Oddbean new post about | logout
 Security "experts" don't want to hear this: But forcing people to log in more often does, in fact, increase the likelihood that:

- Someone will shouldersurf your password
- People will find shortcuts to make logging in more convenient
- People will chose passwords that are least annoying to them irrespective to how secure it is
- Phishing attacks are more successful