GSA / GSA/modernization

Comment from email: Remove static passwords

Open
#9 0 comments 0 reactions 0 assignees View on GitHub
Public comment
Dominant language
CSS
Stars
59
Forks
8
PR merge metrics
No merged PRs in 30d

Description

Dear ATC,

As part of a forward looking vision for our national security, and the internet as a whole – I propose that you advocate for the removal of static passwords.

Why?
When I researched why the internet is so insecure I concluded that static passwords are the main reason.
Because they are static, they are stolen via breaches.
Because they rely on users to be security experts (like our own parents and kids.)

I found out I am not the only one thinking static passwords are the main reason.
https://www.cnbc.com/2016/10/06/passwords-are-the-weakest-link-in-cybersecurity-today-michael-chertoff-commentary.html


Does the security industry expect everyone to remember passwords with eight characters or more—upper, lower, number, special characters and also use a captcha?
Oh, and also to change them once in a while?
Oh, and have a different password for every website?
Oh, and...

I wrote this manifesto, to explain the pros and cons of keeping passwords. This article is not meant to be read, it is meant to be read and acted upon.
https://www.trusona.com/no-passwords-manifesto/

We can see how keeping passwords help fund evil. The bad guys use this to their advantage, and from the proceeds fund terrorism, human trafficking, weapons and child exploitation online.

“The only thing necesary for the triumph of evil is for good men and women to do nothing.”
— Edmund Burke


Best,

Ori Eisen

Ori Eisen
Trusona CEO

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.