Hacker News new | ask | show | jobs
by Lagged2Death 3250 days ago
I have a default password that is very simple ... that I use for most logins ... Unless you're vitally important to my life...

That's all fine if you're a perfect robot. It will turn out that you aren't, though.

You could let one of your important passwords slip to a compromised dumb-password site by mistake; you could fail to appreciate how important a dumb-password site had become to you until it was too late; you could just make a human goof and set up PayPal (or what have you) with your dumb password.

But your personal ability or inability to get this stuff perfectly correct forever is kind of beside the point when you're setting policy. In a population of dozens, mistakes will be made. In a population of millions, mistakes will be legion.

If more organizations followed this guidance, it would make password systems easier to implement, easier to use, and more secure for everyone who did care. It wouldn't effect your practice in the slightest.

1 comments

This same principle also applies if you have one Serious Business e-mail (job applications, professional-related things), and another "Just For Random Crap" email address -- you may find yourself, one day, having signed up for a cloud service or other thing (I don't know, bitcoin exchange?) with an account that you suddenly wish were your Serious Business one.