Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I use a system where I mix a counter, a master password and website URL.

I don't hash it via a software algorithm, it is a system simple enough to do in my head.

I basically only have to keep track of the counter for the few websites that have forced me to change password.

The counter exist both as a number and spelled out, ensuring that changes in password differs enough for websites that require new passwords to not be similar to old passwords.

It is as secure as any 8-10 character password, except if a person is targeting me, and manages to get 2 or more passwords, there is a chance that they'll notice the system.

But if I am targeted by someone who can crack multiple of my online passwords, then I have pretty much given up hope for my safety.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: