4 ms·
I don't use a password manager tool because I don't feel I need to. I take a kind of algorithmic approach to generating unique passwords for each site I use. I
by Stoo 12y ago
I don't use a password manager tool because I don't feel I need to. I take a kind of algorithmic approach to generating unique passwords for each site I use. I have a root password which contains the usually required alphanumeric with an upper case letter and some special characters. The rest of the password is based on the site or service I'm logging into.
A really simple example would be:
cabbage123!face <- Facebook
cabbage123!goog <- Google
cabbage123!twit <- Twitter
I only have two things to remember - the root part of the password and the way to generate the last part. Obviously, just using the first four characters isn't the best idea, but you can change that part to whatever you want to - it's kind of your own secret key.
- Gustomaximus 12y ago2 problems; 1) Some sites place rules on the password. A bank I used limited passwords to 6 characters! Can believe someone thought that was a good idea. 2) If you use this on random sites someone might pick up the format quite easily if they are targeting you. I'd suggest using layers of 'root' so random sites you sign-up use one root (e.g. HN), mid-security sites use another root (e.g FB), and high need for security sites use a third root (Financial). I do something like this to limit risk and it's not too hard to remember. Regarding the single point of failure which I believed previously was a problem with password managers, Voxic11 explained otherwise a couple months back in a previous thread: "LastPass and other password services don't actually store your information in any way they can read them. What they do is store the password information as a encrypted blob and the public key derived from your password. When you "log in" you actually are running the key derivation function on your password locally then signing a message with your private key and sending that to Lastpass. When they receive the signed message they check it against your public key and if it passes they send you your password information. Which you then decrypt clientside. So anyone who compromises lastpass gets nothing except a bunch of encrypted blobs and public keys. The only way to get at your lastpass information is to retrieve the unencrypted copy off your computers memory, but if a hacker can do that they can just steal your passwords as your type them in anyways."
- Stoo 12y ago> 1) Some sites place rules on the password. A bank I used limited passwords to 6 characters! Can believe someone thought that was a good idea. That's true, but I haven't recently come across a service that I want to use on a regular basis which has that restriction. If I do need to sign up to a site which has a similar restriction it's normally something I'm going to use once so I use a garbage password and rely on their password reset mechanism if I need to use the service again. 2 is a good idea and I'll start doing that. It still keeps what you need to remember to a minimum while adding greater uniqueness to passwords.
- DanBC 12y agoWhat happens if you suffer a memory-loss causing brain-injury?
- mod 12y agoWhat happens if you suffer that and lose the master password to your password vault? His method, though flawed in other regards, would potentially work out better for this problem--if he could work out one password, he could probably guess at the rest.