4 ms·
My personal method is passphrase + first three characters of domain + number + ! Eg foobarYCO2018! Easy to remember, unique and doesn't rely on third-party se
by baggsie 8y ago
My personal method is passphrase + first three characters of domain + number + !
Eg foobarYCO2018!
Easy to remember, unique and doesn't rely on third-party services.
- vemv 8y agoAnd derivable.
- detuur 8y agoThis was my method until widespread and non-terrible password managers. The fact is that once you're dealing with an adversary who is sufficiently motivated to capture passwords from you and derive the algorithm, you've already lost. Sure, it's a form of security through obscurity, but aren't we essentially relying on our computer systems' flaws remaining obscured to not get hacked?
- notriddle 8y agoBecause you're not special, and you're not smart either. Your adversary already knows your password derivation scheme, and are already checking for it during the brute-force step, because you're not the first one to come up with it. Browser and operating system vendors aren't especially smart either, but at least it's thousands of white hats vs thousands of black hats, instead of thousands of black hats vs just you.
- jmmcd 8y agoIt's not good to reveal your scheme, or for your scheme to be so simple. If a HN database ends up in the open, your accounts on other sites become vulnerable.
- bscphil 8y agoIdeally your passphrase would be secure enough that it couldn't be bruteforced from a (hashed) HN database. But in case a non-hashed database gets leaked, what sort of scheme could one use that couldn't be revealed from a single known password? I suppose one could use a system like bcrypt(passphrase + "domain.com")[:32] But anything requiring a calculation step seems to lose a lot of the advantages of a single-passphrase system.