Hacker News new | ask | show | jobs
by phyller 2670 days ago
The problem is 200 passwords being compromised, including my emails which are used to reset everything else. I can't fix it faster than the thief can wreck my digital life, and everything is digital now. I couldn't even start until I somehow convince my email provider who I am and to change the password for me.

If this ever happens, best plan would probably be to change your email password immediately, banks next, and freeze your credit as soon as possible.

1 comments

A better, simpler-sounding plan is to enable better 2FA on your critical accounts. Doesn't this mostly fix your catastrophic scenario?
Oftentimes 2fa backup codes are slso stored in the password manager.
Or the password recovery for lost 2fa is secret questions (this is so awful,but see it often). And chances are those secret questions/answers might also be in the vault
Does anyone have a good solution to these issues for non techncial users? 1password etc + 2fa is great for even not super technical people.

But if it's ever breached I have no idea how you would get clear.

Sure but that's roughly equivalent to disabling or not having 2fa. You can still avoid the catastrophic scenario by not-doing that.