4 ms·
I use a simple algorithm. So you don't actually remember the password, put the algorithm to produce the password for the site or service. Not perfect, but each
by 725686 2y ago
I use a simple algorithm. So you don't actually remember the password, put the algorithm to produce the password for the site or service. Not perfect, but each passwords turns out to be unique (mostly). I don't know what experts think about that, but it has worked fine for me.
- joshstrange 2y agoThe problems with this method are numerous: * If 1 to N password(s) leak the pattern may be obvious leading to your other accounts being compromised * Not all sites have the same password “rules” so there is no algorithm that works for all passwords without you being aware of the rules of the given site. Rules that only you only (may) have access to at signup time. * Typing passwords out manually sucks (slow and error prone)
- maeil 2y agoNumerous is greatly overstated. 1) only matters if you're a very high value target who is being manually target. Doesn't apply to 99.999% of people, who only need to worry about credential stuffing and brute force. 2) Similarly, it's not hard to come up with an algorithm that satisfies 99.9% of websites. 3) To a lot of people, managing a password manager sucks. I personally do use a password manager and automatically generated passwords, but also understand that for many people it's the better option.
- n8m8 2y agoI agree that especially with modern LLMs, I would avoid following patterns like this. Dedicated 2FA on a hardware device seems pretty resilient, I hope more banks incorporate it instead of SMS 2FA. Hosting vaultwarden also seems pretty good because it’s unlikely for you to be targeted, but requires selfhost maintenance.
- 725686 2y agoYes! I'm totally aware, but, for the first point, attacks are generally automated. If someone tries to find the pattern, you are being personally targeted and you have bigger problems. As per number 2, it is true and it sucks big time. As per number 3, I don't really mind much. You don't generally have to use your password every time.
- 9x39 2y agoBut where do you store emergency codes? Or secret metadata for things? I think these are common artifacts to accumulate. A password manager is ideal for these when security is far more than passwords at this point.
- cuu508 2y ago> But where do you store emergency codes? On paper.