Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This isn't the actual algorithm I am using, but was just an example to make my point.

But true, this isn't perfect, but just makes one step more complex, without having to use an external password manager...



I do something similar, however I take a portion of the site name an intersperse it throughout the stronger password in set positions. I could modify case of the site name snippet, however I do not currently.

While this is certainly relying on obscurity, it at least makes it much more difficult to figure out what is going on. I'd think you'd need access to two of my passwords in plain text in order to really figure it out.

My lastpass password is a 29 character password comprised of 3 parts, one of which is this pattern, the other two are 'secure' passwords i've used in the past but haven't been compromised to my knowledge.

Even with all of this - if one password was compromised in plain text I would likely abandon all of my passwords and try again with something new.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: