3 ms·
> how do you propose remembering unique fully random passwords for dozens to hundreds of services over the course of decades? not fully random, but: make up a
by kaens 8y ago
> how do you propose remembering unique fully random passwords for dozens to hundreds of services over the course of decades?
not fully random, but:
make up an algorithm that uses pieces of data that you know you can derive from some superficialities of anything you need a password for plus some some obfuscation function and some other data that you can derive or remember that is not related to the thing you need a password for.
e.g: the name of the site and the month you signed up in leet speek, rot-5'd and alternating letters, interspersed with symbols at some period related to a rhythm you like.
doing this gives you relatively strong passwords that you can reliably recreate while not needing to memorize them, that do not have an obvious pattern to them even if looking at them in mass, that have a very low chance of collision. you can remember a fairly complex recipe pretty easily ;)
depending on where your passwords are and what they're for, this might be preferable than storing them in one app that can compromise every password you have.
either way, someone only needs your important pw once. use multi-auth.
- NikolaeVarius 8y agoAnd then what happens when that has to change every 30 days?
- kaens 8y agofor the example above, you could chunk-rotate, change the rot-degree you use as obfuscation or have other variants of your algorithm. there's a point somewhere a bit faster than monthly-expiration where I would consider using a store and random gen in situations where i would otherwise not. really depends on you, what it's for, and what risks you need to care about the most.
- gruez 8y agoWhat you're basically describing is no-sync password managers[1], with all of its disadvantages (password changes/rotation, username storage, etc) but also with security by obscurity instead of a proven KDF. [1] I'm not sure what they're called exactly, but basically all you do is enter a password and it generates your password using your password + site + KDF.
- kaens 8y agocorrect, the point of doing something like what i'm describing is to have a system for keeping / creating N unique passwords stored only in your head, in a way that provides an acceptable amount of strength, avoids disclosing all of your passwords if one is compromised, and doesn't require you to be a savant of long-random-string memorization. there are plenty of things that this isn't an appropriate approach for, and fwiw I wouldn't tell someone it would be a good strategy for all their passwords. it can be useful when you have a set of longer lived passwords that you need to care about guaranteeing that the entire set can't be snarfed without holding you at gunpoint.
- jsutton 8y agoYour strategy doesn't negate the need for a password manager for all of your non-essential web accounts.
- UncleMeat 8y agoHow do you propose to change your password after a breach?