Self-defeating security measures
Categories: TechnologyThings like this make me feel like I need to go get a degree in psychology to make any more headway with information security. It’s semi-well-known that idiotic password complexity/change requirements generally have the opposite of the intended effect. That is, people either write them down or choose predictable ones, and go to greater lengths to make them predictable. PayPal™ has taken this to the next level. (Screenshot after the jump since I can’t get my style sheet right for images here within the 5 minutes I’ve allocated for posting this…) (more…)