3 ms·
I have a pretty simple way to generate a unique password for each site I use. I start with a strong password: aw3#rTT That will not change from site to site.
by elbrodeur 16y ago
I have a pretty simple way to generate a unique password for each site I use. I start with a strong password:
aw3#rTT
That will not change from site to site.
Then I insert site specific data into that password. You can also append, prepend or insert. The point is to have a site-specific password that uses a formula that is hard to guess. There are a number of ways to do this. You could use the company name, login name, domain name, url of the login page or any other site specific rubrik.
Let's say my formula is to use the first and last character, the last character always being capitalized. Let's use the domain name:
gmail.com -> gL -> gaw3#rTTL
Or, you could take the first and last characters and insert them after a specific character in your password. Say, the pound symbol:
facebook.com -> fK -> gaw3#fKTTL
Or take last two characters of the domain (or last two, etc) and prepend them to the password:
twitter.com -> Er -> Eraw#rTT
- tzs 16y agoThat would be a little too easy to figure out if the bad guy got to see 2 or 3 of your passwords, which could happen if 2 or 3 sites you use got compromised. A better scheme in the same spirit as yours but with better security would be to take your master password and append the name of the site, say aw3#rTT:gmail.com, an then hash this, and then use a base 92 encoding to map that to letters, digits, and punctuation, and take as many characters of the resulting string as the site allows. I started to design and build a simple password manager based upon something like that. It would store in a file a list that looked something like this: 0:*.amazon.com 0:*.ycombinator.com ... When you ask for the password for a given site, it would look through the file matching the URL against the patterns on the right, until it found a match. The input to the hash would be the matching line and your master password. The prefix number is a password revision number. Since the whole line is part of the hash input, changing the revision number changes the generated password. Then I got 1Password as part of MacHeist, and my simple password manager project pretty much died.
- elbrodeur 16y agoThat's certainly a vulnerability, though a pretty small one. Most huge credential compromises that result in other accounts being hijacked are done programmatically: It's not like the script that's checking if your gawker password matches your gmail password will try permutations after first attempt. I really like your mechanism for secure passwords. Though it's definitely more time intensive. 1Password has been praised highly by a couple coworkers and I've been meaning to try it -- the problem is, you should still have strong passwords for individual services even if you're strong them in a single repository like 1Password. I think my formula is decent, though by no means totally secure.
- tzs 16y ago1Password (and most other password managers, I believe) are happy to generate strong passwords for you. I generally actually have no idea what my password is at most sites, as I let 1Password deal with that. Here are a few samples. I've asked it for 16 character random passwords with 2 digits and 2 symbols, repetition allowed and ambiguous characters allowed: xQO3<hCnp^uKh7mP t0ee4uHIsQv'Kk<Z zXS;DY3)U3OzAebT It also lets you ask for pronounceable passwords, although you generally then nead longer passwords for good strength. Here are some examples: cac-kon-eg-voil-eng-es- rhook-bea-say-rou-hen-h ju-cadd-irv-iaf-moif-do I'll use that kind if I'm using 1Password just for storage, not automatic entry (for example, the login password for a game client). You can also ask for digits instead of dashes in the pronounceable passwords, like this: ho9swap4cyat6lold9us6bu or no separators (requiring you ask for a longer password for the same strength), like this: mitalwebshefrufegbiheagdihet
- deleted 16y ago[deleted]
- troyhunt 16y agoSo what do you do when the site doesn't allow hashes? Or special characters? Or letters? And yes, there are lots of these http://troy.hn/dJbdTU http://troy.hn/dJbdTU
- elbrodeur 16y agoI haven't run into that problem yet. If I consistently had to deal with that, I think my approach would be two have two password keys. A strong and a weak one.