| My alternative is believing that not all websites you log into pose the same risk to you and accepting some risk. This means I divide websites that require login into two categories: 1. I don't care if somebody gains access to my account 2. I do care if somebody gains access to my account I use the same password for all the websites on the first category. It should be at least 8 characters long, consists of a made up word with some numbers and characters. Example: 7%Frifells. I drop the special character on websites that don't allow them in passwords and then it's a matter of failing to log in once and trying without it. I use a different "xkcd" password (https://www.xkcd.com/936) for every website on the second one. Those are essentially catchphrases which I end up associating with the website I use them for. They consist of several words with numbers and special characters (using the example in xkcd, mine would be correctHorse?1batterystaple!). So, I have to memorise about 8 passwords, all which make sense to me. In addition I have a password reminder file which consists of the website URL and the first two/three characters of the password. I don't bother adding completely unimportant websites from the first category. If my password from category 1 gets compromised then it's a bit of a hassle to change the password on all the websites on the files, but no harm done.
If a password from category 2 gets compromised then it doesn't affect the other websites. --- I wish a lot of websites would realise they can be password-less. Pinterest is a good example. I have never posted anything, they don't have any personal or financial information from me and if and the only reason I registered was because I wanted to search something there once, and they made me register for that.
Same goes to Quora and many other websites. I think all those should allow registering without a password but limit the functionality of those accounts. --- Edit: formatting |
Each account an attacker can gain control of, is more information they can glean and potential leverage points to gaining access to the accounts you do care about.