Comment on More than $35 million has been stolen from over 150 victims since December — ‘nearly every victim’ was a LastPass user

<- View Parent
thbb@lemmy.world ⁨1⁩ ⁨year⁩ ago

At one of my clients, a large institution, they go further: you’re not allowed to use the local browser’s password manager. And still have to abide by the usual password rules: rotate every 3 months, complex passwords, etc.

As a result, users store a plain text file on their desktop (some go as far as printing it), that conveniently allows them to retrieve their passwords.

Too much security kills security.

source
Sort:hotnewtop