Password trolling
It's been a while since Cory Doctorow speculated that the utterly parasitic patent-trolling industry would soon evolve into an even more parasitic EULA-trolling industry. The argument goes that since we all click on absurdly one-sided t&cs every day, one day a company will emerge that makes a business out of trying to enforce them. I worry, therefore, that password trolling isn't already a business model. Buy up a defunct dotcom (perhaps found via the hallowed archives of Fuckedcompany or the Techcrunch dead pool); match passwords to email addresses; go ID-thieving. All you have to believe is that (some) people use the same email/password combination to try out the latest web2.0 toy as they do for their bank and you're away.








This is why DBAs are paid less than any other job in IT, but there are always 25 applicants per vacancy. :-)
Posted by: zzz | August 07, 2007 at 04:10 AM
I have thought about exactly this - but it's worse than you think. You don't need to use the same password for your bank as for your new Web 2.0 toy... you just need to use the same password for the Webtoy and your email - then ask for a password reminder by email.
Roll on OpenID
Posted by: Ross Parker | August 07, 2007 at 05:28 PM