Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This strikes me as a really good strategy. Thanks for sharing.

At first I thought you were going to advocate the "just pick a prefix and then append the name of the site after it", like Go123facebook and Go123gmail. Which is, of course, quite awful because one plaintext reversing of one password may very well defeat all of the other passwords.



I figure if people are going to write things down on sticky notes anyway, it might as well be part of the system.

Hmmm... also, there's a failure-mode with systems that notice the prefix and reject future passwords as "too similar to one you used before". Users would have to deviate from the strategy somehow.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: