3 ms·
My personal favorite method for passwords is come up with a passphrase I can remember, encode it to base 64, and use the encoded string as the password. If its
by broast 3y ago
My personal favorite method for passwords is come up with a passphrase I can remember, encode it to base 64, and use the encoded string as the password. If its not too long, the encoded version is usually not hard to memorize either.
- akerl_ 3y agoWhy?
- jmclnx 3y agoI usually do this: tr -cd "[:alnum:]" < /dev/urandom | fold -w 20 | sed 10q Then I use an encrypted text file via Emacs to store my passwords
- an_ko 3y agoThanks, I'll add base64 as one of the trivial transformations to my ongoing brute-forcing effort of all your passwords, multiplying total search effort by a tiny constant. I'm joking. But what if I weren't? Especially if you're going to announce this on the internet, it sounds far more effective to add 1 character to the end of your passphrase instead, since each exponentiates any brute force effort, and isn't defeatable by a simple pattern. (Or announce on the internet that you're doing something far more complex, like running bcrypt on all your passphrases to generate your passwords. That would make an attacker's life significantly more difficult than base64.) (Or always lie on the internet about how you generate your passwords. I hope that's what you're already actually doing.)
- broast 3y agoI personally can appreciate multiplying an attackers standard dictionary with a transformation. I find the decoded passphrase is already high entropy so it just adds a little bit of trouble. I might consider bcrypt, thanks for the idea.
- seoulmetro 3y agoWouldn't it be adding whatever the sum of your brute forcing list is onto itself? Which seems like a lot?