Hacker News new | ask | show | jobs
by OnMyPhone 2968 days ago
I got into the habit of using a separate password for each site I use, except for the throwaway sites.

I have a method I use regardless if 2fa is an option or not.

I have a fairly secure password that I have memorized. Then for each site I pick something about it that I can remember to add on to the password.

For example if my current ebay password is: Pa$$w0rd the new one would be: Pa$$w0rdEb or EbPa$$w0rd Amazon would be: Pa$$w0rdam

That has helped a few people I know keep separate passwords for each site without having to go through a password manager. YMMV of course.

The way I look at it is if the sites DB gets dumped, at least the scripts will fail using the password on other sites, even if it's not the most secure password.

You're point about the phishing e-mails is spot on though. No amount of secure passwords will stop that

1 comments

Exactly!! I have a scheme like this but more convoluted, low/medium/high consequence sites, different random 'main chunks' that I can remember, and a quasi-methodical per-site head/mid/tail chunk that is related to each site.

Never found any of even the main chunks in the PW lists, but I'm sometimes forced into stupid PWs by stupid rules as in above comments.