3 ms·
How does that work? With Keychain I literally have a different password on every single site I visit. If someone hacks Facebook they'll have... my Facebook pa
by alien_at_work 9y ago
How does that work? With Keychain I literally have a different password on every single site I visit. If someone hacks Facebook they'll have... my Facebook password (and whatever sites use OAuth and won't let me opt out of it). Does your brain consistently handle that level of password diversification, because that's the best defense against password theft.
- heavymark 9y agoAgreed. Though always does come down to the weakest link. Such as if a person had access to just your email account password then they could reset most any other password on other accounts you have in the middle of the night while you slept. Which is why 2 factor on your email is most important though, depending on what software/methods you use for 2 factor always a chance that could be bypassed. Also if someone gains physical access to your device(s) while you are in the bathroom or what not, if they know your laptop password which is usually something easy to remember, then they have access to all your keychain passwords no matter how complex each of them are. Still million times better than attempting to memorize custom passwords for each site, since most people will just have one password, and will add a few characters based on the site name/domain which can also easily be cracked.
- Waterluvian 9y agoFor many years now I've used an algorithm for password generation that I keep in my head. It's pretty simple, I have a memorized string (like a traditional password), and a memorized set of rules. For example, I might have a rule where I take my password, replace the first character with the first character of the product (a for Amazon), and replace the last letter with the type of product I'm using (s for shopping). I have a significantly more complex algorithm than that, but you get the idea. Every password I have is different, but they're all trivial to remember. This isn't super hardcore security, but it helps me have like 40 passwords that are all different.
- ZoFreX 9y agoAnd how many of your passwords need to leak for that scheme to be completely transparent?
- snowwolf 9y agoSo your password has a root password and probably 2-4 pseudo random characters appended/prepended/replaced? That means once it has been leaked in 1 breach, your 'true' algorithmic password is only 2-4 characters long. Which should take a few minutes to crack on other sites. And the more breaches you are included in, the easier it would be to work out your algorithm, reducing the number of attempts further. But they aren't going to target me specifically? They won't. They just find everyone whose password across multiple breaches is similar (Levenshtein distance or something) and brute force the differences.
- Santosh83 9y ago> But they aren't going to target me specifically? They won't. They just find everyone whose password across multiple breaches is similar (Levenshtein distance or something) and brute force the differences. Is this possible when the leaked passwords are all only salted hashes?
- snowwolf 9y agoYou mean like LinkedIn (SHA1 hashes without salt), Adobe (Poor Crypto), Dropbox (half of them SHA1), etc., etc. [1] https://haveibeenpwned.com/PwnedWebsites#LinkedIn https://haveibeenpwned.com/PwnedWebsites#LinkedIn [2] https://haveibeenpwned.com/PwnedWebsites#Adobe https://haveibeenpwned.com/PwnedWebsites#Adobe [3] https://haveibeenpwned.com/PwnedWebsites#Dropbox https://haveibeenpwned.com/PwnedWebsites#Dropbox
- arghwhat 9y agoNo, but not everyone follow good crypto practices...
- Santosh83 9y agoI did this too, back when I had to use public terminals and obviously could not use password managers. But the idiosyncrasies of password rules on many sites added to the complexity of my own "transformation" of the base password, until the whole thing while workable, became burdensome. These days I do all logging in on my own PC and therefore I see no real need not to use a password manager and unique, random passwords for each site. The obvious downside to this approach is if I were ever to be caught in a situation where I MUST log in to some site but do not have access to my PC AND phone, and therefore cannot risk opening the password DB on an alien system. Pretty unlikely scenario though.
- randallsquared 9y agoThis seemed like a great idea when I first encountered it, but trying to use it was a major fail for me. Encrypted files with a single long passphrase I can actually remember seems less prone to failure. What exactly is the product name? What is the website name? Does it include www? What about other subdomains? These are the same kinds of questions that make security questions so frustrating as designed. "What was your elementary school?" Hm. Is preschool elementary, or separate? Is the private school I went to for K and 1st an "elementary school" (there was no division between those in that school)? Maybe I should use the first school I attended between K-6 that had such a division? Or maybe just when I started public school, since that one was the first one called elementary...? "What was your mother's maiden name?" I hardly remember my mother, and when I started being asked her maiden name, I had to guess how to spell it. Is this security question one I answered when I was guessing wrong, before I knew how to spell it for real? Even if it's not, did I decide this time to use the old spelling for consistency, or to add a slight hitch to someone who looked that up and is trying to access my account? Essentially every answer to these kinds of questions that isn't about a number (and some of those!) comes with so many caveats that it seems unlikely I'll remember which path down this tree I took when I added it. The world is so fuzzy. This is like those "puzzles" where the wording of the puzzle actually admits many possible answers depending on how you interpret words and phrases, but everyone seems to settle on a meaning that's obvious to them, but the most "obvious" answer seems different from day to day for me.
- hellofunk 9y agoI did this myself for a couple years. I soon learned it is a flawed and insecure approach. I don't recommend it for a variety of reasons.
- bjt2n3904 9y agoFor web accounts I don't care about, a password manager seems to be handy. But for things like bank and email, I don't particularly trust a password manager. "CorrectHorseBatteryStaple" isn't too difficult to remember, and is plenty secure.