4 ms·
I agree. The section on "Use tough passwords and change them frequently", except for the final suggestion to use a password manager, felt like antiquated passwo
by glitcher 8y ago
I agree. The section on "Use tough passwords and change them frequently", except for the final suggestion to use a password manager, felt like antiquated password advice.
- plemer 8y agoWhat do you use instead of a password manager?
- TimTheTinker 8y agoI think you misunderstood the sentence. OP is saying TA's password advice (except for "use a password manager") is antiquated.
- plemer 8y agoYou're correct, I misread. Thank you.
- stretchwithme 8y agoAs long as the password manager is trusted. Some are run by a single person nobody's heard of. I met a woman in Vegas who ran one and who couldn't believe that people trusted it so much.
- tokyodude 8y agoAnd then there are ones like LastPass that people on HN seem to recommend even though their TOS basically says they spy on all your browser behavior and sell it to 3rd parties
- TimTheTinker 8y agoI trust 1Password at present. Everything they’ve done so far (including the structure of their financial incentives) has indicated to me that they are both willing and able to protect my privacy (even from future untrustworthy management) via their software.
- SlowRobotAhead 8y agoBecause that IS antiquated password advice. 1. In terms of “strong passwords” it’s better to use the words “paraphrase” which if they get past 4 words are almost always stronger than traditional “passwords” humans actually use. It’s a nitpick, but using the better term leads to better results in my experience. “Do I need a new password? No, you need a new passphrase” 2. In terms of rolling credentials frequently and on some time period, NIST specifically recommends against that now.