Medicos could be world's best security bypassers, study finds

The fact that some security is based on "Best Practice" or "Industry Standard" is what winds me up. It's not based on "What we can observe and measure in the real world" but rather on "sufficient documentation exists to support this practice that no one will hold the security people accountable for problems if we implement these policies".

You must have a complex password, change it every 60 days, not reuse it - these are my favourites. Teach the user base how to generate pattern passwords that meet the rules and problem solved (from the users' perspectives)

