3 ms·
Depends on the attacker, but it's probably accounted for at least partially. In some passwords where I don't care much about security I'll use this technique an
by romdev 8y ago
Depends on the attacker, but it's probably accounted for at least partially. In some passwords where I don't care much about security I'll use this technique and some personal, site-specific mnemonic - if their logo reminded me of a gerbil, I might start with the name of a pet gerbil I once had and obfuscate it with character replacement or keyboard proximity replacement (same characters, one row up or down). These passwords are always unique to the site, which doesn't get any financial info.
When I need a secure password that's easy to remember I'll obfuscate the initials of a memorable passphrase from a joke, poem, song or book. My password manager is offline (remember the LastPass hack?) so I need to read from it once and type it in.
Update: I remembered this old article that describes some of the techniques that have been used to crack passwords, including 133t-character replacement:
https://arstechnica.com/information-technology/2013/05/how-crackers-make-minced-meat-out-of-your-passwords/ https://arstechnica.com/information-technology/2013/05/how-c...