Live data from Hacker News

PasswordCard

passwordcard.org

1–10 of 31 posts

Re: PasswordCard

#2
A thief could still very easily brute force your password if you actually follow the instructions on the card. I suppose you could get creative with how you interpret the card.

Security is tricky.

Re: PasswordCard

#3
This would be kind of annoying to pick that card every time I want to enter a password.. no?

I Like To Take The First Word Of Easy To Remember Sentences. (iltttfwoetrs) and put some random i->1 and a->@ and o->0.

This way, it's fairly secure and easy to remember.

Re: PasswordCard

#4
post #2

A thief could still very easily brute force your password if you actually follow the instructions on the card. I suppose you could get creative with how you interpret the card. Security is tricky.

Maybe, but agree that if a thief find this "weird" cards by taking your wallet, the chance that he find what it means.. and to actually find a way to brute force is really low.

Compare that to a plain paper with a password written on it!

But yes.. security is all about trade of.

Re: PasswordCard

#5
or... you just use something like firefox's master password.

you can use as many passwords as you can think of, but only have to remember 1 of them.

Re: PasswordCard

#6
My personal password scheme is to string together a few random things. 2 or more random things I happen to be thinking about that day (often abbreviated weirdly to prevent having actual words in my password) with random special characters between them and/or at the beginning or end.

This may not be as secure as a random SHA1, but it's so random (and usually pretty long) that I think it's pretty solid.

One bad thing is that I have taken to having one password for all of my "really don't care about this" websites. Only for stuff where if it were compromised, I really wouldn't care (though I might care a little), but it's still not a great practice, and that password is weaker than my other ones.

Re: PasswordCard

#7
post #3

This would be kind of annoying to pick that card every time I want to enter a password.. no? I Like To Take The First Word Of Easy To Remember Sentences. (iltttfwoetrs) and put some random i->1 and a->@ and o->0. This way, it's fairly secure and easy to remember.

Personally, after some silent wonderment, other reasons don't.

(I'm sorry, that was awful.)

Re: PasswordCard

#8
post #3

This would be kind of annoying to pick that card every time I want to enter a password.. no? I Like To Take The First Word Of Easy To Remember Sentences. (iltttfwoetrs) and put some random i->1 and a->@ and o->0. This way, it's fairly secure and easy to remember.

works until you recall it as "iltttfloewoetrs" :)

Re: PasswordCard

#9
This is a stupid password scheme. You still need to remember some weird piece of information (a symbol and colour? wtf?), and if you put that as the password hint for your websites, they will be able to figure out your password if they have the card.

And it can be brute-forced too.

Just use something like 1Password or LastPass.

Re: PasswordCard

#10
The problem I see is: it's still a bit complicated (i.e. too complicated for the "usual" folks). I see a lot of the security stuff failing for most people because it's just not easy enough.

In this sense, Lastpass (passwords stored online) or Roboform (passwords stored locally) is imho better in that it makes it easy to use secure, one-time passwords for each website.

Post reply on HN