Hacker News new | ask | show | jobs
by Ensorceled 2977 days ago
I'm not sure what you are saying ... should I memorize dozens of passwords like WCLfx(edI%uHgjWM6RuEeC6Qh for the services I use or should I strap on getting those dozens of services to use a perfect SSO service that doesn't leak privacy and is perfectly secure and doesn't exist yet?
1 comments

I'm saying all solutions are a compromise.

(And you do need to memorize your password manager password - and your main email account password as well)

Also a lot of leaked passwords were strong, they just got compromised because someone didn't know about 70's password security basics.

Should we just never use any leaked password ever again? (Note I'm not saying: with the same login - or any of the "top 100") Should we really trust all of our passwords to one service that might get compromised or just go away?

Should we bother creating a strong unique password for that new cool SF startup that doesn't know how to use bcrypt?

But why is it a crutch for me to use a password manager? What's my non-crutch alternative?