Live data from Hacker News

Ask HN: I have 176 logins/accounts. How many do you have?

news.ycombinator.com

111–120 of 300 posts

Re: Ask HN: I have 176 logins/accounts. How many do you have?

#114

If I need to login to your site less than once or twice a year, "Forgot my password" is my password manager. Personally, I feel that the utility of me working to keep and maintain that information in a database for high availability is essentially zero. As a result, I store very few accounts overall and checking out as "guest" hasn't been a problem of any sort. There's like 10 critical things that I feel the need to…

I just use a crappy password. It's been leaked before. I don't care.

If someone wants to take over my last.fm account that I haven't used in 3 years, sure go for it.

The important accounts get a randomly generated password stored in my password manager. And the really important accounts only have half the password saved, I manually fill in the other half.

Re: Ask HN: I have 176 logins/accounts. How many do you have?

#118
post #90

Earlier quoted context omitted.

It's not pragmatic, it's dangerous. Sooner or later someone could take control of one of the accounts you don't care about and use in a way you don't expect to gain control of things you do care about.

Beyond my accounts related to my important email addresses, Steam, finances and medical which can all be counted on one or two hands, I really couldn't give a damn about the other accounts or their password security. Strong and unique passwords for the important accounts, simple and reused passwords for the rest. You're welcome to hack into my accounts on Hacker News, Reddit, Discord, LINE, various IRC networks, vari…

On its own, the information in those private accounts is probably not interesting. I used to use the "few sites get a unique and secret password, but most reuse the same 10 character one" ruleset, but I became worried about how much data could be aggregated about me. By re-using the same password, I felt like I gave a simple test that attackers could use to definitively confirm "user XYZ on site ABC is the same as ccooffee".

I'm now firmly in the "everything gets a unique password" camp. There are 4 important passwords I type myself, but everything else is in a password vault.

Re: Ask HN: I have 176 logins/accounts. How many do you have?

#120
post #90

Earlier quoted context omitted.

I take a pragmatic approach: the dozen logins in my life that actually matter get strong unique passwords, and everything I don't give a shit about gets the same password.

It's not pragmatic, it's dangerous. Sooner or later someone could take control of one of the accounts you don't care about and use in a way you don't expect to gain control of things you do care about.

> use in a way you don't expect to gain control of things you do care about

An example would really drive your point home. Can you provide one that people would deem "dangerous"?

Edit: ccooffee just mentioned in the thread that you could be de-anonymized by reusing the same password. Is this what you mean? There's a spectrum of comfort with privacy so maybe that's the source of the disagreement between whether it is important to have unique passwords or not for accounts that don't contain financial/SSN/medical/etc information

Post reply on HN