Let me ask you a question, I regularly use two on-line financial services – with very two different authentication systems:
The first service uses a simple user name/password authentication, my login name is my e-mail address and the password never has to be changed.
The second service uses a more complex authentication scheme, my user name is a random collection of letters and numbers, I have to change my password every month and I have a third identification code have to type to login.
Which of those two services is more secure?
I believe most people...