Hacker News new | ask | show | jobs
by lolinder 1094 days ago
> You don't need a unique one for every site, either. Having 15 or 20 that you choose at random means that an invalidated one doesn't affect everything you do.

But it does mean that if one of those passwords gets leaked and the service that leaked it takes a while to notice, you now have X other services that are compromised and you don't even know it.

There are breaches on haveibeenpwned for my email that I was never notified of. If I were reusing passwords, each of those would represent a possible security breach in unrelated accounts.

1 comments

I'm not going to give examples here, but: there are tons of sites that no one is ever going to bother impersonating you on. They can't use them to buy, sell, move money, or ruin your reputation.

Maybe they're like diseases you have that aren't any threat to your health.

If some site is really important, then yes: you do need a unique password for it.