3 ms·
What about the other case - when they're not random, but also not reused ... such that the psychology of the user's password-selection methodology might be expo
by royce 9y ago
What about the other case - when they're not random, but also not reused ... such that the psychology of the user's password-selection methodology might be exposed?
- kazinator 9y agoIf you have a password selection methodology that you do not change when hashed passwords are compromised, then it doesn't help you. The methodology will be uncovered once the password is cracked, even if that specific password doesn't itself work anywhere anymore. It's somewhat better if the methodology is discovered later than earlier, I suppose.