Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That's fine until the first time you have to rotate a password, at which point it devolves to, at best, a mnemonic device.


At that point add a 2 to the end or change your username. Worst case you have to try a few times to get in, but eventually you'll remember it's one of those sites that uses the extra version information.


Right, at which point you now have to remember what iteration you're on (mnemonic device), or iterate versions on every login (IMO worse).


I don't think just appending a character to your password is such a good idea if it is compromised.


As a side note, trying various passwords doesn't strike me as a great idea either. You're basically telling the site you're trying to log into your other passwords you use, along with a username. At the very least you're revealing something about how you derive your passwords, if you have some scheme.

I'd say that if I'm not sure about the right password, it's safest to go straight for a password reset function, instead of giving all my passwords or a password derivation method to some random website.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: