<?xml version="1.0" encoding="windows-1252"?>
<node id="785321" title="Re^3: Status of Recent User Information Leak" created="2009-08-02 21:29:42" updated="2009-08-02 21:29:42">
<type id="11">
note</type>
<author id="35324">
Trimbach</author>
<data>
<field name="doctext">
&lt;blockquote&gt;When developers and designers continue to ignore how people actually behave then said developers and designers are the ones at fault. Studies have shown over and over that people write complicated passwords down, reuse passwords, etc.&lt;/blockquote&gt;

&lt;p&gt;Yes, people do dumb things. And they use their birth date for their ATM pin. The natural (and even universal) tendency to do dumb things doesn't absolve users from taking responsibility for their actions.

&lt;blockquote&gt; What we really need is a decent and inexpensive two-factor auth solution.&lt;/blockquote&gt;

&lt;p&gt;Sure. And maybe (maybe) we'll get one of those someday, but until then the game is all about risk mitigation. The risk for me for a security breach at PM is zero. So therefore I don't care what PM does or does not do to secure my information. YMMV.&lt;/p&gt;

&lt;blockquote&gt;And if you want to play the "professional" card then you might want to avoid saying things like "[certain people] should be publicly humiliated with extreme prejudice".&lt;/blockquote&gt;

&lt;p&gt;No, if I wanted to play the "professional" card I'd use much harsher terms, like "fired." Any professional, who has been trained in IT security procedures, and who is fully aware of the risks and hazards of password security, who nevertheless uses the same same password on PM that they use on a &lt;i&gt;server&lt;/i&gt; or a &lt;i&gt;bank account&lt;/i&gt; deserves much more punishment than mere humiliation.&lt;/p&gt;
&lt;!-- Node text goes above. Div tags should contain sig only --&gt;
&lt;div class="pmsig"&gt;&lt;div class="pmsig-35324"&gt;
&lt;p&gt;&lt;a href="mailto:gblackburn@mac.com"&gt;Gary Blackburn&lt;/a&gt;&lt;br&gt;
Trained Killer
&lt;/div&gt;&lt;/div&gt;</field>
<field name="root_node">
784737</field>
<field name="parent_node">
785310</field>
</data>
</node>
