Hacker News new | ask | show | jobs
by philipwhiuk 3017 days ago
I mean it's bad but it's not that bad really. Obviously if everyone used the same sequence it would be very terrible.

It's marginally better than pure password reuse.

But compared to Troubador (https://xkcd.com/936/ ) it's not really worse.

It slightly mitigates the 'humans are bad password generators' trap.

Really it mainly falls down because passwords are terrible and the best industry standard solution is a shit version of OAuth where the OAuth mechanism is 'copy and paste from <InsertPasswordProvider>'.