2 ms·
Are you saying that you remember a unique and sufficiently random password for every website/app/etc you use? If so, you've got a far better memory that me.
by wrboyce 10y ago
Are you saying that you remember a unique and sufficiently random password for every website/app/etc you use? If so, you've got a far better memory that me.
- anonred 10y agoNot the GP, but yes, and it doesn't require a good memory. The main things I do: 1. "Salt" my email usernames with the name of the service (johndoe+reddit@example.com) 2. Use multiple (long) password bases depending on the type of service (eg website vs app) 3. Combine the password bases with a cipher/salt based on the service name and my username I'm guilty of not rotating passwords on a regular basis, however.
- deleted 10y ago[deleted]
- viraptor 10y agoSo do you use encryption on that combined version? If yes, how do you deal with different requirements (one website says symbols required and more than 8 characters, another says symbols forbidden and less than 8 characters). If no, what stops someone who finds one password from changing the service name part and trying it somewhere else?
- anonred 10y agoNo encryption or hashing, since that would require (easy-access to) an external tool and lacks control over length and characters. It's not possible to simply change the "name part" of one of my passwords since the general format looks something like: {password_base}{service_cipher}{username_cipher}{special_chars}. Depending on the type of service, `password_base` changes. For example, HN uses a separate one from Gmail for Business. Likewise, `service_cipher` and `username_cipher` are simply that: truncated ciphers of the service name and username. Lastly, `special_chars` is used for pesky sites that want special characters outside the range provided by my password base. I'd like to think my system is very difficult for someone to crack without gaining access to a large number of passwords. The only limitation is that a few sites have limits on password length(!) which requires using a shorter base or even truncating the password entirely.
- thousande 10y agoWhat about this technique? https://support.mozilla.org/en-US/kb/create-secure-passwords-keep-your-identity-safe https://support.mozilla.org/en-US/kb/create-secure-passwords...