Password restrictions limit Diceware word list – (when) can this get bad enough one should choose another strategy?

Besides “your password must contain this” complexity requirements, some places also have “your password must not contain this” rules, sometimes with fairly short substrings of the username, a day of the week,… being enough for a password t… Continue reading Password restrictions limit Diceware word list – (when) can this get bad enough one should choose another strategy?

Does the new Danish authentication solution for online contact with municipality etc. genuinely use 2FA?

In Denmark, the current digital identification/authentication solution for pretty much any online contact with the municipality, state, etc. is being switched over to a setup consisting of the following steps:

You enter your username on … Continue reading Does the new Danish authentication solution for online contact with municipality etc. genuinely use 2FA?

How to handle a router from an apparently security-indifferent ISP with no possibility to switch?

My ISP’s security strikes me as… somewhat alarming to my admittedly non-expert eyes. They store wifi passwords in plaintext on their website and allow changing it there – this is apparently meant to be the only way to change password/net… Continue reading How to handle a router from an apparently security-indifferent ISP with no possibility to switch?