Hacker News new | past | comments | ask | show | jobs | submit login

I love passphrases and mnemonics. There are passwords that I retired out of anywhere they existed several years ago that I will probably never forget as long as I live. And not only is it easy to create memorable passphrases, and they're fairly long, you can then combine your passphrases in interesting combinations to get even more passwords that you probably will never forget.

Beyond that, the "never reuse passwords" adage is horribly oversold. If it handles my money, my email, or my web hosting, it needs to be unique. Passwords for places I comment are commonly reused and not as sophisticated because it is not seriously impactful to me if someone gets a hold of them.

Reuse passwords for sites that can't meaningfully harm you if they get compromised. Minimize how many accounts can harm you by not saving your credit card info in most of them, uncheck that box when you pay for stuff.

I'm also insanely liberal about deploying 2FA. I have it everywhere it's available, even sites with common/stupid passwords. So a lot of sites I don't bother with unique passwords will still be somewhat protected if my password is compromised. I'm also subscribed to haveibeenpwned with every email address I've ever used for anything.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: