The answer is yes, and the TL;DR is not to use them, use 2FA, and not share personal details online (which is hopefully all obvious advice)

cross-posted from: https://lemmy.world/post/12060980

  • summerof69@lemm.ee
    link
    fedilink
    English
    arrow-up
    12
    ·
    5 months ago

    no they are not, just another stupid article from proton. nothing stops you from saying that bwE0FpHb5iPzMZiismyeiTIWhoB*#V8SaD0F3R*SeH was your first pets name.

    And how many regular people do that? Or does security apply only to advanced users?

    • flatbield@beehaw.org
      link
      fedilink
      English
      arrow-up
      5
      ·
      edit-2
      5 months ago

      Security is always porous. The article really had no suggestions. They say 2FA but account recovery is often a combination of access to your email account or questions. None of this stuff is particularly secure.

      So yes security is an advanced feature usually not provided and normal users do not even try at being secure nor do most systems insist on it.

      Edit: Some sites are doing away with passwords and just sending and email with a link to login. Totally not secure but account recovery has long used the same method so it may not be actually reducing security much since there never was much security.

    • jlow (he/him)@beehaw.org
      link
      fedilink
      English
      arrow-up
      2
      ·
      5 months ago

      I’m probably not a regular user but my first pet’s name, the city I was born in, my first school and my childhood nicknames are also very long strings of characters 👌