Technically or socially?
The second one is hard, the first one can be done easily - just require the passwords to be 14/16+ characters, multiple symbol domains and calculate tempo of input. Slower than 350ms between keystrokes - error message.
Those who can type that fast already are using pw manager or you can just skip this 0.001%.
Technically or socially? The second one is hard, the first one can be done easily - just require the passwords to be 14/16+ characters, multiple symbol domains and calculate tempo of input. Slower than 350ms between keystrokes - error message. Those who can type that fast already are using pw manager or you can just skip this 0.001%.
Doing that will certainly get people to use a password manager.
But it doesn't say which password manager.
The most popular password manager is some text/word/excel document on the desktop.
I have no evidence to back this hypothesis, but I wonder if that’s still more secure than using bad passwords.
Everyone's password is now 1q1q1q1q1q1q1q1q1q1q!Q