Hacker News new | ask | show | jobs
by SAI_Peregrinus 1390 days ago
> I mean, you're not supposed to write down passwords, but with all the various restrictions you can't even use a consistent convention so you can actually remember them all.

You're supposed to use a password manager. Preferably with a passphrase and a second factor like a keyfile or hardware token.

2 comments

While password managers are great, there are some cases where I prefer to memorize the password.

That is because I want to be always able to easily access these accounts even when traveling or losing access to my technological devices. Though sadly these days things like 2FA make my life much harder in that regard.

Accounts that insists on doing 2fa over SMS...

No only is SMS generally considered insecure, it also falls down dramatically when I travel to the mountains where there's no cell coverage and try to do things on the cabin wifi.

Are you 'supposed to' or is that just the least worst option?

There are fairly limited scenarios when a password manager is better than a plain text document. And if it's online to actually share passwords between devices it's strictly worse.