Hacker News new | ask | show | jobs
by ninjay 4760 days ago
So put that high entropy pass phrase in Keepass and don't worry about a cracker getting access to all your accounts through a misplaced hash. With all these sites getting attacked you have to assume anything you put in a website is public knowledge.

I mean, using a password safe is no more inconvenient than having to go to a website. When set up, the safe can even be a one click auto-fill deal. I don't see any reason to take the added risk.

1 comments

I'm not recommending this approach. I'm merely saying that it isn't as trivially broken as one would think.