← Back to context

Comment by n0rdy

8 hours ago

Sorry, I might be too young to remember those times. Can you tell me more, please? I'm genuinely curious.

Because from the sound of that, it feels that it would patch the `123456` problem, but opens up a new vulnerability - the password is known / being sent through / printed, so it can be leaked from that source.

It was just that. And email with the new password. Hard to remember at first but then, somehow, I could type it from memory. Not sure how they got rid of the emails after they sent them but there are ways. It can be leaked from the source, true, but people with better technical skills were handling that source. So I guess overall it was better. The big insight might be that you can't evaluate the security of a system only from the technical aspect. You have to take into consideration also the human aspect. And that's a very weak point. Even Communism failed because they didn't take into consideration the human aspect (people don't want to work more if they get what everybody else gets anyway).