitude easier to register a new account than to hunt down for an existing one. Conversion is way too low.
> Accounts with bad passwords get compromised, spam, then banned
Just like any other account with a proper good password (10 char, 3/4? Certain e-gov site recently forced me for a 12-char, 4/4 without any 3 chars of the sitename in a row) on a proper good one-time/one-use email address... which was compromised by a malware running on the user's machine. Forcing a stupid password policies only increases the friction for a new (and sometimes existing) users, while not providing a meaningful increase in 'non-compromising'.
> Give guidance to users about creating strong passwords
Yeah, if I just want to talk about a propane with some folks I would eagerly wait to be lectured about IT security, scolded at my passwords of choice, go out of my way to appease site administrator's password policy...