Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Shit, just looking at the replies, there's a solid case for password managers. No normal human is going to memorize 100+ unique passwords meeting various complexity requirements. It almost makes shaming people for re-using passwords look like you're out of touch. Of course they're following bad practices, how could they not be?!


This. And password managers can do more by constantly checking latest account breaches like on https://haveibeenpwned.com then flagging it to their customers to rotate their credentials.


There's a case for that even if you just have 5 important accounts. If the account matters, give it a long random password.


There's an unfortunate correlation between how long and complex my password is and how I often I have to manually type it in. Microsoft are really good in this regard, and you almost never have to type in your password once you have the Authenticator set up. Google isn't too bad, once you're logged in, but you still sometimes have to type out your password in a situation where having access to your password manager is not convenient. But I find Apple is the worst - I often need to type in my password, and often in situations where I don't have access to my password manager.


IIRC, Treasury.gov makes you enter your password by clicking buttons on a virtual, on-screen keyboard. Ugh.


They finally removed the virtual keyboard.

Do you remember when it was a random layout virtual keyboard? Good times.


Since when? As far as I know they still have the virtual keyboard and it was never random. They used to have a random seed physical card.


May 2 of this year, they posted a notification that the virtual keyboard would be removed the week of May 7 "to improve the customer experience."


They removed it approximately two weeks ago.


Thank god.


> . No normal human is going to memorize 100+ unique passwords meeting various complexity requirements.

No, they're either going to reuse their passwords or use post-its or excel.

> It almost makes shaming people for re-using passwords look like you're out of touch.

Shaming regular people for reusing passwords _is_ out of touch.


It's a solid case for FIDO2 keys.

- Inherent MFA that is faster and more secure than SMS codes, or app notifications.

- One pin code and/or biometric to remember rather than hundreds.

The answer isn't to add another layer of management to passwords, but to eliminate passwords as a method of authentication.


This. This is the only thing that actually solves all warts of authentication nowadays. Companies really should switch to a webauthn-first mindset. The technology has been here for over a decade, it's not new. There is a standrad and a library for every language, it's not hard. FIDO2 keys start at 20 bucks and every android phone can act as one, it's not expensive. They are literally the only thing that can actually protect you from phishing and they generate new login creds per domain, protecting your privacy. Companies, support webauthn!


I find those keys immensely inconvenient, though. I used them for a couple of years, but finally gave up and went back to long, randomly-generated passwords.


Yep. Password managers are quickly becoming a required utility for modern services. And oh how painful it would be to lose that. I memorize maybe 10~20 passwords. And I sometimes mix them up in my head as I type them too.

It's why we always laugh at anyone who says to "not reuse passwords".


Or a solid case for alternatives to standard username / password login concepts.


I take a pragmatic approach: the dozen logins in my life that actually matter get strong unique passwords, and everything I don't give a shit about gets the same password.


I don't know if I agree. A password manager is more pragmatic even for just a handful of accounts.

Whether it is safe or not, people can argue, but more practical? It definitely is.


It's not pragmatic, it's dangerous.

Sooner or later someone could take control of one of the accounts you don't care about and use in a way you don't expect to gain control of things you do care about.


> use in a way you don't expect to gain control of things you do care about

An example would really drive your point home. Can you provide one that people would deem "dangerous"?

Edit: ccooffee just mentioned in the thread that you could be de-anonymized by reusing the same password. Is this what you mean? There's a spectrum of comfort with privacy so maybe that's the source of the disagreement between whether it is important to have unique passwords or not for accounts that don't contain financial/SSN/medical/etc information


Socially engineered hacks are also a danger.

You might not care about what's contained in a certain online account, but there could be utility in taking control.


Beyond my accounts related to my important email addresses, Steam, finances and medical which can all be counted on one or two hands, I really couldn't give a damn about the other accounts or their password security.

Strong and unique passwords for the important accounts, simple and reused passwords for the rest. You're welcome to hack into my accounts on Hacker News, Reddit, Discord, LINE, various IRC networks, various forums, etc. I don't care; there's nothing important in there besides sentimental value.


On its own, the information in those private accounts is probably not interesting. I used to use the "few sites get a unique and secret password, but most reuse the same 10 character one" ruleset, but I became worried about how much data could be aggregated about me. By re-using the same password, I felt like I gave a simple test that attackers could use to definitively confirm "user XYZ on site ABC is the same as ccooffee".

I'm now firmly in the "everything gets a unique password" camp. There are 4 important passwords I type myself, but everything else is in a password vault.


I take the same approach with the extra precaution that those logins also get a separate email address (with a different pseudo-strong password). Makes it really easy to share nonsense logins with my wife/family.


That's how I lost my Twitter account. Using a PW manager only for the non-important accounts is a definitive improvement at a very low cost.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: