you are viewing a single comment's thread
view the rest of the comments
[–] 11 points 2 years ago (2 children)

I really wish their password manager used a serif font, though. That's pretty unacceptable if you're generating secure passwords.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 4 points 2 years ago (1 child)

    Could you explain why them not using a serif font is bad?

  • source
  • parent
  • hideshow 2 child comments
  • [–] 12 points 2 years ago (1 child)

    Generally speaking, serif fonts make it easier to distinguish between visually similar characters like o, O, and 0 or 1, I, and l.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 3 points 2 years ago (1 child)

    Yeah that’s true, but I can’t see why distinguishing is required of a human. I use my password manager to generate and input passwords for me. I don’t even know any of them.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 4 points 2 years ago (1 child)

    It's not uncommon for the password manager to not be on the same system as where the password is being entered - hence a human needs to type. For example: consumer electronics with their own dinky little screens. Smart TVs/game systems and servers where remote access is not possible (or copy/paste does not work by design).

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 2 years ago

    Oh yeah that makes perfect sense; I just hadn’t thought of it because those scenarios haven’t applied to me for a bit. One solution would be to generate readable passwords like discernible sentences. Longer in most cases so more entropy, and less chance to confuse characters.

    Some password managers provide this as an option, though some authN systems require special characters because they think it improves security.

  • source
  • parent