Hacker News new | ask | show | jobs
by johngarrison 3184 days ago
Frankly, I don't trust password managers. Perhaps I'm naive and they're perfectly safe, but still.

My solution is to develop an algorithm for all my passwords that is pretty quick and simple to memorize but allows me to "generate" a unique password for each service that I use.

Although I seriously doubt anyone could figure out my algorithm by learning one of my passwords, I'll admit that if they were to gather 3 or more then they'll probably be able to figure out my system. But since I never write down or record any passwords whatsoever (all I need to remember is my algorithm), someone would have to steal my credentials from multilple sources and also be able to know which credentials from one service match a user from another, etc.

1 comments

1. Linkedin, Yahoo, Disqus. Probably a few others for good measure.

2. Search for any combinations of john, garrison, and any other names I can determine by looking up your comment / post history here

3. Check the list of results to see which appear to be reasonably complex and of similar construction to determine which are likely yours. People with "good" passwords are very much in the minority, so this should be pretty straight-forward and mostly automatable.

4. Manually try to determine your scheme, which according to you is probably doable with this information.

---

Not saying it'd get you for sure, but if your replacement of a password manager is hamstrung by knowledge of at most three of your previously used passwords, you're probably doing yourself a disservice.