Expert Flouts Conventional Wisdom Regarding Passwords

MOUNTAIN VIEW, Calif. — Internet security expert David Schneier, author and founder of California web security firm Counterpane, has suggested that writing down Internet passwords might not be the huge taboo it once was, considering the number of passwords the average surfer needs to juggle.

Schneier, author of “Applied Cryptography” and “Beyond Fear,” a book about personal safety in the digital age, echoed the recent suggestion by Microsoft security chief Jesper Johansson that keeping a written record of passwords allows users to maintain the complexity required to keep hackers from guessing oft-used or too-simple login information.

"People can no longer remember passwords good enough to reliably defend against dictionary attacks,” Schneier wrote in his newsletter, Cryptogram. “[Users] are much more secure if they choose a password too complicated to remember and then write it down."

Schneier recommends keeping passwords in places previously frowned upon, like one’s wallet, but obfuscating certain key elements, like transposing letters or switching descriptions to foil would-be thieves.

These recommendations come on the heels of Schneier’s rejection of “two-factor” authentication, a security feature that has been around since the 1980s but that is gaining ground due to its use by America Online and some banks.

Two-factor authentication is being marketed as a failure-proof security system, Schneier said, but only in the case of certain types of hacks.

Like writing down passwords, Schneier said, keeping authentication simple and smart might be better than making complex systems that fail big when they are finally compromised.

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

France Reinstates Age Verification Rule for EU Sites

France’s highest court, the Council of State, on Tuesday reinstated age verification rules for EU-based sites under the country’s Security and Regulation of the Digital Space (SREN) law, ruling in favor of the French government and against Hammy Media.

Whisper Fans Joins Pineapple Support as Supporter-Level Sponsor

Whisper Fans has joined the ranks of over 70 adult businesses and organizations committing funds and resources to Pineapple Support.

Utherverse Launches 'Red Light Center' Virtual World

Virtual reality and metaverse technology company Utherverse has launched its new virtual world, RedLightCenter.io.

European Commission Approves AV Guidelines, Unveils Prototype App

The European Commission on Monday released its final, approved guidelines for protecting minors online under the EU’s Digital Services Act (DSA) and made public a “white label” age verification app intended to help sites and platforms comply with age verification rules under the DSA.

New Membership Site 'Sluts Corner' Launches

R18 Entertainment has launched a new membership site, SlutsCorner.com.

Roxie Rae Relaunches Site Through XSiteAbility

Roxie Rae has relaunched her site through XSiteAbility.

Federal Appeals Court Vacates FTC 'Click to Cancel' Rule Pending Review

The U.S. Court of Appeals for the 8th Circuit on Tuesday vacated the Federal Trade Commission’s “click-to-cancel” rule aimed at making it easier for consumers to cancel online subscriptions, pending further review.

FSC Drops Florida AV Lawsuit in Wake of SCOTUS Decision

A U.S. district court judge granted on Tuesday a motion by Free Speech Coalition to dismiss the trade association’s lawsuit over Florida’s age verification law, a case that had been on hold pending the Supreme Court’s recent ruling on the constitutionality of state AV laws.

Show More