5 ms·
Tell HN: Use a system instead of an app to manage your passwords
Hello.
I wanted to share my system in managing passwords, especially after reading this[1] story on HN yesterday.
Without thinking much, I've always been against these app enabled solutions for managing important information, reading that story only increased that feeling.
How to rely on yourself and a system personal to you to manage your passwords?
1. Have a system.
2. Use the surrounding information to always tell you how to access your password (or other important information).
The only requirement for the system is that it is consistent.
Once you start using it, you can't change it.
If you want to change it, you have to start fresh.
For example, a system can be: ${constantSpecial1}${context}${constantSpecial2}...
By using this the only thing you need to remember is the ${constantSpecial1} and ${constantSpecial2}.
Make them as complex and as easy to remember as you can.
What I mean by use the surrounding information?
If you're logging into a website, the website is always known to you.
You can't forget that, because, it's the website name.
So in conjunction with the system, you can always have a unique password for a unique website.
Examples:
System - veryWeak${context}123
Passwords:
...
Log into Facebook: veryWeakFacebook123
Log into HN: veryWeakHackerNews123
Log into BBC: veryWeakBBCNews123
...
By using these simple rules, it's quite impossible to forget your passwords.
You also have a unique password for all services.
Hope this was interesting!
P.S.
If you're logging into a shady website, which does not seem trustworthy, use a simple password (password1), to check if they do anything shady.
Only after confirmation use your real password.
[1]: https://shkspr.mobi/blog/2022/06/ive-locked-myself-out-of-my-digital-life/
- gigel82 4y agoI host my own Vaultwarden (Bitwarden backend), but every month or so print a physical copy of my passwords and put that piece of paper in a safe. Never needed the paper, but it's good to know it's there in case something catastrophic happens (where my home server, my backups and my offsite backups all get destroyed).
- moasda 4y agoInteresting approach. What do you do if one of the passwords got leaked? What new password do you use then? If I knew one of your passwords, would you consider your system to be still secure?
- crugthew 4y agoThanks! Perfect security does not exist. It's the same as if the master password to a password manager app would be leaked, what then? You start from scratch and change the system. If a plain-text version would be leaked, that's the worst scenario. But in in most cases what could be leaked these days, is the hash. So you can change the password by modifying the context. For example, if you log in to "microsoft.com", you first used `ms` as the context string, so change it to `microsoft` or `m$`, or something else. You would still likely remember that quite easily. What this tries to solve is to be secure, unique for each account and not rely on any other third party.
- moasda 4y ago> not rely on any other third party That's the main advantage of your approach I think. And it works with all devices. A lot better than using the same password for several accounts, as many people do.
- night-rider 4y agoCheck out Master Password: https://en.m.wikipedia.org/wiki/Master_Password https://en.m.wikipedia.org/wiki/Master_Password It’s a deterministic password manager that already has a ‘system’ prebuilt. There are caveats to using however like when you changed a password and you no longer can use MP.
- speedgoose 4y agoSometimes a website will refuse your password because it’s too long, or doesn’t contain special characters, or does contain special characters,… Then you need to remember the specific password rules for a website. I used to use your system, but i think that a password manager app is a lot more convenient.
- crugthew 4y agoI get your point, but frankly, if a website does not allow special characters, then you probably should not use it. I'm not stating that this approach is a catch all solution. It simply aims to be non dependent on any other third parties and generate unique, but memorable passwords for all the websites we need.