Live data from Hacker News

Enforcing Different Passwords for Different Sites

diegobasch.com

51–56 of 56 posts

Re: Enforcing Different Passwords for Different Sites

#51
The desire to enforce unique password across sites is understood. You might as well advocate all browsers to implement a builtin password manager a la LastPass and a protocol to auto-gen a password (by the site to enforce cross-site uniqueness) to be managed by the password manager. Imagine zero password fiddling signups!

Force a per site password policy on end users other than length is super annoying. The worst kind are those who restrict you to use only alpha-numeric passwords.

Down with manual password policies!

Re: Enforcing Different Passwords for Different Sites

#52
post #29

Earlier quoted context omitted.

See all my other comments on this thread. Why does your mother use LastPass? How did she learn about it? How about the other 99% of the people? How do you make them use LastPass? This is not about us.

> Tell the user: your password must contain the following word: “hzru” Enforcing this kind of thing on the masses won't make for stronger passwords, it will just have them opening up notepad.exe and saving this sites too-hard-to-remember-because-it-has-too-many-rules password on ~/Desktop/logins.txt

And when they go to another computer (home/work/relatives/...) the only option is to carry that file.

Re: Enforcing Different Passwords for Different Sites

#53
Because browsers already optionally store passwords, adding the "password same" warning would be quite a welcome feature (or add-on), for me anyways (in mobile browsers too).

I advocate the use of password managers, but they don't offer "password same" warnings either.

My point: it's a best-practice feature option which should be implemented widely. People can turn it off if they want.

Re: Enforcing Different Passwords for Different Sites

#54

I am the only person I know who uses a unique, memorable and strong password for every site I use. I store all of them in my head. I have a base password and I add the first several characters of the site to the middle. For example: Facebook - sdfb231a2 Hacker News - sdyc231a2 Yahoo - sdya231a2 For strong passwords I can add a suffix to further strengthen the password. PayPal - sdpa231a2a4 I use the same suffix for a…

What do you do when you log in to your bank and they tell you that your password has expired and that you need to create a new unique 6-8 character password with exactly one capital letter and one number but no special characters? And that it can't contain any part of any of your old passwords? I guess the same thing you'd do if you ran across a site with this well intentioned but terrible idea: write it down or emai…

I have a standard set of characters that I add to passwords. So far Craigslist has been the only site to really throw me for a loop. I try to be consistent but I end up using 'Forgot my Password' more than I should with them.

They are the only ones.

Re: Enforcing Different Passwords for Different Sites

#55
post #43

I am the only person I know who uses a unique, memorable and strong password for every site I use. I store all of them in my head. I have a base password and I add the first several characters of the site to the middle. For example: Facebook - sdfb231a2 Hacker News - sdyc231a2 Yahoo - sdya231a2 For strong passwords I can add a suffix to further strengthen the password. PayPal - sdpa231a2a4 I use the same suffix for a…

That seems like what SuperGenPass ( http://supergenpass.com/ ) does, but with more effort and easier to break. Essentially, with SGP you type a master password into the password box and click the button in your browser (you don't have to install anything, just bookmark the javascript). It uses a one-way hash to create a unique password based on the domain.

I guess, but my method only uses my brain. I can access my accounts using an internet cafe, someone else's iPod Touch, etc.

Re: Enforcing Different Passwords for Different Sites

#56
post #48

I am the only person I know who uses a unique, memorable and strong password for every site I use. I store all of them in my head. I have a base password and I add the first several characters of the site to the middle. For example: Facebook - sdfb231a2 Hacker News - sdyc231a2 Yahoo - sdya231a2 For strong passwords I can add a suffix to further strengthen the password. PayPal - sdpa231a2a4 I use the same suffix for a…

I've done a bit of this and I suspect a few others have considered something similar, if not doing it themselves. I'm concerned about leaking a couple of these types of passwords, enough for someone to notice the pattern and apply it to the rest of your online presence. I'm sure there are black hats building personal databases of every password leak that goes by and it wouldn't be hard to do some sub-string matching…

I don't think I am interesting enough or lucrative enough for someone to expend that much effort trying to hack my accounts. If they compromise my password on one service (and presumably gain access to thousands of other passwords), if mine is unique and others aren't, I'm betting the attack (on me) stops there.
Post reply on HN