I'm thinking of creating an @owasp Top Ten Dumb Things Security Makes Users Do.
Here are a few:
1. Making users rotate passwords without evidence of compromise.
@TechFTC actually does an awesome job of explaining why it's dumb.
ftc.gov/news-events/blogs/teβ¦
4
3
3


