Hacker News new | ask | show | jobs
by cdubzzz 3382 days ago
There has been lots of discussion surrounding that comic. I have read a few articles over time and ultimately landed, one way or another, on considering it bad advice.

Here is some info from a quick search: https://security.stackexchange.com/questions/6095/xkcd-936-s...

1 comments

Cool thanks for the link! Were you meaning to say that you consider the "correct horse" password selection principles bad advice? Or that the advice given by the author of the article is bad advice?
I feel the "correct horse" method is bad advice. Though, certainly not terrible. I actually followed it for a while and it works amazingly well for memory, but over time I was convinced that the best route is a password manager with randomly generated passwords.
That doesn't make it bad advice.

The comic advises using correct-horse style passwords rather than tr0ubaDour-style. That is good advice.

I agree, I think a manager with randomly generated (and long) passwords is the way to go in terms of security + ease of use sweet spot. edit: in addition to 2FA/yubikey type measures.
What do you use to unlock your password manager?

A 7 word diceware passphrase would be a good idea.