4 ms·
I changed all my passwords recently to do the same thing. The problem I've recently started to see is that, let's say for example my hashed+salted password is
by ToastyMallows 13y ago
I changed all my passwords recently to do the same thing. The problem I've recently started to see is that, let's say for example my hashed+salted password is stolen from a site. If they brute-force figure out what my password is, they'll have my "base word" and all my other accounts may still be able to be compromised.
Recently I changed my big accounts (Google, Facebook, StackOverflow) to have a slightly different "base word" and the other accounts that I can afford to lose control of have stayed the same.
- smileysteve 13y agoIt's significantly more difficult to reuse the base and figure out the additional characters than it is to get access to the user whose password is 'password' For insecure services that I use on mobile, public, etc computers, I do this.