|
|
|
|
|
by tetrad
4783 days ago
|
|
Their advice for diversifying your passwords is not very good. If you are using the same password stem with a suffix determined by the site name, as "m1p.5AsGs9LXo_HN" for HackerNews
"m1p.5AsGs9LXo_RandomForum" for some random forum
"m1p.5AsGs9LXo_WF" for Wells Fargo and the random forum's database gets popped, how secure do you think your Wells Fargo password "m1p.5AsGs9LXo_WF" is? Less than 12486848 years. That goes from the realm of password cracking to some guy typing out all the abbreviations he can think of for Reddit or Twitter. In case you're wondering, Wells Fargo will not accept "m1p.5AsGs9LXo_WF" as a password - too long! |
|
To me, it always feels like they're putting up a humongous, blinking sign proclaiming "Proudly storing your passwords in plaintext since 1991!" (Most notable offender, last time I checked: Skype)