Hacker News new | ask | show | jobs
by bargl 3989 days ago
Troy Hunt comments on this. If it's a non-important site that shares a password with another important site that is an attack vector (I'm sure you aren't doing this but many users do). So if you stick to all non-important sites get weak passwords you'll probably be fine you just have to make sure there is no attack vector to another site of more importance.

I.E. If one of them has the last 4 digits of your credit card then they can call customer service at another more important site and get more information building to a full scale attack. It could happen in a similar way to what happened to Mat Honan http://www.wired.com/2012/08/apple-amazon-mat-honan-hacking/

However, that example leads to what the article is talking about. If it's a low probability then users figure the risk is worth it.

2 comments

Lastpass and it seems to work well. Have it generate a strong 12 character password with uppercase, lowercase, special characters and numbers (depending on the restrictions of the application). Secure it with a strong master password and change the master password on a regular basis.

That said, if someone guesses your master password, then you are in trouble.

My SSN is not protected my password! A hacker can steal my SSN by hacking the server database.