Hacker News new | ask | show | jobs
by dredmorbius 4415 days ago
Better to simply utilize one of the many, many, many, many, many lists of most frequently used passwords.

There are lists extending to the tens of thousands if not millions, but simply forbidding the 10 or 100 most frequent combinations would be a huge win. Using full lists as available would be great -- and is actually what password security should be based around. A known password is a bad password.

Don't get me started on PINs.